Who this reaches
Accredited persons, accredited data recipients, data holders, and outsourced service-provider arrangements handling CDR data under the CDR framework.
What the rule requires
Privacy Safeguard 8 restricts overseas disclosure of CDR data unless an exception applies. CDR outsourcing arrangements also bring specific consent, use, disclosure, security, deletion, and chain-of-provider requirements.
What changes when the email path is regional
A Sydney email plane may remove an unnecessary overseas messaging provider from a CDR-adjacent notification workflow and make the remaining outsourcing chain easier to enumerate.
What your team still owns
Boundry does not claim CDR accreditation or that every use of its API forms a compliant CDR outsourcing arrangement. Do not send CDR data until the role, contract, consent, disclosure, and deletion design is reviewed.
Read the primary sources
This is an engineering and vendor-evaluation guide, not legal advice. Confirm the current rule for your entity, contract, and workload from the primary source.