What Australian and NZ privacy law says about uploading your documents online
Most people think of privacy law as something that matters during a big data breach, not when they're merging two PDFs before lunch. But the moment a document containing someone's name, address, signature or account details leaves your device, you may have triggered obligations under the Privacy Act 1988 or New Zealand's Privacy Act 2020, whether or not you meant to. This is a plain-language walk-through of what actually applies, aimed at people who aren't lawyers, not a substitute for advice from one.
What counts as "personal information" in a document
Both countries define it broadly. Australia's Privacy Act 1988 covers any information about an identified or reasonably identifiable individual. New Zealand's Privacy Act 2020 uses almost identical wording. In practice, that covers most of what a normal business document contains: a client's name and address, a signature, a phone number, a bank account or tax file number, medical or employment detail. A single scanned tenancy application or client intake form can easily contain half a dozen categories of personal information at once.
Australia: the Privacy Act and the Australian Privacy Principles
The Privacy Act 1988 is enforced through 13 Australian Privacy Principles (APPs), overseen by the Office of the Australian Information Commissioner (OAIC). The one that matters most for online tools is APP 8, cross-border disclosure. Before an organisation discloses personal information to someone overseas, including an overseas server that a tool uploads a file to, it generally has to take reasonable steps to ensure that recipient doesn't breach the APPs, or fall back on the specific exceptions the Act allows. Uploading a client's document to a PDF tool hosted on a server outside Australia can count as exactly that kind of disclosure, even if nobody at the company ever opens the file.
There's an important carve-out: businesses with annual turnover of AU$3 million or less are generally exempt from the Privacy Act, unless they fall into an excluded category such as health service providers or businesses that trade in personal information. If that exemption applies to you, the Act itself doesn't bind you, though reform proposals to narrow or remove the small business exemption have been under discussion for several years, so it's worth checking current guidance rather than assuming it always will.
New Zealand: the Privacy Act 2020
New Zealand's equivalent is built around 13 Information Privacy Principles (IPPs). IPP 12 covers disclosure of personal information outside New Zealand, and works on a similar logic to Australia's APP 8: an agency generally needs to be satisfied the overseas recipient is subject to comparable privacy safeguards, or that a specific exception applies, before sending personal information offshore. The notable difference from Australia is that New Zealand's Privacy Act 2020 has no small business exemption. It applies to every agency that holds personal information, a sole trader with one client file is covered the same as a large company.
Why this catches more people than expect it to
A bookkeeper merging a client's monthly bank statements. A property manager redacting a tenant's driver's licence number before forwarding an application. A small law firm splitting a signed contract bundle into individual exhibits. None of these feel like "data disclosure" in the way a headline-making breach does, but if the tool doing the work uploads the file to a server, and that server sits overseas, it can be exactly the kind of cross-border disclosure APP 8 and IPP 12 are about. Most people reach for whichever tool shows up first in search results and never check where it actually processes the file.
Where processing happens is the whole question
This is a technical point, not a legal one, but it's the one that makes the legal question disappear: if a file never leaves your device, there's no disclosure to assess in the first place. Every tool on this site, from redacting a PDF to merging several into one, runs entirely in your browser tab using your device's own memory. Nothing is uploaded, so there's no overseas server in the picture to worry about under APP 8 or IPP 12. It doesn't remove your other privacy obligations, how you store and eventually delete the file is still on you, but it takes the cross-border upload question off the table entirely.
Process a document without it leaving your device
Browse the toolsFrequently asked questions
Does privacy law apply to me if I'm a sole trader or freelancer?
In Australia, it depends on turnover: businesses with annual turnover of AU$3 million or less are generally exempt from the Privacy Act, unless they're in a category that's excluded from the exemption, such as health service providers or businesses that trade in personal information. In New Zealand, the Privacy Act 2020 has no small business exemption, it applies to every organisation that holds personal information, regardless of size.
Is it illegal to use a free online PDF tool under privacy law?
Not automatically, no. Using a tool that uploads a file containing personal information isn't itself an offence, but if it counts as a disclosure of personal information overseas, it can trigger obligations under APP 8 in Australia or IPP 12 in New Zealand, obligations that are easy to miss if you haven't checked where the tool actually processes your file.
Is this article legal advice?
No. It's a general explanation of how these laws work, written for people who aren't lawyers. If you handle other people's personal information as part of your work and you're unsure of your specific obligations, it's worth a conversation with a privacy professional or the OAIC/Office of the Privacy Commissioner directly.
Related guides
- Is it safe to use free online PDF tools?
- Why you should share less personal information online
- How different industries across Australia and New Zealand use PDF tools