
Customer Data
Part of Marketing stack security and permissions
Checking how a vendor stores customer data
Check where a marketing vendor stores customer information and copies, who can access them, how recovery works and what happens at exit.
To check a vendor’s storage arrangement, follow the customer information the proposed workflow would send: where it goes, who can access it, what copies are made, how it is restored and what happens at exit. A named hosting region or a general security statement does not answer all of those questions.
Key Regulatory Sources for Data Storage Compliance in Australia
- OAIC – Security Guidance
- Guide to Securing Personal Information
- OAIC – APP 11 Guidelines
- Security of Personal Information
- OAIC – APP 8 Guidelines
- Cross-Border Disclosure of Personal Information
- Cyber.gov.au – Cloud Responsibility Model
- Shared responsibility guidance for SMEs and individuals
Define the proposed data flow
List the fields, files and events the service would receive via forms, imports, tracking, support or exports. Remove information the task does not need. Identify the proposed service, edition and configuration so you can check the vendor’s answer against the arrangement you would actually use.
Ask the vendor to distinguish its primary store from replicas, backups, logs and support copies. Establish where storage, processing, administration and supplier support may occur, and which subcontractors may handle the information and for what purpose. A region setting may cover only part of a service, so obtain its written scope.
Request evidence for each control
| Question | Evidence or clarification to request |
|---|---|
| Who can see the information? | Customer roles, supplier and subcontractor access, and approval controls |
| How is it protected? | Encryption scope, key responsibilities, logging and relevant assurance material |
| How can it be recovered? | Backup coverage, restoration route and who may request a restore |
| How long is it kept? | Retention and deletion rules for live records, logs and backups |
| What happens at exit? | Data return or export options, portability limits, and deletion arrangements for remaining copies |
| What happens during an incident? | Customer contact route, investigation support and written commitments |
Check who operates each control. The supplier may protect its infrastructure while your organisation controls users, configuration, exports or an optional backup. Read service documentation alongside the proposed contract. An assurance report is useful only to the extent that its scope covers the relevant service and controls.
Assess the Australian privacy boundary
Under the Australian Privacy Principles, APP 11 requires reasonable steps to protect personal information an entity holds. Outsourced storage can still leave the customer holding that information if it retains the right or power to deal with it. Ask the privacy owner to assess the proposed handling and any overseas recipient.
If information may be accessed or received overseas, ask the privacy owner to assess whether an overseas person receives personal information and whether APP 8 applies, including any relevant exceptions. Confirm where access may occur and who may receive the information. Check what purposes and rights to retrieve or delete it the arrangement sets out.
Australian Privacy Principles: APP 8 (Cross-Border Disclosure) vs. APP 11 (Security)
- APP 8 – Cross-Border DisclosureApplies if personal information is sent overseas; requires assessment of recipient's privacy practices and compliance with Australian standards.
- APP 11 – Security of Personal InformationRequires reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure.
Record the decision and its gaps
Place each vendor answer beside the document or demonstration supporting it, with its date and scope. Mark unanswered questions. An early assessment may use synthetic information while live customer-data use waits for material storage, access and privacy questions to be resolved. If a copy or deletion route remains unclear, make that gap an explicit decision condition.



