Australian Privacy Principles (APPs)
Part 3 - Dealing with Personal Information

Australian Privacy Principles (APPs) APP-8: APP 8 - Cross-border disclosure of personal information

Before disclosing personal information overseas, take reasonable steps to ensure the overseas recipient does not breach the APPs.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 109 controls across 72 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 4 controls

  • 7.2.6 Contracts with PII processors
  • 7.5.1 Identify basis for PII transfer between jurisdictions
  • 7.5.2 Countries and international organizations to which PII can be transferred
  • 7.5.3 Records of transfer of PII

APPI · 3 controls

  • APPI-A25 Supervision of Trustees
  • APPI-A28 Provision to Third Parties in Foreign Countries
  • APPI-A31 Provision of Personally Referable Information

GDPR · 3 controls

  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • EHDSREG-4 Digital Health Authorities, Governance, MyHealth@EU
  • EHDSREG-5 Cross-Border Health Data Flows

C5 (Germany) · 2 controls

  • C5-PSS-12 Locations of Data Processing and Storage
  • C5-SSO-04 Monitoring of compliance with requirements

FedRAMP High · 2 controls

  • SA-9 External System Services
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))

FedRAMP Moderate · 2 controls

  • SA-9 External System Services
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • UAE-PDPL-Art.22_23_24 Cross-border data transfers (UAE PDPL Articles 22-24)
  • UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29)
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • CH-FADP-24 Cross-border transfer safeguards
  • FADP-10 Cross-Border Disclosure (Articles 16-18)
  • AL-DPA-14 Direct Marketing
  • AUCDR-PS-8 Privacy Safeguard 8 - Overseas disclosure of CDR data
  • MYHR-CUD-4 Records not held or taken outside Australia
  • AZ-DPA-12 Article 13 - Cross-border transfer

Bahrain PDPL · 1 control

  • BB-DPA-17 Section 24 - Appropriate Safeguards

CCPA/CPRA · 1 control

  • §1798.100(d) Contractual Requirements for Third Parties, Service Providers, and Contractors
  • LOPDP-EC-Cross-Border-Transfers-Articles-59-65-Adequacy-SCC-BCR-EU-Schrems-LatAm-CBPR-Andean-Community Ecuador LOPDP Cross-Border + Articles 59-65 + Adequacy + Andean Community + LatAm

HIPAA Security Rule · 1 control

  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)
  • ICP-25 Supervisory Cooperation and Coordination

India DPDP Act · 1 control

  • INCDPA-Processor-Contracts-DPA-Subprocessor-Audit-Confidentiality-EndOfContract Indiana CDPA Processor Contracts - Data Processing Agreement (DPA) + Required Provisions + Subprocessor Approval + Confidentiality + End of Contract Deletion + Audit Rights + Assistance
  • IsraelPPL-CrossBorder-Transfer-Sec36-EU-Adequacy-Israel-Adequacy-SCCs-Reciprocity-Foreign-Recipient Israel POPL Cross-Border Transfer + Section 36 + Privacy Protection (Transfer of Data to Databases Abroad) Regulations 5761-2001 + EU Adequacy Decision (2011) + SCCs + Foreign Recipient Obligations + Reciprocity

LGPD · 1 control

  • LGPD-BR-Cross-Border-International-Transfer-Article-33-Adequacy-SCC-BCR-ANPD-Approval-Mercosur-RIPD Brazil LGPD Cross-Border + Article 33 + Adequacy + SCC + BCR + Mercosur + RIPD
  • DOM172-Cross-Border-Transfer-Article-80-Vendor-Processor-Management-Marketing-Direct-Communications-Article-23-24-26 Dominican Republic Law 172-13 Cross-Border Transfer + Vendor Management + Marketing + Articles 23-24-26-80

Liechtenstein DPA · 1 control

MTCS (Singapore) · 1 control

  • MTCS-Scope-SS-584-Singapore-Standards-Council-IMDA-SAC-3-Tier-2013-2015-2020-2024-Certification MTCS Scope + SS 584 + Singapore Standards Council + IMDA + SAC + 3-Tier Framework + Certification

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing

Mauritius DPA · 1 control

  • MU-DPA-Enforcement-Commissioner-Section-41-43-MUR-200K-5-Year-Prison-ICT-Appeal-Tribunal-Supreme-Court Mauritius DPA Enforcement + Commissioner + Section 41 + Section 43 + MUR 200K + 5 Year Prison + ICT Appeal Tribunal + Supreme Court

Mexico LFPDPPP · 1 control

  • MX-LFPDPPP-Enforcement-INAI-Articles-63-64-67-320K-Days-Minimum-Wage-3-Year-Prison-TFJA-Recurso-Revision-SCJN Mexico LFPDPPP Enforcement + INAI + Articles 63-64-67 + 320K Days Minimum Wage + 3 Year Prison + TFJA + Recurso de Revision + SCJN
  • MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-Identification Minnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification
  • MT-CDPA-Processor-Contract-Security-MCA-30-14-2809-30-14-2811-Pseudonymisation-De-Identification Montana CDPA Processor + MCA 30-14-2809 + Security + Pseudonymisation + MCA 30-14-2811 + De-Identification

NIST SP 800-122 · 1 control

  • NISTSP122-7 PII Sharing, Cross-Border Transfers, and Third-Party Agreements
  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NGNDPR-7 Cross-Border Transfer of Personal Data under NDPR Section 2.7-CBT
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs

PDPA Singapore · 1 control

  • PDPASG-6 Transfer Limitation, Cross-Border Safeguards, and Data Intermediary Oversight

PDPA Thailand · 1 control

  • PDPATH-6 Cross-Border Transfer and Processor Engagement

POPIA · 1 control

  • POPIASA-6 Transborder Information Flows, Direct Marketing
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • NORWAY-6 International Transfers and Processor Agreements

Privacy Act 2020 · 1 control

  • NZPRV-5 IPP 11-12 Disclosure, Cross-Border Disclosure (Schedule 8)

Qatar DPL · 1 control

  • QATAR-6 Cross-Border Transfer and Processor Management
  • RCEPEC-2 Cross-Border Transfer, Computing Facilities, Localization (12.14-15)

Saudi Arabia PDPL · 1 control

  • SA-PDPL-24 Cross-border transfer safeguards
  • IM8-CLD.4 Cloud Data Sovereignty

South Korea ISMS-P · 1 control

  • ISMSP-PI-04 Cross-Border Transfer

South Korea PIPA · 1 control

  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021

Taiwan PDPA · 1 control

  • TAIWAN-4 DPIA, Privacy by Design
  • TEXASTDPSA-3 Sensitive Data, Children, Sale Notice

Turkey KVKK · 1 control

  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • UK-DPA18-LE-03 International Transfers (Law Enforcement)
  • UKGDPRREG-3 Controller and Processor (Articles 24-43)
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation

Uruguay DPL · 1 control

  • URUGUAY-5 Database Registration with AGESIC URCDP
  • VIETNAMCYBER-3 Data Localization and Cross-Border

Vietnam PDPD · 1 control

  • VIETNAMPDP-3 Data Subject Rights

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-4 Privacy Notice and DPIA

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Part 3 - Dealing with Personal Information

You are reading one control. How much of Australian Privacy Principles (APPs) have you already done?

Australian Privacy Principles (APPs) APP-8 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Australian Privacy Principles (APPs) your existing evidence covers. Hold GDPR and 11 of 13 Australian Privacy Principles (APPs) controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the GDPR pair alone.

Query this from an agent

The graph holds this control, the 109 it maps to, and the evidence behind each claim, over MCP and REST.