What Australian businesses must consider under APP 8 before sending personal information overseas for AI processing.

dgm is an independent osFoundry integration partner — not affiliated with osFoundry’s maker (OS LLC), and dgm has no completed client integrations yet.

Sending data to an AI service overseas is common — most major AI providers are US-based. Here is what Australian businesses must consider under APP 8 before data crosses the border.

The APP 8 position

Australia permits overseas disclosure of personal information, but APP 8 generally makes you accountable for the overseas recipient’s handling of it — you must take reasonable steps to ensure they handle it consistently with the Australian Privacy Principles, unless a recognised exception applies (such as informed consent). It is an accountability model, not a ban.

What ‘reasonable steps’ looks like

In practice that means contractual protections with the AI provider, due diligence on their handling, and transparency in your privacy policy about overseas disclosure. For sensitive information, the bar is higher.

Reducing the exposure

For sensitive data, the simplest way to avoid cross-border complexity is to keep processing in Australia. osFoundry’s managed cloud pins data to the US, EU or Japan — it does not currently offer an Australian managed region. For data that must stay in Australia, the honest path is self-hosting osFoundry (BYO Cloud) inside an Australian cloud region such as AWS (Sydney or Melbourne), Microsoft Azure (Australia East, Australia Southeast or Australia Central in Canberra) or Google Cloud (Sydney or Melbourne), or running models locally on-device. Running models in an Australian region or locally removes the overseas-disclosure question for those workloads.

Where dgm fits

dgm is an independent integration partner that helps Australian businesses adopt osFoundry — scoping a first use case, handling the build, and connecting AI to the systems you already run. dgm is independent of osFoundry’s maker (OS LLC) and has no completed client integrations yet, so everything described here is a service offered, not a past result. If you want to scope a practical first project, dgm can help you map it out.