Meet your Australian Privacy Act duties when your CRM sits offshore
The Privacy Act 1988 and the 13 Australian Privacy Principles set the rules for how Australian organisations handle personal information. They are obligations you meet, not a certification a vendor can hold. When your CRM is a cloud product, two principles do most of the work in a vendor assessment: APP 11 on security, and APP 8 on cross-border disclosure. This page explains what the Act requires, walks through the APPs as they apply to a sales CRM, covers the Notifiable Data Breaches scheme, and sets out what HelloGrowthCRM does and what stays your responsibility as the APP entity.
Who the Privacy Act covers
The Privacy Act applies to APP entities, which include Australian Government agencies and most private sector organisations. Historically, organisations with annual turnover of three million Australian dollars or less have been treated as small business operators and fallen outside the Act, subject to exceptions such as health service providers, businesses that trade in personal information, and contracted service providers to the Commonwealth. That exemption has been narrowed by recent reform activity and remains under review, with further categories brought into scope. Confirm your own status against current law rather than relying on a turnover figure you checked several years ago.
The Act reaches beyond Australia's borders in two directions that matter for CRM buyers. An overseas organisation carrying on business in Australia can be caught by the Act in relation to personal information it handles here. Separately, and more importantly for most buyers, if you are an APP entity and you disclose personal information to an overseas recipient, APP 8 makes you accountable for that recipient's handling of it in most circumstances. Choosing an offshore cloud CRM does not move the obligation offshore along with the data. It stays with you, which is exactly why the vendor assessment matters so much.
Personal information is defined broadly as information or an opinion about an identified individual or an individual who is reasonably identifiable. It does not need to be true, and it does not need to be recorded in a material form. That covers essentially everything in a sales CRM: names, business contact details, call notes, meeting records and the inferences your team writes down. Sensitive information is a defined subset with stricter rules, covering health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, biometric and genetic information, and it generally requires consent to collect.
The 13 APPs in a CRM context
The principles run in a rough lifecycle order. APP 1 requires open and transparent management of personal information, including a clearly expressed and current privacy policy and practices that ensure compliance. APP 2 gives individuals the option of dealing with you anonymously or by pseudonym where practicable. APP 3 governs collection of solicited personal information and sets a higher bar for sensitive information. APP 4 tells you what to do with unsolicited information you did not ask for, including destroying or de-identifying it where you could not have collected it yourself. APP 5 requires notification at or before the time of collection.
The middle group governs use. APP 6 limits use and disclosure to the primary purpose of collection, or to a secondary purpose the individual would reasonably expect that is related to the first. APP 7 restricts direct marketing and requires a simple opt-out. APP 8 governs cross-border disclosure. APP 9 restricts adopting or using government related identifiers, which is a good reason not to store tax file numbers or similar identifiers in CRM fields. Each of these is a decision your team makes about how it uses the system, not something a vendor configures for you, which is why staff training matters as much as product selection.
The final group governs data quality, security and individual rights. APP 10 requires reasonable steps to ensure information is accurate, up to date and complete. APP 11 requires reasonable steps to protect information from misuse, interference, loss and unauthorised access, modification or disclosure, and to destroy or de-identify it when no longer needed. APP 12 gives individuals a right of access to their personal information, and APP 13 a right of correction. A CRM supports APP 10, 12 and 13 directly if you can search, export, edit and delete records without engineering help, which is worth testing during a trial.
APP 11 security and APP 8 cross-border disclosure
APP 11 sets a reasonable steps standard rather than a fixed checklist, and what is reasonable scales with the sensitivity of the information and the harm that could follow. For a cloud CRM, the OAIC's guidance points at familiar ground: access controls, encryption, logging and monitoring, secure destruction, and governance over who can reach the data. HelloGrowthCRM encrypts data in transit with TLS and at rest. Customer records live in Supabase-managed Postgres on AWS, with row-level security enforcing tenant isolation at the database layer. Production access is least-privilege, MFA-gated, logged and periodically reviewed, and automated backups run with point-in-time recovery.
APP 11 also has a destruction limb that is easy to overlook. You must take reasonable steps to destroy or de-identify personal information once it is no longer needed for any purpose for which it may be used or disclosed, unless a law or court order requires retention. In a CRM, that means having an actual retention rule for dormant leads and closed-lost opportunities, and applying it. Workspace admins can export contacts, deals and activity data at any time and account deletion is honoured, which gives you the mechanics. Deciding what to keep and for how long is a policy decision that remains yours.
APP 8 is the principle that determines whether you can use an offshore CRM comfortably. Before disclosing personal information to an overseas recipient, you must take reasonable steps to ensure the recipient does not breach the APPs, unless an exception applies. Under section 16C, you generally remain accountable for the overseas recipient's acts as if they were your own. In practice this means contractual commitments, a documented assessment of the vendor's controls, and telling individuals in your APP 5 notice which countries recipients are likely to be in. The hosting region for your workspace is confirmed during onboarding, so ask before you migrate.
The Notifiable Data Breaches scheme
The NDB scheme requires APP entities to notify the Office of the Australian Information Commissioner and affected individuals about eligible data breaches. A breach is eligible where there is unauthorised access to, unauthorised disclosure of, or loss of personal information, and a reasonable person would conclude that this is likely to result in serious harm to any of the individuals to whom the information relates, and the entity has not been able to prevent that likely harm through remedial action. Serious harm can be physical, psychological, emotional, financial or reputational, and the assessment is objective rather than based on how the entity feels.
Timing has two parts. If you have reasonable grounds to suspect an eligible breach but are not yet sure, you must carry out a reasonable and expeditious assessment within thirty calendar days of becoming aware of those grounds. The OAIC treats thirty days as a maximum rather than a target, and expects entities to move faster where they can, because risk to individuals grows with time. Once you have reasonable grounds to believe an eligible breach has occurred, you must prepare a statement and notify the Commissioner and affected individuals as soon as practicable, with no separate grace period.
Where more than one entity holds the affected information, all of them technically have obligations, but only one needs to assess and notify on behalf of the group. Usually that should be the entity with the most direct relationship with the individuals at risk, which for CRM data is you rather than your software vendor. What you need from a vendor is prompt, useful notice and enough detail to run your own assessment inside the thirty day window. HelloGrowthCRM operates a documented incident-response workflow covering detect, contain, assess, remediate and notify, and publishes a vulnerability disclosure process at /legal/vulnerability-disclosure.
Assessing any CRM vendor against the APPs
Work through the assessment in the order the principles apply to you. For APP 8, establish where data will be stored and which countries subprocessors operate from, then confirm the contractual commitments that bind them. The subprocessor list is published at /subprocessors, and the hosting region for your workspace is confirmed during onboarding. For APP 11, ask for evidence rather than assertions. Soor LLC completed a SOC 2 Type II examination covering the February to June 2025 observation window, and the report is available to procurement teams under NDA from sales@hellogrowthcrm.com. That is independent testing of controls, not a self-assessment.
For APP 12 and APP 13, test the product rather than reading the datasheet. Can an ordinary administrator find every record about one person, export it in a usable format, correct it and delete it, without raising a support ticket or waiting on the vendor? Workspace admins can export contacts, deals and activity data at any time, records can be corrected in place, and account deletion is honoured. Run that end to end during your trial with a test record. Access and correction requests carry timeframes and an obligation to give written reasons for refusal, so a slow manual process becomes a compliance problem quickly.
For the NDB scheme, ask about notification mechanics before you sign, not after an incident. Who contacts you, how quickly, through what channel, and what detail will you get. Make sure the vendor holds current contact details for whoever in your organisation runs breach assessment. Finally, remember which duties never move. Your privacy policy under APP 1, your collection notice under APP 5, your use and disclosure decisions under APP 6, your direct marketing practices under APP 7 and your retention policy under APP 11 are yours. A vendor supplies controls and evidence. You supply the governance.
Controls and capabilities at a glance
- Data is encrypted in transit with TLS and encrypted at rest, supporting the reasonable steps standard for protecting personal information under APP 11.
- Customer records live in Supabase-managed Postgres on AWS, with row-level security enforcing tenant isolation at the database layer rather than only in application code.
- The hosting region for your workspace is confirmed during onboarding, so you can document destinations for your APP 8 assessment and APP 5 notice.
- The subprocessor list is published at /subprocessors, letting you identify every overseas recipient before you disclose personal information to the service.
- Production access is least-privilege, MFA-gated, logged and periodically reviewed, addressing the access control expectations that sit behind APP 11.
- Role-based access control inside each workspace lets you limit which staff can view or change contact records, reducing internal misuse risk.
- Workspace admins can export contacts, deals and activity data at any time, which supports access requests under APP 12 and portability.
- Records can be corrected in the workspace and account deletion is honoured, supporting APP 13 correction and the APP 11 destruction obligation.
- A documented incident-response workflow covering detect, contain, assess, remediate and notify helps you complete an NDB assessment within thirty days.
- Soor LLC completed a SOC 2 Type II examination for the February to June 2025 window; the report is available under NDA from sales@hellogrowthcrm.com.
Questions reviewers ask
- Is HelloGrowthCRM certified under the Australian Privacy Act?
- No, and no product is. The Privacy Act 1988 sets obligations for APP entities and does not operate a certification scheme for software. What a vendor can offer is evidence and contractual commitments that help you meet your own obligations, particularly APP 8 on cross-border disclosure and APP 11 on security. Soor LLC completed a SOC 2 Type II examination covering February to June 2025, available under NDA, and HelloGrowthCRM publishes its subprocessor list at /subprocessors and documents data rights handling at /legal/data-rights.
- Can we use an offshore CRM under APP 8?
- Yes, and most Australian organisations do. APP 8 does not prohibit overseas disclosure. It requires you to take reasonable steps to ensure the overseas recipient does not breach the APPs, unless an exception applies, and under section 16C you generally remain accountable for that recipient's handling. Practically that means contractual commitments, a documented assessment of the vendor's security controls, knowing which countries are involved, and disclosing the likely destination countries in your APP 5 collection notice. Ask about hosting region during onboarding and record the answer.
- Does the small business exemption apply to us?
- Check current law rather than assuming. Organisations with annual turnover of three million Australian dollars or less have historically been treated as small business operators outside the Act, but there are longstanding exceptions covering health service providers, businesses that trade in personal information and Commonwealth contracted service providers. Reform activity has narrowed the exemption and brought further categories into scope. Even where an exemption applies, many organisations choose to follow the APPs voluntarily because customers and enterprise buyers expect it in contracts.
- What does APP 11 actually require?
- Reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, plus destruction or de-identification when the information is no longer needed. Reasonable scales with sensitivity and potential harm, so there is no fixed checklist. In practice, assessors look for access controls, encryption in transit and at rest, logging and monitoring, tested backups, incident response and a real retention practice. Independent evidence such as a SOC 2 Type II report is the most efficient way to demonstrate the vendor side.
- When do we have to notify a data breach?
- When a breach is likely to result in serious harm and you cannot prevent that harm through remedial action. If you suspect an eligible breach but are not certain, you must complete a reasonable and expeditious assessment within thirty calendar days of becoming aware of the grounds for suspicion. The OAIC treats that as a maximum, not a target. Once you have reasonable grounds to believe an eligible breach occurred, notify the Commissioner and affected individuals as soon as practicable using a statement meeting the prescribed content requirements.
- Who notifies if the breach happens at the vendor?
- Where more than one entity holds the affected information, all have obligations under the scheme, but only one needs to assess and notify on behalf of the group. The OAIC guidance points to the entity with the most direct relationship with the individuals at risk, which for CRM records is normally you rather than the software vendor. What you need from the vendor is prompt notice with enough detail to run your own assessment. Confirm the notification route and your contacts before an incident, not during one.
- How do we handle an access or correction request?
- APP 12 gives individuals a right to access their personal information and APP 13 a right to correction, both with response timeframes and an obligation to give written reasons if you refuse. Operationally you need to locate every record about the person, produce it in a usable form, and amend or annotate it where required. Workspace admins can export contacts, deals and activity data at any time, records can be corrected in place, and account deletion is honoured. Test this with a sample record during your trial.
- What about direct marketing under APP 7?
- APP 7 generally restricts using personal information for direct marketing, with conditions depending on how the information was collected and whether the individual would reasonably expect it. You must provide a simple means of opting out and honour it, and you must stop on request. The Spam Act and the Do Not Call Register impose separate rules on electronic messages and calls. Your CRM records consent and suppression states, but the marketing decisions, the notice wording and the opt-out honouring are your responsibility.
Get the evidence your privacy assessment needs
Email sales@hellogrowthcrm.com to request the SOC 2 Type II report and the DPA under NDA, and to confirm the hosting region for your workspace. The subprocessor list at /subprocessors and data rights documentation at /legal/data-rights are public, so you can start the APP 8 and APP 11 assessment now.