Back to BlogHiring & Outsourcing

Hiring an Offshore Dev Team from Australia: APP 8, Contracts and Overlap

Rupak Amin

Founder & Lead Engineer, RAITHub

12 min read

An Australian business can hire an offshore development team in Bangladesh, but if the team will access customers' personal information, APP 8 of the Privacy Act 1988 requires you to take reasonable steps, usually a contract, so the team does not breach the APPs, and s16C can leave you accountable for its mistakes. Sydney shares about 5 working hours with Dhaka, 4 during daylight saving.

This guide is for founders, CTOs and operations leads in Australia weighing an offshore team. RAITHub is a software studio in Dhaka, so we have an interest in the answer; we are an offshore team, several time zones from you, and we have no office in Australia. This is general information, not legal advice. Confirm every point with your privacy adviser and the Office of the Australian Information Commissioner (OAIC) before you sign.

Does APP 8 apply when I hire an offshore developer?

It applies when two things are true: your business is covered by the Privacy Act, and you disclose personal information to the offshore team. APP 8.1 says that before disclosing personal information to an overseas recipient, you must take "such steps as are reasonable in the circumstances" to ensure the recipient does not breach the Australian Privacy Principles (OAIC APP guidelines, chapter 8).

Is your business covered? Many small businesses are not. The OAIC defines a small business as one with an annual turnover of A$3 million or less, and most are exempt, but some are covered regardless of turnover, including health service providers, businesses that trade in personal information, and operators of a residential tenancy database (OAIC: small business). A PropTech startup should check that last one carefully. Even if you are exempt today, your enterprise customers usually are not, and they will ask you the APP 8 questions in their security questionnaire.

Is it a disclosure or a use? The OAIC describes a disclosure as making information accessible outside your entity and releasing its later handling from your "effective control" (guidelines, 8.8). Giving information to an overseas contractor to perform services for you is generally a disclosure (8.12 to 8.13). The guidelines give one narrower case, cloud storage, where a binding contract limits the provider to storing the data and giving you access, and keeps you in effective control; that may be a use instead (8.14). A development team that works on your data is closer to the contractor case than to storage. Where your particular set-up falls is a question for your adviser.

What does s16C mean if the offshore team makes a mistake?

Section 16C makes you accountable for an overseas recipient's acts that would breach the APPs. The OAIC's guidance says this accountability can apply even where you took reasonable steps and the recipient later does something that would breach them (guidelines, 8.62). In plain terms: a contract is necessary, but it does not transfer the risk away from you.

That changes what you should look for in a vendor. The question is not only "will they sign our clauses?" but "is their day-to-day practice designed so that a breach is unlikely?" Signed paper plus weak habits still leaves you exposed.

Are there exceptions to APP 8 for an offshore team?

APP 8.2 lists exceptions, and the two that come up in vendor conversations rarely fit a development engagement.

  • A "substantially similar" law. If you reasonably believe the recipient is bound by a law or binding scheme substantially similar to the APPs, with accessible enforcement, APP 8.1 does not apply (8.20). Do not assume this for Bangladesh. Its data protection framework is new, and whether it meets the test is a legal judgement; confirm the current position with your adviser.
  • Consent. You can disclose with an individual's consent after expressly telling them APP 8.1 will not apply (8.31). For a product with thousands of users, collecting that consent from each person is rarely practical.

For most Australian companies hiring a development vendor, the realistic route is APP 8.1: reasonable steps, backed by a contract and by an architecture that limits what the team can see.

Which contract clauses should an Australian company ask an offshore team for?

The OAIC says you should generally have an enforceable contract requiring the overseas recipient to handle the information in accordance with the APPs, and lists what it might cover: the types of information and purposes, APP obligations including for subcontractors, complaint handling, and a data breach response plan with notification (guidelines, 8.16). The table maps those points, plus the commercial clauses a software engagement needs, to what you should ask a vendor for.

ClauseSource of the requirementWhat to ask the vendor for
Types of information and purposesOAIC guidelines 8.16A written scope: which systems, which data fields, for which tasks
Handle information in line with the APPsOAIC guidelines 8.16An express obligation, plus APP 11-style security measures listed in a schedule
Subcontractors bound by the same termsOAIC guidelines 8.16A named list of subcontractors, and your approval before any change
Complaint handlingOAIC guidelines 8.16A named contact and a response time for privacy queries you pass on
Breach response and notificationOAIC guidelines 8.16; the Notifiable Data Breaches schemeA duty to tell you of a suspected breach within an agreed number of hours, with the facts you need to assess it
Return or deletion at the endGood practiceA written deletion confirmation in the offboarding checklist
IP assignment and confidentialityCommercialFull assignment of all code and documents to your company, and an NDA
Audit and informationGood practiceWillingness to answer questionnaires and show evidence of controls

Under the Notifiable Data Breaches scheme, organisations must notify affected individuals and the OAIC when a data breach is likely to result in serious harm (OAIC: about the NDB scheme). You cannot meet that duty if your vendor tells you late, so the notification window in the contract matters more than most other clauses. For the IP side, the offshore IP assignment checklist is written for US founders, but the repository and assignment steps apply in Australia too; ask your lawyer about the Australian wording.

Can I keep personal information in Australia and still use an offshore team?

Yes, and it is usually the most effective step you have, because it shrinks what the team can see in the first place. The design is simple: code travels, customers do not.

  • Production stays in an Australian region in your own cloud account. AWS runs Asia Pacific (Sydney), ap-southeast-2, and Asia Pacific (Melbourne), ap-southeast-4 (AWS Regions). The account, billing and root credentials are yours.
  • Synthetic data in development and staging. Generated test records with realistic shape and no real people behind them.
  • Deploys through your CI pipeline. The team merges reviewed code; your pipeline deploys it. Human access to production is an exception, time-limited, approved and logged.
  • Access through your identity provider, with multi-factor authentication, so you can switch off every account in one place.
  • No production exports on laptops, written into the contract.

A small guard in the seed script stops the most common accident, synthetic data or a destructive reset pointed at the wrong database:

// scripts/seed.ts: synthetic data goes to dev and staging only.
const ALLOWED_HOSTS = ['localhost', 'staging-db.internal']

const host = new URL(process.env.DATABASE_URL ?? 'postgres://unset').hostname

if (!ALLOWED_HOSTS.includes(host)) {
  throw new Error('Refusing to seed ' + host + ': not a dev or staging database')
}

None of this makes the legal question disappear if the team ever needs production access, for example to debug a live incident. It does make that access rare, visible and easy to describe in your privacy policy and your customers' questionnaires. Answering your first security questionnaire without SOC 2 shows how to describe these controls honestly.

How many working hours do Sydney, Brisbane and Perth share with Dhaka?

Dhaka is on UTC+6 and does not change its clocks. Australia's eastern states do, from 4 October 2026 to 4 April 2027, while Queensland, Western Australia and the Northern Territory do not (NSW Government: daylight saving). With both sides working 9:00 to 18:00:

CityDhaka is behind byShared hoursWindow in local timeWindow in Dhaka time
Sydney or Melbourne (AEST, UTC+10)4 hours513:00–18:0009:00–14:00
Sydney or Melbourne (AEDT, UTC+11)5 hours414:00–18:0009:00–13:00
Brisbane (AEST all year)4 hours513:00–18:0009:00–14:00
Perth (AWST, UTC+8)2 hours711:00–18:0009:00–16:00

So the shared window is the Australian afternoon, and the Dhaka working day ends at 18:00 Dhaka time, which is 22:00 or 23:00 in Sydney. The practical rhythm: raise questions in the Sydney afternoon, get answers and working code the next morning, with written daily handoffs in between. RAITHub agrees the working week with each client; it is not fixed. If your team needs someone available through the whole Sydney morning, an onshore vendor or a Perth-based one is the better fit.

Should I hire a fixed-scope team or a dedicated monthly team?

Fixed scope for a defined release, a dedicated team for an open-ended roadmap. The privacy work is the same either way: a contract, a data map and an architecture that keeps personal information in your account. Dedicated team vs fixed price explains the commercial difference, and how to check a Bangladesh software agency gives the due-diligence questions to ask before either.

Why RAITHub for an Australian company?

  • We design so the data stays with you. Production in your Australian cloud account, synthetic data in development, deploys through your pipeline. That is the default, not an upsell.
  • We sign your paperwork. RAITHub signs data processing terms, your APP clauses and an NDA, fills in security schedules with real measures, and follows your controls. We make no certification or conformity claims; whether your arrangement meets APP 8 is a judgement for you and your adviser.
  • Tested money and data paths. PropDesk, the property management platform RAITHub built, collects rent through Stripe and runs 1,024 automated tests; Sundor Skin enforces row-level security across 146 PostgreSQL tables with 530+ tests.
  • Clear terms. Fixed-scope projects or a dedicated monthly team, a free 15-minute technical audit, then a fixed written quote. You own the IP. See SaaS development for what a build includes.

When you don't need us

  • Your procurement requires SOC 2 or ISO 27001. RAITHub holds neither.
  • Personal information must never be accessible from outside Australia, even for incident debugging. Choose an onshore vendor.
  • You want developers placed in your team under your management. RAITHub does not offer staff augmentation.
  • You need a full Sydney business day of overlap, or someone on site. RAITHub has no Australian office.
  • The work is a native mobile app. RAITHub builds web applications, not native iOS or Android apps.

Sources checked on 30 September 2026. General information only; confirm with your privacy adviser and the OAIC.

If none of those rule us out, book the free 15-minute technical audit. Bring your data map, or a list of the personal information your product holds, and we will tell you on the call what the team would and would not need to see.

Frequently asked questions

Can an offshore developer handle Australian customer data under APP 8?

Yes, if you take reasonable steps first. APP 8.1 requires reasonable steps, usually an enforceable contract, to ensure the overseas recipient does not breach the APPs. Under s16C you can remain accountable for the recipient's breaches, so architecture that limits access matters as much as the contract. Confirm the details with your adviser.

Does APP 8 apply to small businesses?

Most businesses with annual turnover of A$3 million or less are exempt from the Privacy Act, but some are covered regardless, including health service providers and operators of a residential tenancy database. Check the OAIC's small business guidance, and remember your larger customers will usually expect APP-level handling anyway.

What is section 16C of the Privacy Act?

Section 16C makes an Australian entity accountable for an overseas recipient's acts that would breach the APPs, after it discloses personal information to that recipient. The OAIC notes this can apply even where reasonable steps were taken, which is why contracts alone are not enough.

Is giving an offshore team access to our database a disclosure?

Often, yes. The OAIC treats providing information to an overseas contractor to perform services as generally a disclosure, with a narrower storage-only cloud case that may be a use. Keeping production data in your Australian account, with synthetic data in development, reduces what the team ever sees.

Which Australian cloud regions keep data onshore?

AWS runs Asia Pacific (Sydney), ap-southeast-2, and Asia Pacific (Melbourne), ap-southeast-4. Keep the account in your company's name so you control billing, root credentials and access.

How many hours overlap between Sydney and Dhaka?

About 5 working hours during Australian Eastern Standard Time and 4 during daylight saving, on a 9:00 to 18:00 day at both ends. Brisbane shares about 5 hours all year and Perth about 7.

Is RAITHub certified to SOC 2 or ISO 27001?

No. RAITHub signs your contract clauses and NDAs, follows your controls and answers security questionnaires with evidence, but holds neither certification. If your procurement requires one, choose a certified vendor.

offshore software development AustraliaAPP 8Privacy Act 1988section 16Ccross-border disclosureoffshore development contractBangladesh software team

Ready to discuss your project?

Book a free 15-minute technical audit with our engineering team.