Onshore by default for Australian AI
A Sydney region alone does not keep your data under Australian law.
Thomas
Founder · Forward-Deployed Engineer
“The cloud is everywhere, so it doesn’t matter where the data lives.” The line is comforting and wrong: the cloud is data centres, buildings with owners and addresses, and both the owner and the address come with laws attached. Ship Australian data into an AI system and you have chosen which jurisdictions can reach for it, whether or not anyone in the room noticed the choice being made.
We build the production half of AI, the part that still has to work when users pile in and an auditor asks for evidence. In that work, where the data lives keeps turning out to be an architectural decision with legal consequences, the kind that cannot be bolted on at the end.
What residency leaves out
Residency and sovereignty get used interchangeably, and they name different things. Data residency is the physical or geographical location where data is stored and processed. Data sovereignty is the principle that data is subject to the laws of the jurisdiction in which it is physically stored.1
You can satisfy a residency requirement (“keep the bytes in Australia”) and still hand a foreign government legal reach over those bytes. When a vendor promises residency and says nothing about sovereignty, ask the second question: who can lawfully compel them to produce this data?
“Keep the bytes in Australia” says nothing about who can order them produced.
The Australian legal reality
Start with the Privacy Act 1988 and the Australian Privacy Principles. APP 8 governs what happens when personal information leaves the country. Before an APP entity discloses personal information about an individual to an overseas recipient (someone not in Australia, who is neither the entity nor the individual), the entity must take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the APPs (other than APP 1) in relation to the information.2
On a first read, APP 8 looks like a due-diligence requirement. Section 16C of the Privacy Act makes it an accountability regime: an act or practice of the overseas recipient that would breach the APPs is taken to have been done by the disclosing Australian entity, and to be a breach by that entity.3 If the vendor mishandles the information over there, the Act treats the mishandling as yours.
There are exceptions. APP 8.1 does not apply where you reasonably believe the recipient is subject to a law or binding scheme that protects the information in a substantially similar way to the APPs, with accessible enforcement mechanisms, or where the individual consents after being expressly told that APP 8.1 will not apply.4 Both exceptions are real, and both are narrow. Use them deliberately, with advice, and write the basis down. “The cheapest model endpoint happens to live in another country” is not one of them.
The regime is also getting sharper. The Privacy and Other Legislation Amendment Act 2024, the first tranche of reform, passed Parliament on 29 November 2024 and received Royal Assent on 10 December 2024. It introduced a statutory tort for serious invasions of privacy, a Children’s Online Privacy Code, and automated-decision transparency requirements, and it expanded the OAIC’s enforcement powers with new civil penalty tiers and infringement notices.5
And there is a clock running underneath all of it. Under the Notifiable Data Breaches scheme, any organisation covered by the Privacy Act must notify affected individuals and the OAIC when a breach is likely to result in serious harm;6 entities generally have a maximum of 30 days to assess whether a breach is an eligible one and must notify as soon as practicable once they have reasonable grounds to believe it has occurred.7 When something goes wrong across a border, you will be assessing harm and drafting notifications on a deadline, for data you no longer control.
The sovereignty trap
The part the residency brochures skip is the operator. Keeping data in an Australian data centre does not put it beyond foreign legal reach if that operator is US-linked.
The US CLOUD Act, passed in 2018, gives US law enforcement the power to compel a US-based provider of electronic communication or remote computing services to disclose data in its possession, custody, or control, regardless of whether that data is stored inside or outside the United States. It applies to all such providers that operate or have a legal presence in the US.8 The trigger is the provider’s legal nexus to the US, and the location of the bytes plays no part in it.
Independent analysis is blunt about it: the legal obligations of a provider with possession, custody, or control of the data remain the same regardless of whether that data sits within or outside the United States.9 So a workload can run in a Sydney region, owned by a US parent, with every residency clause in the contract honoured, and still be subject to compelled disclosure under US process.
The CLOUD Act’s test is possession, custody, or control, with no mention of where the data is stored.
None of this requires bad faith from any provider; compelled disclosure runs on ordinary legal process, served on whoever holds the levers. A threat model that includes foreign governments but leaves out the operator’s ownership chain is missing an entry.
Where the law just says no
In some sectors Parliament has removed the choice entirely. Section 77 of the My Health Records Act 2012 is titled, with no ambiguity, “Requirement not to hold or take records outside Australia”. It prohibits the System Operator, registered repository operators, registered portal operators and registered contracted service providers from holding or taking My Health Record records outside Australia, or processing or handling the related information outside Australia, where it includes a healthcare recipient’s personal or identifying information. The penalty is up to 5 years imprisonment or 300 penalty units, with a civil penalty of 1,500 penalty units.10
Holding is the obvious prohibition, and the section also reaches processing and handling. An AI pipeline that sends a prompt containing such information to an offshore inference endpoint is processing it outside Australia, whether or not the model stores a byte of it. In connected health, the diagram that shows where inference runs doubles as a map of criminal exposure.
Onshore by default
“Onshore by default” means the in-country path is the one you get without asking, and an offshore hop is an exception someone has to argue for in writing. Most AI stacks get assembled the other way around: the model endpoint gets chosen first, and the contract is asked afterwards to say something reassuring about where the data goes.
Concretely, that starts with the region. AWS operates the Asia Pacific (Sydney) Region, region code ap-southeast-2, located in Australia with three Availability Zones, and it is one of the Regions enabled by default for AWS accounts.11 That gives us a genuine in-country home for storage and processing. On its own the region does not answer the CLOUD Act problem from the previous section, so we pair it with de-identification, tight data minimisation, and row-level isolation. By the time anything crosses a border, it is the least sensitive form of the data that can still do the job.
Posture gets the same treatment. We build against the Australian baselines rather than discovering them during an audit:
- 01
Essential Eight. The ASD’s baseline of eight mitigation strategies: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups. ASD grades it against Maturity Levels Zero to Three and treats it as the cyber security baseline for organisations.12
- 02
IRAP alignment. The Infosec Registered Assessors Program is the ASD program of endorsed, independent assessors who evaluate a system’s cyber security posture against the ASD Information Security Manual, identifying risks and suggesting mitigations. It is the yardstick government and regulated cloud workloads are measured against.13
- 03
Onshore residency. Data stored and processed in ap-southeast-2 by default, with offshore movement requiring an explicit, documented decision and an APP 8 basis.
The defaults do not slow the build. Skipping them moves the findings later: into a security review a fortnight before launch, or years afterwards into a letter from the OAIC, at which point the fix means retrofitting sovereignty onto a system that already leaks across borders. Doing it from the first commit is cheaper.
When we leave, the client owns a governed system they run themselves: in-country, isolated, and documented. If a reviewer asks whose law can reach the data, the answer is already on file, down to the region (ap-southeast-2) and the documented APP 8 basis for anything that leaves the country.
References
- 01Splunk, “Data Sovereignty vs. Data Residency: What’s The Difference?” Link ↗ ↩
- 02Office of the Australian Information Commissioner, “Read the Australian Privacy Principles” (APP 8.1). Link ↗ ↩
- 03Office of the Australian Information Commissioner, “Chapter 8: APP 8 — Cross-border disclosure of personal information” (APP Guidelines; Privacy Act 1988 s16C). Link ↗ ↩
- 04Office of the Australian Information Commissioner, “Read the Australian Privacy Principles” (APP 8.2 exceptions). Link ↗ ↩
- 05Office of the Australian Information Commissioner, “Passing of bill a significant step for Australia’s privacy law” (Privacy and Other Legislation Amendment Act 2024, C2024A00128). Link ↗ ↩
- 06Office of the Australian Information Commissioner, “About the Notifiable Data Breaches scheme.” Link ↗ ↩
- 07Office of the Australian Information Commissioner, “Part 4: Notifiable Data Breach (NDB) Scheme” — Data breach preparation and response (Privacy Act 1988 ss 26WH, 26WK, 26WL; 30 calendar-day maximum assessment period under s 26WH(2) and “as soon as practicable” notification once there are reasonable grounds to believe an eligible data breach has occurred). Link ↗ ↩
- 08Amazon Web Services, “Clarifying Lawful Overseas Use of Data (CLOUD) Act.” Link ↗ ↩
- 09Cross-Border Data Forum, “Frequently Asked Questions about the U.S. CLOUD Act.” Link ↗ ↩
- 10My Health Records Act 2012 (Cth) s 77, “Requirement not to hold or take records outside Australia,” Federal Register of Legislation (compilation in force). Link ↗ ↩
- 11Amazon Web Services, “AWS Regions and Availability Zones” (ap-southeast-2, Asia Pacific (Sydney)). Link ↗ ↩
- 12Australian Signals Directorate, “Essential Eight” and “Essential Eight maturity model” (Cyber.gov.au). Link ↗ ↩
- 13Australian Signals Directorate, “Infosec Registered Assessors Program (IRAP)” (Cyber.gov.au). Link ↗ ↩
Read next
De-identification gates
How we let teams build on real data without ever touching what makes it risky.
AI that never leaves the building
Open weights caught up. A frontier-class model now ships under MIT, and a capable one runs on a single workstation GPU. For clients whose data cannot leave the premises, that changes the answer. This is the anatomy of a build where the network cable is optional.