The Privacy Act 1988 and the 13 Australian Privacy Principles set the rules for how Australian organisations handle personal information. They are obligations you meet, not a certification a vendor can hold. When your CRM is a cloud product, two principles do most of the work in a vendor assessment: APP 11 on security, and APP 8 on cross-border disclosure. This page explains what the Act requires, walks through the APPs as they apply to a sales CRM, covers the Notifiable Data Breaches scheme, and sets out what HelloGrowthCRM does and what stays your responsibility as the APP entity.
The Privacy Act applies to APP entities, which include Australian Government agencies and most private sector organisations. Historically, organisations with annual turnover of three million Australian dollars or less have been treated as small business operators and fallen outside the Act, subject to exceptions such as health service providers, businesses that trade in personal information, and contracted service providers to the Commonwealth. That exemption has been narrowed by recent reform activity and remains under review, with further categories brought into scope. Confirm your own status against current law rather than relying on a turnover figure you checked several years ago.
The Act reaches beyond Australia's borders in two directions that matter for CRM buyers. An overseas organisation carrying on business in Australia can be caught by the Act in relation to personal information it handles here. Separately, and more importantly for most buyers, if you are an APP entity and you disclose personal information to an overseas recipient, APP 8 makes you accountable for that recipient's handling of it in most circumstances. Choosing an offshore cloud CRM does not move the obligation offshore along with the data. It stays with you, which is exactly why the vendor assessment matters so much.
Personal information is defined broadly as information or an opinion about an identified individual or an individual who is reasonably identifiable. It does not need to be true, and it does not need to be recorded in a material form. That covers essentially everything in a sales CRM: names, business contact details, call notes, meeting records and the inferences your team writes down. Sensitive information is a defined subset with stricter rules, covering health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, biometric and genetic information, and it generally requires consent to collect.
The principles run in a rough lifecycle order. APP 1 requires open and transparent management of personal information, including a clearly expressed and current privacy policy and practices that ensure compliance. APP 2 gives individuals the option of dealing with you anonymously or by pseudonym where practicable. APP 3 governs collection of solicited personal information and sets a higher bar for sensitive information. APP 4 tells you what to do with unsolicited information you did not ask for, including destroying or de-identifying it where you could not have collected it yourself. APP 5 requires notification at or before the time of collection.
The middle group governs use. APP 6 limits use and disclosure to the primary purpose of collection, or to a secondary purpose the individual would reasonably expect that is related to the first. APP 7 restricts direct marketing and requires a simple opt-out. APP 8 governs cross-border disclosure. APP 9 restricts adopting or using government related identifiers, which is a good reason not to store tax file numbers or similar identifiers in CRM fields. Each of these is a decision your team makes about how it uses the system, not something a vendor configures for you, which is why staff training matters as much as product selection.
The final group governs data quality, security and individual rights. APP 10 requires reasonable steps to ensure information is accurate, up to date and complete. APP 11 requires reasonable steps to protect information from misuse, interference, loss and unauthorised access, modification or disclosure, and to destroy or de-identify it when no longer needed. APP 12 gives individuals a right of access to their personal information, and APP 13 a right of correction. A CRM supports APP 10, 12 and 13 directly if you can search, export, edit and delete records without engineering help, which is worth testing during a trial.
APP 11 sets a reasonable steps standard rather than a fixed checklist, and what is reasonable scales with the sensitivity of the information and the harm that could follow. For a cloud CRM, the OAIC's guidance points at familiar ground: access controls, encryption, logging and monitoring, secure destruction, and governance over who can reach the data. HelloGrowthCRM encrypts data in transit with TLS and at rest. Customer records live in Supabase-managed Postgres on AWS, with row-level security enforcing tenant isolation at the database layer. Production access is least-privilege, MFA-gated, logged and periodically reviewed, and automated backups run with point-in-time recovery.
APP 11 also has a destruction limb that is easy to overlook. You must take reasonable steps to destroy or de-identify personal information once it is no longer needed for any purpose for which it may be used or disclosed, unless a law or court order requires retention. In a CRM, that means having an actual retention rule for dormant leads and closed-lost opportunities, and applying it. Workspace admins can export contacts, deals and activity data at any time and account deletion is honoured, which gives you the mechanics. Deciding what to keep and for how long is a policy decision that remains yours.
APP 8 is the principle that determines whether you can use an offshore CRM comfortably. Before disclosing personal information to an overseas recipient, you must take reasonable steps to ensure the recipient does not breach the APPs, unless an exception applies. Under section 16C, you generally remain accountable for the overseas recipient's acts as if they were your own. In practice this means contractual commitments, a documented assessment of the vendor's controls, and telling individuals in your APP 5 notice which countries recipients are likely to be in. The hosting region for your workspace is confirmed during onboarding, so ask before you migrate.
The NDB scheme requires APP entities to notify the Office of the Australian Information Commissioner and affected individuals about eligible data breaches. A breach is eligible where there is unauthorised access to, unauthorised disclosure of, or loss of personal information, and a reasonable person would conclude that this is likely to result in serious harm to any of the individuals to whom the information relates, and the entity has not been able to prevent that likely harm through remedial action. Serious harm can be physical, psychological, emotional, financial or reputational, and the assessment is objective rather than based on how the entity feels.
Timing has two parts. If you have reasonable grounds to suspect an eligible breach but are not yet sure, you must carry out a reasonable and expeditious assessment within thirty calendar days of becoming aware of those grounds. The OAIC treats thirty days as a maximum rather than a target, and expects entities to move faster where they can, because risk to individuals grows with time. Once you have reasonable grounds to believe an eligible breach has occurred, you must prepare a statement and notify the Commissioner and affected individuals as soon as practicable, with no separate grace period.
Where more than one entity holds the affected information, all of them technically have obligations, but only one needs to assess and notify on behalf of the group. Usually that should be the entity with the most direct relationship with the individuals at risk, which for CRM data is you rather than your software vendor. What you need from a vendor is prompt, useful notice and enough detail to run your own assessment inside the thirty day window. HelloGrowthCRM operates a documented incident-response workflow covering detect, contain, assess, remediate and notify, and publishes a vulnerability disclosure process at /legal/vulnerability-disclosure.
Work through the assessment in the order the principles apply to you. For APP 8, establish where data will be stored and which countries subprocessors operate from, then confirm the contractual commitments that bind them. The subprocessor list is published at /subprocessors, and the hosting region for your workspace is confirmed during onboarding. For APP 11, ask for evidence rather than assertions. Soor LLC completed a SOC 2 Type II examination covering the February to June 2025 observation window, and the report is available to procurement teams under NDA from sales@hellogrowthcrm.com. That is independent testing of controls, not a self-assessment.
For APP 12 and APP 13, test the product rather than reading the datasheet. Can an ordinary administrator find every record about one person, export it in a usable format, correct it and delete it, without raising a support ticket or waiting on the vendor? Workspace admins can export contacts, deals and activity data at any time, records can be corrected in place, and account deletion is honoured. Run that end to end during your trial with a test record. Access and correction requests carry timeframes and an obligation to give written reasons for refusal, so a slow manual process becomes a compliance problem quickly.
For the NDB scheme, ask about notification mechanics before you sign, not after an incident. Who contacts you, how quickly, through what channel, and what detail will you get. Make sure the vendor holds current contact details for whoever in your organisation runs breach assessment. Finally, remember which duties never move. Your privacy policy under APP 1, your collection notice under APP 5, your use and disclosure decisions under APP 6, your direct marketing practices under APP 7 and your retention policy under APP 11 are yours. A vendor supplies controls and evidence. You supply the governance.
Email sales@hellogrowthcrm.com to request the SOC 2 Type II report and the DPA under NDA, and to confirm the hosting region for your workspace. The subprocessor list at /subprocessors and data rights documentation at /legal/data-rights are public, so you can start the APP 8 and APP 11 assessment now.