APP 8 and Section 16C: You Own Your Vendor Data Breach
Section 16C of the Privacy Act makes your clinic accountable for what an overseas vendor does with a patient's data, and APP 8 sets the reasonable steps you must take before that disclosure happens. This guide breaks the rule into the vendor categories a clinic or dental practice actually runs and what each one needs on file to satisfy an exception.

On this page 11
- What APP 8 and Section 16C Actually Say
- What That Means for the Build
- Vendor Categories and Your Cross-Border Exposure
- A Worked Example
- What to Check on Your Own Site
- The Enforcement Anchor
- Where This Gets Hard
- Status
- Frequently Asked Questions
- Get Your Vendor Stack Checked Before It Becomes Your Breach
- Sources
If a booking platform, email tool, or after-hours answering service outside Australia mishandles a patient’s personal information, the Privacy Act treats the mishandling as your clinic’s breach, not the vendor’s. That is what section 16C of the Privacy Act 1988 does, working alongside Australian Privacy Principle 8 (APP 8): the OAIC’s Chapter 8 guideline (October 2025, version 1.3) calls it an accountability approach, and your clinic stays liable for what an overseas recipient does with information you disclosed to it unless a specific exception applies. As at 21 August 2026 this rule is neither new nor proposed, and it has nothing to do with the still-unlegislated small business exemption debate. It has covered health service providers, cosmetic clinics and cosmetic dental practices among them, since the current Australian Privacy Principles commenced in March 2014, regardless of turnover.
What APP 8 and Section 16C Actually Say
The OAIC’s Australian Privacy Principles Guidelines, Chapter 8: Cross-border disclosure of personal information (October 2025, v1.3), sets out two obligations that work together, one at the front of the disclosure and one behind it.
APP 8.1 is the front-end duty. Before your clinic discloses personal information about a patient to an overseas recipient, you must take steps that are reasonable in the circumstances to ensure the recipient does not breach the Australian Privacy Principles in relation to that information.
Section 16C of the Privacy Act is the back-end consequence. If an overseas recipient does breach the APPs after you disclosed information to it, the Act treats that breach as if your clinic committed it. The recipient’s act or practice is, in the guideline’s own language, “taken to have been done by the APP entity, and to be a breach of the Australian Privacy Principles by that entity.” Your contract with the vendor, and any argument the vendor makes about jurisdiction, does not change who the OAIC pursues.
APP 8.2 sets two exceptions that cover most clinic situations. Under 8.2(a), you can disclose without the reasonable steps duty if you reasonably believe the recipient is subject to a law, or a binding scheme, that protects the information in a way that is, overall, at least substantially similar to the APPs, with mechanisms the patient can access to enforce that protection. Under 8.2(b), you can disclose after expressly informing the patient that APP 8.1 will not apply if they consent, and the patient then consents. A handful of narrower exceptions cover law enforcement and legally required disclosures, but they rarely apply to a private clinic’s day-to-day vendor stack.
What That Means for the Build
Turn this into an implementation checklist rather than a legal reading, and three things need a home in your stack.
First, a vendor data flow map. List every third party your booking flow, contact form, and patient communication touch: booking widget, live chat or chatbot, email or SMS reminder tool, payment processor, offshore reception or call answering service, and any offshore development or support contractor with access to production data. For each one, record where the vendor actually processes and stores data, not just where its marketing page says its head office is.
Second, a documented exception for every offshore vendor. The file should state a position: “8.2(a), because the vendor’s Data Processing Addendum names GDPR-equivalent handling with an enforceable complaint mechanism the patient can use,” or “8.2(b), because the patient was expressly told and consented before the booking form submitted,” or “reasonable steps taken: contract clause referenced, subprocessor list attached, review date set.” A vendor being probably fine is not a documented exception.
Third, a privacy policy field. APP 1.4(f) requires your collection notice or privacy policy to state whether your clinic is likely to disclose personal information to overseas recipients and, if practicable, which countries. Most template clinic privacy policies carry generic wording like “we may use third party service providers” with no country named. That does not satisfy the notice requirement once you know which countries your booking widget, patient record system and email tool actually run from, and it is a short fix once the vendor map from step one exists.
Health service providers reported 225 of the 1,205 total data breach notifications made to the OAIC in the 2025 calendar year, more than any other sector, according to the OAIC’s Notifiable Data Breaches statistics for the period.
Vendor Categories and Your Cross-Border Exposure
The same vendor category can sit under a different exception depending on where it processes data and what it collects. Use this as a starting map, then confirm each row against your own vendor’s actual location.
| Vendor category | Typical data disclosed | Likely APP 8 exception | Action before go-live |
|---|---|---|---|
| Booking widget or online scheduling | Name, contact details, treatment interest | 8.2(a) if EU or UK based with equivalent terms, otherwise reasonable steps | Get a Data Processing Addendum, confirm storage region |
| Email or SMS reminder platform | Name, contact, appointment, sometimes treatment photos | 8.2(a) or reasonable steps | Check the subprocessor list, restrict photo fields |
| Live chat or chatbot widget | Enquiry text, sometimes health details typed by the patient | 8.2(b) consent, stated in the chat disclaimer | Add a pre-chat notice naming the vendor’s country |
| Offshore answering service or virtual reception | Name, phone, treatment interest, call recordings | Reasonable steps via contract clause | Written data handling clause, no health detail capture by phone |
| Patient record system with offshore support access | Full patient record, clinical notes | Reasonable steps, often 8.2(a) | Support-access logging, region-locked storage where offered |
| Offshore development or support contractor | Database and admin access during projects | Reasonable steps via contract | Time-boxed access, revoked after the project ends |
Financial services (157), the Australian Government (118), and business and professional associations (103) were the next-largest sectors reporting to the OAIC in 2025, with education and the legal, accounting and management sector tied at 81 notifications each, according to the same OAIC 2025 Notifiable Data Breaches figures cited above.
A Worked Example
A cosmetic injectables clinic
Consider a Perth cosmetic injectables clinic running a booking widget hosted by a US-headquartered SaaS vendor, plus a US-based email platform for post-treatment care reminders that sometimes include a photo of the treated area. Both are overseas recipients under APP 8. The clinic’s file should state which exception it relies on for each: if the email platform’s Data Processing Addendum names a framework providing GDPR-equivalent protection with a complaints mechanism the patient can use, that supports 8.2(a). If it does not, the clinic needs either genuine informed consent captured before the booking form submits, naming the vendor and the country, or documented reasonable steps: reviewing the vendor’s security certifications, checking its breach notification clause, and setting a review date. If the email vendor later suffers a breach because it left a database publicly accessible, section 16C makes that the clinic’s own breach for notification purposes, not a story the clinic can hand off to the vendor’s incident page.
A cosmetic dental practice
A cosmetic dentistry practice running an after-hours online enquiry form routes overflow calls to an offshore answering service based in the Philippines. Enquiry details, including which cosmetic procedure the caller asked about and sometimes a description of their teeth, are disclosed to that overseas call centre every time a call is diverted. Because the informed-consent exception under 8.2(b) requires the disclosure to be express and specific, a generic privacy policy line does not qualify. The practical fix is a short spoken or written disclosure at the point the call is diverted or the after-hours form is submitted, naming the answering service’s location, plus a written data handling clause in the answering service contract covering call recording storage and retention. Without either, the practice is relying on APP 8.1 reasonable steps alone and needs to be able to show what those steps were if the OAIC ever asks.
Malicious or criminal attacks caused 716 of the 1,205 notifications reported to the OAIC in the 2025 calendar year, the largest single cause category. That is exactly the risk APP 8.1’s reasonable steps duty is aimed at reducing before a disclosure happens, not after.
What to Check on Your Own Site
- List every integration on your booking flow, contact form and reminder system, and note which country each vendor processes data in.
- Open your current privacy policy and check the disclosure section. If it only says “third party service providers” with no country named, it does not meet the APP 1.4(f) notice requirement.
- Ask each offshore vendor for a signed Data Processing Addendum stating storage region, subprocessor list and breach notification timeframe. No Data Processing Addendum means no evidence of reasonable steps.
- Check whether a live chat or chatbot widget lets a patient type health information before any privacy notice naming the vendor’s country has been shown.
- If an answering service or virtual receptionist handles after-hours enquiries, confirm the contract has a specific data handling clause, not just a general service agreement.
- Check whether developer or support access to your patient record system or website admin is time-boxed and revoked after a project ends, rather than left open indefinitely.
The OAIC recorded 1,205 data breach notifications in the 2025 calendar year, an 8 percent rise on the 1,112 notifications logged in 2024 and the highest total since the scheme began, the same trend behind the sector and cause figures charted throughout this guide.
The Enforcement Anchor
No published OAIC determination names an AHPRA-registered cosmetic clinic or cosmetic dental practice for a breach of APP 8 or section 16C specifically. That absence is worth stating plainly rather than dressing up an unrelated case as a precedent it is not.
What is verified and current is the penalty regime behind the rule. The OAIC’s Guide to Privacy Regulatory Action, Chapter 7 confirms the maximum civil penalty for a body corporate found to have seriously or repeatedly interfered with privacy under section 13G of the Privacy Act is the greater of $50 million, three times the value of any benefit obtained, or 30% of adjusted turnover during the breach period. That figure rose from $2.22 million when the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 commenced on 12 December 2022, and it remains the current law.
The health sector’s exposure is also verified and current. The OAIC’s 2025 Notifiable Data Breaches figures show health service providers reported more notifications than any other sector for the calendar year, with malicious or criminal attacks the largest single cause. Cross-border disclosure through a vendor is one of the ways that exposure reaches a clinic that never touched the breach itself.
Where This Gets Hard
Two parts of this framework resist a clean checklist answer.
Assessing whether an overseas recipient’s country has a law that is substantially similar, overall, to the APPs is a comparative legal judgment, not a technical setting in a vendor’s admin panel. A vendor’s marketing page claiming GDPR compliance is not the same as your clinic having a documented, defensible basis for believing 8.2(a) applies to that specific disclosure.
The consent exception under 8.2(b) is only as strong as the disclosure that produced it. If the notice shown to a patient before they consent does not specifically flag that APP 8.1 protections will not apply, a regulator or a court could find the consent was not the kind APP 8.2(b) requires, which puts the clinic back under the 8.1 reasonable steps duty it may not have otherwise met.
Both of these are the same shape of problem: the regulator says an APP entity is accountable for an overseas recipient’s mishandling of personal information unless it reasonably believed the recipient was subject to a substantially similar law or held valid, informed consent from the patient; the build consequence is that every offshore vendor integration on your site needs a documented, dated answer to which exception it relies on and evidence to back that answer; whether your specific vendor contract, privacy notice wording and consent flow actually satisfy that exception is a question for your medical defence organisation or your lawyer.
Status
As at 21 August 2026, APP 8 and section 16C are both fully in force and have been since the current Australian Privacy Principles commenced under the Privacy Act 1988 on 12 March 2014. Neither is a proposal, and neither is connected to the separate, still-unlegislated removal of the small business exemption, which as at this date has no passed Bill and no commencement date, only the Attorney-General’s confirmation in February 2026 Senate estimates that a second tranche is progressing.
Frequently Asked Questions
What is APP 8 of the Privacy Act?
Australian Privacy Principle 8 requires an APP entity to take reasonable steps before disclosing personal information to an overseas recipient, to make sure the recipient does not breach the Australian Privacy Principles with that information, unless a specific exception applies.
What does section 16C of the Privacy Act mean for cross-border disclosure?
Section 16C makes the disclosing entity accountable for what an overseas recipient does with information after it was disclosed. If the recipient breaches the Australian Privacy Principles, the Act treats that breach as if the disclosing entity committed it.
Does the small business exemption cover a cosmetic clinic that uses overseas vendors?
No. Health service providers, which includes most cosmetic clinics and cosmetic dental practices, are already covered by the Privacy Act regardless of annual turnover. This existing rule is separate from a proposed removal of the general small business exemption, which has not been legislated as at August 2026.
What counts as reasonable steps under APP 8.1 before sending patient data overseas?
The OAIC’s guideline does not set a fixed checklist. In practice, reasonable steps typically include reviewing the vendor’s security and privacy commitments, a signed Data Processing Addendum naming storage regions and subprocessors, and a documented basis for believing the vendor will not breach the Australian Privacy Principles with the information.
Can a clinic use patient consent to avoid APP 8 obligations?
Only if the consent is specific and informed. APP 8.2(b) requires the patient to be expressly told that APP 8.1 protections will not apply before they consent. A general privacy policy clause is unlikely to meet that standard, which means the reasonable steps duty under APP 8.1 stays in place.
Get Your Vendor Stack Checked Before It Becomes Your Breach
Get in touch with RockingWeb and we’ll review every integration on your booking flow and enquiry forms against APP 8, and return a written list of which vendors disclose patient data overseas, which exception each one relies on, and where the documentation is missing.
Sources
- OAIC - APP Guidelines Chapter 8: Cross-border disclosure of personal information, October 2025, v1.3. Checked 21 August 2026.
- OAIC - Guide to Privacy Regulatory Action, Chapter 7: Civil penalties for serious or repeated interference with privacy. Checked 21 August 2026.
- OAIC - Data breach notifications increase to all-time high in 2025, new NDB stats show. Checked 21 August 2026.
- Rules Mate - The second tranche of Privacy Act reforms: what’s proposed and what’s still uncertain. Checked 21 August 2026.
- Biztech Lawyers - Australia’s privacy reform: shaping the future of data protection, confirming the Attorney-General’s February 2026 Senate estimates statement that a Tranche 2 Bill is progressing. Checked 21 August 2026.
Last reviewed: 21 August 2026.

Vikas Thakur
Founder of RockingWeb. 16 years building for companies like TPG, iiNet and Monadelphous, now focused on websites and marketing that comply with AHPRA's advertising guidelines and still book patients.




