If a client or an insurer asks where your data lives, the honest answer for most Australian businesses is: the files sit in an Australian data centre, the company that runs it is American, and the people who administer it could be anywhere. Those three facts are separate questions, and most providers answer only the first one and call it sovereignty. Getting the distinction right matters, because the Privacy Act holds you responsible for what happens to personal information after it leaves your hands.
Data residency is where your data is physically stored. Data sovereignty is whose laws apply to it. Jurisdiction is which courts and agencies can compel its production. A data centre in Sydney settles residency. It does not settle the other two.
Residency, sovereignty and jurisdiction are three different questions
Residency is a fact about geography. Microsoft or Google can tell you which metropolitan area holds your mailboxes and files, and both publish that information.
Sovereignty is a question about law. A US-headquartered provider remains subject to US law wherever its servers sit, and an Australian subsidiary does not change the parent company’s obligations. A local region does not create a legal firewall.
Jurisdiction is the practical version of the sovereignty question: who can lawfully order the data to be handed over, and under what process. That question is answered by the provider’s corporate structure and the contract, not by the postcode of the building.
Providers who blur these three are usually selling a data centre tour. Ask which of the three they are actually addressing.
APP 8 makes you accountable for what your overseas provider does
Australian Privacy Principle 8 governs cross-border disclosure. Before an APP entity discloses personal information to an overseas recipient, it must take such steps as are reasonable in the circumstances to ensure that the recipient does not breach the APPs. Section 16C then makes the disclosing entity accountable for acts or practices of the overseas recipient that would breach the APPs. In plain terms: if your offshore provider mishandles the information, you are treated as having breached the APPs yourself.
The OAIC’s expectation is that “reasonable steps” normally means an enforceable contract requiring the recipient to handle the information in accordance with the APPs, requiring the same terms to flow down to subcontractors, setting out complaint handling, and requiring the recipient to notify you of suspected breaches so you can meet your obligations under the Notifiable Data Breaches scheme.
There is an important wrinkle that changes the analysis for cloud storage. The OAIC’s APP Guidelines say that providing personal information to an overseas contractor may be a use rather than a disclosure where you do not release the information from your effective control. The example given is a cloud provider engaged for the limited purpose of storing the information and making it available to you, where a binding contract limits the provider to those purposes, binds subcontractors to the same obligations, and leaves you with effective control over access, security and deletion. In that case APP 8 does not apply.
That is not a free pass. The Guidelines are equally clear that where the arrangement is a use, you still hold the information, so you can still breach APP 11 and the other APPs if the provider mishandles it. You have changed which principle you are judged under, not whether you are responsible.
There are also two exceptions worth knowing. APP 8.2(a) applies where you reasonably believe the recipient is subject to a law or binding scheme substantially similar to the APPs with an accessible enforcement mechanism. APP 8.2(b) applies where the individual consents after being expressly told that if they consent, you will not be accountable and they will not be able to seek redress under the Privacy Act. Consent-based offshoring is legally available and commercially unattractive, because you have to say that sentence out loud to the customer.
Before any of this is workable you need to know what you actually hold. That is why we ask clients to classify your data first and to keep a documented record of where each system stores data. Without it, the APP 8 question cannot be answered honestly for any given system.
Microsoft 365 in Australia: what the commitment actually covers
Microsoft treats Australia as a Local Region Geography, with Microsoft 365 data centre locations in Melbourne and Sydney. For a tenant whose Default Geography is Australia, Microsoft’s Privacy and Security Product Terms provide a durable data residency commitment for Exchange Online, SharePoint and OneDrive, Microsoft Teams, and Microsoft 365 Copilot and Copilot Chat.
Four things about that commitment are routinely misunderstood.
The Default Geography is set when the Microsoft Entra ID tenant is created and cannot be changed afterwards. If someone signed your business up for a trial with the wrong country years ago, that decision is still governing your data location today.
The commitment covers a defined list of services, not everything with a Microsoft logo. Coverage for Microsoft Defender for Office P1, the Microsoft 365 web apps, Viva Connections and selected Microsoft Purview services requires the Advanced Data Residency add-on, which must be applied to 100 per cent of paid licences in the tenant. Services outside the covered list follow their own provisioning logic.
Where there is no durable commitment for a service, Microsoft’s own documentation states that the data is not committed to reside in any particular data centre and that the storage location is subject to change without notice.
Finally, Microsoft’s documentation notes that a customer request may be handled by servers in a region other than the one where the data is stored at rest. Processing paths and storage location are not the same thing.
On access, Microsoft states that engineers have no standing administrative privileges and no standing access to customer data, that any access is limited, logged and approved by senior management, and that customers licensed for Customer Lockbox also approve it themselves. That is a meaningful control and it is worth turning on. It is not the same as saying nobody outside Australia can ever see the data.
You can check your own position in the Microsoft 365 admin center under Settings, Org settings, Organization profile, Data location.
Google Workspace does not offer an Australian data region
This one surprises people, so state it plainly. Google Workspace data regions let an administrator pin covered data to the United States or to Europe. The third option is “No preference”. Australia is not a choice.
The coverage is otherwise reasonably good where it applies. Data regions cover data at rest, including backups, and data processing for core services including Gmail, Calendar, Drive, Docs, Chat, Meet, Contacts and Vault, subject to edition. Google’s documentation is explicit that data regions cannot be applied to data types not listed, such as logs or cached content, and that users on an unsupported edition are not covered even if a policy is applied to their organisational unit.
Google Cloud, which is a different product, does operate Australian regions. If a vendor tells you their Workspace data is held in Australia, they are either describing something built on Google Cloud rather than Workspace, or they have not read the documentation.
Storage is local. Support and administration usually are not.
This is the gap that catches businesses in a client security review. Your tenant can be pinned to Melbourne and your support model can still involve people outside Australia.
Three things to check. First, the vendor’s own support model: follow-the-sun support desks routinely mean an engineer in another country holds a privileged account in your tenant. Second, subcontractors: a vendor with an Australian front office and an offshore development or support partner has an APP 8 question of its own to answer, and the OAIC expects the obligations to flow down. Third, your own provider: if your MSP uses offshore staff for after-hours triage, that is a disclosure decision you have made whether or not you were told about it.
TechAssist runs an Australian team from our Tecoma head office and Melbourne CBD office, so this is an easy question for us to answer. The point is that it is a question you should be asking of every provider with administrative access, including the ones you have used for years.
Foreign government access, stated factually
The United States enacted the Clarifying Lawful Overseas Use of Data (CLOUD) Act in March 2018. It confirms that US providers can be compelled to produce data in their possession, custody or control regardless of where that data is stored, and it authorises bilateral agreements allowing partner countries to serve orders directly on US providers. The United States and Australia signed a CLOUD Act agreement on 15 December 2021.
Two things follow. Data stored in Sydney by a US-headquartered provider is still within reach of US legal process. And Australian agencies have their own compulsory powers, so the alternative is not an absence of government access, it is a different government’s access.
Both Microsoft and Google publish periodic transparency reports on government requests. If this risk is genuinely material to your business, read those rather than the marketing page, and treat customer-managed encryption keys and Customer Lockbox as the controls that actually change the analysis.
The trade-off is worth naming. Moving to a wholly Australian-owned provider removes the foreign jurisdiction exposure and usually costs you the security engineering, availability and feature velocity of a hyperscaler. For most SMBs that is a bad trade. For a defence supplier it may not be.
When sovereignty is a legal requirement, and when it is a procurement preference
Genuine legal requirements exist, and they are narrower than the sales conversation suggests. Commonwealth and state government contracts commonly impose hosting and data location conditions, and those are contractual obligations you can read. APRA-regulated entities have their own prudential standards on information security and outsourcing.
Health is the example everyone reaches for, and it is the one most often stated wrongly. There is a real Commonwealth localisation rule, and it is section 77 of the My Health Records Act 2012 (Cth). It provides that the System Operator, a registered repository operator, a registered portal operator or a registered contracted service provider that holds records for the purposes of the My Health Record system, or has access to information relating to those records, must not hold or take the records outside Australia, must not process or handle the information relating to those records outside Australia, and must not cause or permit another person to do either. The only carve-out is for the System Operator itself, for operating or administering the system, and only where the records and information contain no personal information about a healthcare recipient or participant and no identifying information. Contravention is a fault-based offence carrying imprisonment for 5 years or 300 penalty units or both, with a civil penalty of 1,500 penalty units.
Now read the list of who that binds, because that is the part clinics get wrong in both directions. Section 77 applies to the operators of the My Health Record system and their contracted service providers. It is not a rule that all Australian health data must stay onshore. A medical, dental or allied health practice is a registered healthcare provider organisation, and registered healthcare provider organisations are not in the section 77 list. So section 77 does not, by itself, prohibit a clinic from using an offshore-hosted practice management system for its own clinical records. If your software vendor or your hosting sits inside the My Health Record system as a repository, portal or contracted service provider, section 77 binds that role directly and you should ask them to say so in writing. If it does not, your offshore hosting question is answered by the Privacy Act, your state health records legislation and your contracts, not by section 77. Getting this backwards means either buying sovereignty you are not required to have, or assuming a protection that does not apply to you.
Everything else is usually a procurement preference: a large customer’s security questionnaire, an insurer’s checklist, or a board that would prefer the answer to be “Australia”. Preferences are legitimate, and they cost money. Meeting them can mean an Advanced Data Residency add-on, an edition upgrade, or leaving a product you otherwise like.
The Privacy Act itself does not require personal information to stay in Australia. It requires you to take reasonable steps and holds you accountable if the recipient mishandles it. A business under the $3 million small business turnover threshold in section 6D may be exempt from the Privacy Act altogether, though the exemptions are narrower than most owners assume. It is worth understanding what the Privacy Act asks of a small Australian business before deciding you are outside it.
Where privacy reform has actually got to
Do not build a data strategy on the small business exemption surviving, and do not assume the second tranche has already landed. Both mistakes are common.
The first tranche is law. The Privacy and Other Legislation Amendment Act 2024 passed Parliament on 29 November 2024 and progressed 23 proposals from the government’s response to the Privacy Act Review Report, including a framework for a Children’s Online Privacy Code. Two of its changes reach ordinary businesses. The statutory tort of serious invasion of privacy commenced on 10 June 2025, and the OAIC notes that it is broader in application than the Privacy Act, extending to individuals and entities that are not APP entities, which means it can reach a business the Privacy Act does not. Separately, from 10 December 2026, an APP entity that has arranged for a computer program to use personal information to make a decision that could reasonably be expected to significantly affect a person’s rights or interests must say so in its privacy policy, including the kinds of information used and the kinds of decisions made. The OAIC has consulted on guidance and said it intends to publish it before that date.
The second tranche is not law, and that is where the bigger changes sit, including removal of the small business exemption. At the time of writing the Attorney-General’s Department’s own privacy page still describes the work as developing draft provisions and engaging on the detail to inform the government’s decisions on next steps, and no second tranche Bill has passed. Treat the exemption as a temporary position, check the position again before you rely on it, and note that it was never a shield against the statutory tort, which does not depend on being an APP entity at all.
The questions to put to a SaaS vendor
Send these in writing and keep the answers with the contract.
- In which country is customer data stored at rest, and is that a contractual commitment or a current arrangement you may change?
- Which specific services or modules are covered by that commitment, and which are not?
- Where are backups, replicas, logs and cached content stored?
- From which countries can your staff and subcontractors access customer data, and under what approval process?
- Who are your sub-processors, where are they, and do your contracts require them to meet the same obligations?
- Under APP 8, do you regard your handling of our customers’ personal information as a use or a disclosure, and why?
- Will you notify us of a suspected data breach, within what timeframe, and in what form?
- On termination, how is our data returned and destroyed, and will you provide evidence that destruction occurred?
Question seven is the one that determines whether you can meet your obligations under the Notifiable Data Breaches scheme, which require you to notify the OAIC and affected individuals when a breach is likely to result in serious harm. Question eight is the one everyone forgets until an exit, and it connects directly to secure device disposal and the APP 11.2 obligation to destroy personal information you no longer need. If you want the configuration side handled properly as well, start with cloud security controls that matter for an SME.
If you are filling in a client security questionnaire or a cyber insurance form and cannot answer these questions about your own tenant, we can audit it and give you the documented answers. Call us on 1300 028 324 or get in touch at https://techassist.au/contact/. We will tell you where your data actually sits, not where you would like it to be.
