
Data Sovereignty in Australia: What SaaS Buyers Expect
Australian law does not generally require you to host data in Australia. There is no blanket data residency law for private businesses. What the Privacy Act does require, under APP 8, is that you take reasonable steps before disclosing personal information to an overseas recipient, and that you generally remain accountable for what that recipient does with it. Onshore hosting is usually a contract term your buyer asks for, not a legal obligation, and the two get confused constantly.

One clarification before going further. The phrase data sovereignty is also used in Australia for Indigenous Data Sovereignty, which concerns the rights of Aboriginal and Torres Strait Islander peoples over data about their communities. That is a distinct and important field with its own principles. This article is about the commercial question: where your customers’ data physically sits, and what you are obliged to do about it.
What is data sovereignty in Australia?
In a commercial context, data sovereignty is the idea that data is subject to the laws of the country in which it is physically stored. For an Australian business it usually comes up as a simpler question: is our customer data held in Australia, and if not, who can reach it? The concern behind the question is normally foreign government access, particularly under United States law, rather than the technical risk of a data centre in another country.
Data residency is the narrower term, and it is the one that actually appears in contracts. Data residency means the specific geographic location where data is stored. You can choose data residency by selecting an Australian region with your cloud provider. You cannot choose sovereignty in the same way, because a provider’s parent company may still be subject to its home jurisdiction.
Do Australian data sovereignty laws require onshore hosting?
No. There is no general Australian law requiring private sector businesses to store data within Australia. The Privacy Act regulates how you handle personal information, not where you keep it. APP 8 governs cross border disclosure and requires reasonable steps to ensure an overseas recipient does not breach the Australian Privacy Principles, with the sending entity generally remaining accountable for what the recipient does.
There are sector specific exceptions. My Health Record data has statutory restrictions on being held or taken outside Australia. Australian Government agencies are subject to hosting policy, including the Hosting Certification Framework, which limits which providers may host certain government data. Some state health and justice agencies apply their own rules. None of that applies to a typical Australian SaaS business selling to private companies.

The practical effect is that onshore hosting is a commercial requirement rather than a legal one for most Australian SaaS companies. Your enterprise buyer’s procurement template says Australian data residency, and that becomes your obligation the moment you sign. Our guide to answering vendor security questionnaires covers how to handle the question when the answer is not a simple yes.
What does APP 8 require before data leaves Australia?
APP 8 requires an entity to take reasonable steps to ensure an overseas recipient does not breach the Australian Privacy Principles before disclosing personal information to them. In practice that means contractual terms binding the recipient to equivalent protections, due diligence on the provider, and disclosure in your privacy policy of the countries where information is likely to be sent.

The accountability provision is the part that surprises people. Where APP 8 applies and you have not met one of the exceptions, an act by the overseas recipient that would breach the principles is generally treated as a breach by you. Moving your primary database to an Australian region does not discharge that duty for everything else, and everything else is usually where the personal information really lives: your support desk, your analytics, your email platform, your error tracking.
The OAIC’s Australian Privacy Principles guidelines set out how APP 8 and its exceptions operate. Our guide to the questions buyers ask about suppliers covers the commercial side of the same problem.
What do AWS and Azure actually give you in an Australian region?
Selecting an Australian region with AWS, Microsoft Azure or Google Cloud gives you data residency for the services you deploy in that region. Your data at rest stays in Australia. What it does not automatically give you is control over every supporting service, because logging, identity, support tooling and some managed services can process metadata elsewhere unless you configure otherwise.
All three providers publish data residency documentation, and Microsoft publishes its data residency position by service. Read it for the specific services you use rather than the marketing page for the region, because the answer varies service by service.
| What a buyer asks | What is usually true | What to check before you answer |
|---|---|---|
| Is our data stored in Australia | Yes, if you deployed to an Australian region | Backups and disaster recovery may sit in another region |
| Can anyone overseas access it | Usually yes, your own staff and support vendors | Who is in your support rota and where they are |
| Is it encrypted | Yes, at rest and in transit by default | Who holds the keys, and whether you manage them |
| Who are your sub-processors | You have more than you think | Support, analytics, error tracking, email, AI features |
| Could a foreign government compel access | A US parent company may be subject to US law | Whether your buyer needs a sovereign provider instead |
Where do the tools you use to run compliance sit?
Compliance tooling is a sub-processor question that teams forget to ask, because the tool is bought by the compliance owner rather than by engineering. A platform that holds your policies, your evidence and your control descriptions holds a detailed map of your security posture, and in many cases holds credentials or read access to your production systems as well.
There are three broad options and each makes a different trade. Spreadsheets and a document folder keep everything inside your own tenancy, but they get painful past a few dozen controls and they give an auditor nothing tidy to review. Enterprise platforms such as Vanta and Drata automate evidence collection, which is real value when it works, and they do it by integrating with your systems, so they need access. CertAssist sits between the two: a flat US$375 per month workspace for working through a framework, with no integrations by design, so it does not connect to your systems or pull your data. Which trade off suits you depends on whether you want automation or a smaller footprint.
Whichever you choose, list it as a sub-processor, note where it stores data, and include it in your own vendor review. Our guide to what a compliance platform does and where you still need help covers what tooling can and cannot do for an audit.
How do you answer a buyer asking where the data is?
Answer a buyer’s data location question with a written sub-processor list, the region each service runs in, and the contractual protections in place. A precise answer with one offshore service listed beats a vague assurance that everything is in Australia, because the vague answer collapses the first time their security team reads your privacy policy.
- Build the sub-processor list. Every third party that touches customer data. Include the AI features you shipped last quarter.
- Record the region for each. Not the vendor’s head office, the region your tenancy runs in.
- Note the contractual basis. Data processing terms, standard clauses, or an Australian entity in the contract.
- Publish it. A sub-processor page on your website answers the question before it is asked and shortens your sales cycle.
- Keep it current. Review it when you add a tool, not when a customer asks.
If your buyers are asking these questions systematically, they are usually about to ask for a certification too. Our guides to SOC 2 for Australian SaaS companies and ISO 27001 certification in Australia cover which one your market actually wants, and IRAP versus ISO 27001 covers the path if government is your target.
Common questions
What is data sovereignty in Australia?
In a commercial context, data sovereignty in Australia means data is subject to the laws of the country where it is physically stored, and the concern is usually foreign government access to Australian data held offshore. The related term data residency refers specifically to the geographic location of storage, which you control by choosing a cloud region. The phrase is also used for Indigenous Data Sovereignty, a separate field.
What are Australia’s data sovereignty laws?
Australia has no general law requiring private sector data to be stored onshore. The Privacy Act 1988 regulates handling rather than location, with APP 8 governing cross border disclosure of personal information. Sector specific rules exist, including statutory restrictions on My Health Record data and hosting policy applying to Australian Government agencies. Most onshore hosting requirements come from contracts, not legislation.
What are Australian data sovereignty requirements for government work?
Australian Government agencies are subject to whole of government hosting policy, including the Hosting Certification Framework, which certifies hosting providers for government data. If you are selling software to a Commonwealth agency, expect requirements about where data is held and which providers may hold it, often alongside an IRAP assessment. Check the specific requirements in the tender rather than assuming a general rule.
Why is data sovereignty important?
Data sovereignty matters because the law governing your customers’ data follows its physical location, which affects who can compel access to it. For an Australian business the practical importance is commercial: enterprise and government buyers ask about data location in procurement, and an unclear answer delays or loses deals. It also matters for your own risk, because each offshore service is another party holding your data.
Does AWS or Azure keep Australian data in Australia?
AWS, Microsoft Azure and Google Cloud all operate Australian regions, and data you deploy to those regions is stored in Australia. Supporting services can behave differently. Logging, identity, support tooling and some managed services may process data or metadata in other regions unless configured otherwise, and each provider publishes service level detail. Check the documentation for the specific services you use.
Does hosting in Australia satisfy the Privacy Act?
Not by itself. Hosting in Australia removes the APP 8 cross border question for that data, but the other principles still apply in full, including APP 11 security obligations and the requirement to destroy or de-identify information you no longer need. It also does nothing for the offshore tools still handling personal information, which for most SaaS businesses is the larger exposure.
Where to start
Build the sub-processor list this week. It takes an afternoon, it answers most buyer questions immediately, and it usually surfaces one or two services nobody realised were holding customer data. Everything else in this article depends on having that list.
Siege Cyber helps Australian SaaS companies work out what their buyers actually require, and what is worth building to meet it. You can see how we approach that on our cyber security advisory page, or get in touch if a tender has landed and the questions have started. If government is your target market, our IRAP readiness service is the place to start.