Skip to main content

What are you looking for?

Explore our services and discover how we can help you achieve your goals

Australia software delivery: keep privacy accountability and the afternoon handover in your hands

An Australian organisation that uses an overseas delivery team usually stays accountable for how that team handles personal information. So scope three things first: what personal data the team may see, how a suspected breach reaches you within hours, and a daily handover that fits the three to four hours between Sydney and Hanoi.

Submit a project Explore custom engineering

Reviewed by David Nguyen (CEO) · Updated 28 Sep 2026 · 10 min read

star

OutsourcingVN is operated by Netbase JSC, so this guide is written by a supplier that sells to Australian buyers. It draws on an online designer installed for a Melbourne printer and on the Office of the Australian Information Commissioner's guidance, which your privacy adviser should read. The guides index lists the other market guides.

Contents

What changes for an Australian buyer?

Australian software buyers ask the same engineering questions as anyone else. Three local questions shape the delivery plan.

  • The Australian Privacy Principles. The OAIC describes 13 principles that govern how organisations and agencies covered by the Privacy Act 1988 handle personal information, including APP 11 on keeping it secure. Whether your organisation is covered, and which exceptions apply, is for your adviser.
  • Cross-border disclosure. The OAIC's APP 8 guidelines explain that an organisation disclosing personal information to an overseas recipient generally has to take reasonable steps to make sure the recipient does not breach the principles, and can remain accountable for the recipient's handling. An offshore development or support team that can see customer records is a design decision, not a detail.
  • Notifiable data breaches. Under the Notifiable Data Breaches scheme, a covered organisation must notify affected individuals and the OAIC when a data breach is likely to result in serious harm. Your supplier's role is to tell you quickly and give you the facts to assess it.

Netbase serves clients in the United States, Europe and Asia-Pacific, and Australian work is planned around these three questions from discovery.

What did an Australian online-designer installation show?

The closest published example is Indieprint, a Melbourne digital paper and apparel printer that installed the Netbase WooCommerce online designer on two domains. Indieprint's design errors fell 28% and its production turnaround improved 15%. These are single values from one printer's own operation, published without a period.

The practical point for Australian buyers is where the data sits. An online designer collects customer uploads, names, delivery addresses and order notes, and each store domain holds its own copy. Before an overseas team configures or supports stores like these, decide which of those records it needs to see at all.

A related store is PrintLeo, an e-commerce and advertising company that runs the CMSmart WordPress Printshop package with its online design plugin, delivered by Netbase. The PrintLeo print store record lists the results PrintLeo reported, and the product personalisation and online design solution describes the workflow behind both stores.

How should an overseas team access personal information?

Choose one row per environment with your privacy adviser, and write the choice into the contract and the access matrix.

Access model What the overseas team sees Fits when What you must add
No personal data Code, configuration and synthetic or anonymised test data only Build phases and most feature work A rule for how test data is produced, and who checks it
Masked production support Production logs and records with names, contacts and addresses masked Routine support and performance work Masking tested in acceptance, and a list of fields that stay visible
Named, logged production access Full records, for named people and named tasks only Incident response and data fixes that need real records Time-limited access, an access log you can review and contract terms that meet APP 8
Australian-only operations Nothing in production; an Australian team or your own staff operate it Highly sensitive data or strict customer commitments A handover procedure and support runbooks the local operators can follow

Most projects mix rows: no personal data during the build, masked support after launch and named access only in incidents. Netbase security practices include secure code review and version control, role-based access control, MFA for admin dashboards, contributors under NDA, and NDAs and DPAs on request. The data security and compliance guide lists the wider controls to request.

How do you set up a handover that fits the time zones?

Sydney and Melbourne are three hours ahead of Hanoi in Australian standard time and four hours ahead during daylight saving, roughly October to April. Brisbane does not change its clocks, and Perth is one hour ahead of Hanoi all year.

  1. Use the Australian afternoon as the shared window

    Hanoi's working day covers most of the Australian east-coast afternoon, so hold reviews and decisions there.

  2. Send morning instructions the night before

    A Hanoi morning is already late morning in Sydney, so priorities written at the end of the Australian day are ready when the team starts.

  3. Close each Hanoi day with a written handover

    It should list what was deployed to staging, what needs Australian acceptance and any blocker, and arrive in the Australian evening.

  4. Agree incident hours in writing

    Name who answers a production alert outside shared hours, on both sides, and how fast.

  5. Accept in increments

    Test each release in staging against written criteria during the shared window, using the software acceptance criteria guide as the template.

The time-zone collaboration guide covers overlap windows for other regions.

Worked scenario: customer artwork exposed by a storage setting

A Brisbane print business runs two store domains with an online designer. During routine support, a developer on the overseas team notices that a storage folder holding customer uploads is readable without signing in. Some files include delivery labels with names and addresses.

The contract sets out what happens next. The developer blocks public access and records the time, and the delivery lead notifies the business's named privacy contact within the agreed hours, with the folder path, the file count, the exposure window taken from access logs, and whether any file was downloaded from outside.

The business, not the supplier, assesses whether the incident is likely to result in serious harm and whether it must notify customers and the OAIC. Because the team works under a masked-support model, nobody needed to open the files to answer those questions; the logs and metadata were enough. The fix and a check across both domains are then accepted like any other release.

Without an agreed notice time and a named contact, the same discovery can sit in a chat thread until the next scheduled call.

Which questions should you ask a supplier?

  • Access. Which access model do you propose for build, support and incidents, and who holds production credentials?
  • Overseas handling. What contract terms will you sign so that our APP 8 obligations are met, and how can we review your access logs?
  • Breach notice. How soon after discovering a suspected breach do you tell us, and what facts come with the notice?
  • Rhythm. Which shared window do you propose for our city, and how does it change when daylight saving starts or ends?
  • Exit. How are credentials, documentation and operations handed back if we move support to an Australian team? The handover and exit guide covers the checklist.

What usually goes wrong?

  • Production copies in test environments. Signal: real customer names appear in screenshots or staging data. Owner: the technical lead, with an anonymisation rule.
  • No named privacy contact. Signal: a supplier's notice goes to a general inbox. Owner: the business sponsor.
  • Daylight-saving surprises. Signal: meetings drift by an hour twice a year. Owner: whoever runs the calendar, with times set in both zones.
  • Stores configured differently. Signal: a fix on one domain misses the other. Owner: the product owner, with one release checklist for every domain.

How this guide is sourced and where it stops

This guide uses three OAIC pages, on the Australian Privacy Principles, the APP 8 guidelines and the Notifiable Data Breaches scheme, accessed on 2026-09-29, together with Netbase delivery records and company statements approved in the OutsourcingVN claim register. It is written for product, technology, operations and procurement leads preparing an Australian brief. It does not decide whether the Privacy Act covers your organisation; your adviser does. Netbase JSC's head office is in Hanoi, Vietnam, and it is the company's only office, so Australian projects are delivered remotely, and Netbase delivery communication is in English.

Plan the next step for your project

Common questions

It covers Australian Government agencies and many organisations, with exceptions such as some small businesses. Your privacy adviser should confirm your position before discovery ends, because the answer shapes the access model and the contract.

Yes, when access is designed rather than assumed. Masked support covers most routine work, named and logged access covers incidents, and contract terms address your cross-border obligations. Write the model into the access matrix and test the masking during acceptance.

On the east coast, most of the Australian afternoon: about six business hours in standard time and about five during daylight saving. Perth shares almost the whole day. Plan reviews in the shared window and written hand-offs outside it.

Your organisation, if the breach is notifiable. The supplier's job is to tell you quickly, contain the problem and give you the facts you need to assess harm. Agree the notice time, the contact and the facts included before launch.

The engineering method is shared, but the laws and identity services differ. The Singapore guide covers phased redevelopment and Myinfo data, and the UK guide covers assurance packs and accessibility duties.

Plan the first release

Bring your store or product domains, the personal data they hold, your preferred shared window and the names of your privacy, product and operations owners. Custom Product Engineering is the service for a bounded build, global delivery explains how remote delivery is organised, and the methodology shows how the statements here are recorded. OutsourcingVN is Netbase's own outsourcing-services platform: submit a project with your city and access requirements, and a person will reply with a proposed handover rhythm and the discovery questions to answer first.

Custom product engineering for a bounded release outcome Custom product engineering for a bounded release outcome

One defined release of your product, built to named outcomes and handed over with acceptance evidence.

Learn More
line

Tell us what you want to build or automate.

Submit a project