Data sovereignty in Australia: laws, data residency and what it really means
Key Takeaways
- Many organisations mistakenly believe that hosting data in Australia guarantees data sovereignty, but control and legal jurisdiction are equally crucial.
- Data sovereignty involves understanding where data is stored and processed, and who controls it - foreign laws can still apply even with local storage.
- Regulated industries must prioritise data sovereignty to ensure compliance and protect sensitive information, making it a key governance discussion.
Most organisations assume that if their data is hosted in Australia, they’ve solved the data sovereignty question.
It’s an understandable assumption. After all, if the data never leaves the country, surely Australian law applies. But not necessarily.
Notably, for many organisations, the bigger question isn’t where data is stored, but who ultimately controls it, who can access it and which country’s laws apply if a government comes knocking.
That’s why data sovereignty has moved well beyond an IT discussion. Boards, risk committees and regulators increasingly want to understand not just where critical data resides, but whether organisations can demonstrate appropriate control over it throughout its lifecycle.
For regulated industries such as financial services, superannuation, healthcare and government, those questions have become particularly important. Data sovereignty now sits alongside cyber security, operational resilience and cloud strategy as part of a broader governance conversation.
This guide explains what data sovereignty means in Australia, how it differs from data residency and data localisation, why laws such as the US CLOUD Act have changed the conversation, and the practical questions every organisation should ask before choosing a cloud provider.
What data sovereignty is (and why “Australian-hosted” alone isn’t enough)
Data sovereignty is the principle that data is governed by the laws of the country in which it is collected, stored, processed and controlled. In Australia, that means ensuring data remains subject to Australian law throughout its lifecycle, not simply that it is stored on Australian soil.
That distinction is where many organisations get caught out.
When cloud providers say data is “hosted in Australia”, they’re usually describing where the data physically resides. That’s an important part of the picture, but it doesn’t answer two equally important questions: who controls the data, and which country’s laws ultimately apply to the organisation holding it?
A provider can operate Australian data centres and still be governed by foreign legislation that allows overseas authorities to compel access to customer data. In other words, Australian hosting is a necessary part of data sovereignty, but on its own it isn’t enough.
True data sovereignty brings together three connected layers. First, the provider is governed by Australian law rather than a foreign jurisdiction. Second, the data is stored and processed within Australia. Third, the systems are operated by Australian-based personnel, reducing unnecessary offshore access to sensitive information.
Together, those three layers provide a much stronger foundation for organisations managing sensitive or regulated data.
The sections that follow explore why those distinctions matter, beginning with the US CLOUD Act, before examining how data sovereignty differs from data residency, the Australian laws and regulations organisations need to understand, and the practical questions every technology leader should ask when evaluating a provider.
“It doesn’t matter if you’re the biggest bank in the country. If your data sits with a US-owned provider, the US CLOUD Act can reach it, and there’s nothing the local country can do to stop it.” Dan Cox, Interactive, Managing Director - Cloud
Why it matters: the US CLOUD Act
For many organisations, the conversation around data sovereignty changed with the introduction of the US CLOUD Act.
The legislation allows US authorities to compel US-based technology companies to provide access to data they control, even if that data is physically stored outside the United States. In practical terms, that means data hosted in an Australian data centre may still be subject to US legal jurisdiction if the provider is owned or controlled by a US company.
That’s why data sovereignty has become a board-level issue rather than simply a technology decision. The question is no longer just “Where is my data stored?” It’s “Whose laws ultimately apply to the organisation holding it?”
For regulated industries, that distinction matters. Financial institutions, superannuation funds, healthcare providers and government agencies are increasingly expected to understand not only where sensitive information resides, but also who can legally compel access to it and under what circumstances.
Indeed, the implication is significant. Even one of Australia’s largest organisations could have data stored locally while still being exposed to a foreign jurisdiction through the provider that controls it. The issue isn’t the size of the organisation. It’s the legal framework governing the provider.
That changes the conversation organisations should be having with cloud providers.
Instead of asking:
- Is my data stored in Australia?
Technology leaders should also ask:
- Who owns the company providing this service?
- Which country’s laws govern that organisation?
- Can overseas authorities compel access to my data?
- Who can access my environment, and from where?
- Can you contractually guarantee where my data is stored, processed and accessed?
Indeed, these questions sit at the heart of modern data sovereignty. They move the discussion beyond geography and towards governance, jurisdiction and operational control, which are the factors that ultimately determine how protected sensitive information really is.
Where your data goes when you use Copilot or Gemini
One of the biggest misconceptions about data sovereignty is that if data is stored in Australia, it never leaves Australia. But that’s not always the case.
In fact, modern AI services have introduced a new layer of complexity. An organisation may store its data in an Australian data centre, yet the moment that data is processed by a hyperscaler AI service such as Microsoft Copilot or Google Gemini, elements of that processing may occur outside Australia, depending on how the service is configured and where the underlying AI infrastructure operates.
In other words, the data may be stored in Australia but processed elsewhere.
It’s a practical example of why data residency is not the same as data sovereignty. Storage is only one part of the equation. Organisations also need to understand where data is processed, who controls that processing, and which legal jurisdiction applies throughout the entire lifecycle of the information.
As AI becomes embedded in productivity platforms, customer service applications and business workflows, these questions are becoming increasingly important. Many organisations are enabling AI features without fully understanding how data moves between services or where AI processing actually takes place.
This is one of the fastest-moving areas of data sovereignty. That’s why we’ve explored it in more detail in our guide to sovereign AI, including how organisations can design AI environments that keep both data storage and AI processing within Australia.
The broader lesson is simple: when evaluating any cloud or AI service, ask not only where your data is stored, but also where it is processed. Data sovereignty depends on both.
Data sovereignty vs data residency vs data localisation
These three terms are often used interchangeably, but they describe different concepts. Understanding the distinction is one of the most important steps organisations can take when evaluating cloud providers, because it’s common for vendors to answer a data residency question when the customer is really asking about data sovereignty.
Data residency refers to where data is physically stored. If information is held in an Australian data centre, it has Australian data residency. It answers one question: Where is the data located?
Data localisation goes a step further. It refers to a legal or regulatory requirement that certain types of data must remain within a country’s borders. In these cases, organisations are legally required to keep specific information onshore.
Data sovereignty is broader again. It considers where data is stored, where it is processed, which country’s laws apply to it, and who ultimately controls and operates the environment. In other words, it extends beyond geography to include legal jurisdiction and operational control.
That’s why it’s possible to have data residency without data sovereignty. An organisation may store data in Australia, but if it’s controlled by a provider governed by foreign laws, or processed offshore, it may not meet the broader expectations of data sovereignty.
For regulated organisations, that’s a critical distinction. Data residency is an important starting point. Data sovereignty provides the confidence that sensitive information remains protected under Australian jurisdiction throughout its lifecycle.
At a glance:

The three layers of data sovereignty in Australia
“I see sovereignty in three layers: is the company governed by Australian law, does the data stay in Australia, and do only Australian-based people touch it. You can get local data in a hyperscaler’s sovereign zone and still be working with an American company.”
— Dan Cox, Interactive, Managing Director – Cloud
True data sovereignty rests on three interconnected layers. Organisations need all three working together to achieve genuine sovereignty. If one layer is missing, the sovereignty picture changes.
1.Jurisdiction
The first layer is jurisdiction: the legal framework governing the organisation that controls your data.
An organisation may store data in Australia, but if the provider is owned by a company governed by foreign laws, those laws may still apply. That’s why jurisdiction sits at the heart of the data sovereignty conversation. It determines which legal system ultimately governs the provider and whether foreign authorities may be able to compel access to customer data.
2. Data residency and processing
The second layer is data residency. Data should not only be stored in Australia but, where sovereignty is required, also processed here.
This distinction has become increasingly important as cloud services and AI platforms evolve. A workload may appear fully Australian because the data is stored locally, yet processing can occur elsewhere depending on how the service is designed. True sovereignty considers both storage and processing throughout the data lifecycle.
3. Operational control
The third layer is operational control. This focuses on who administers, supports and has privileged access to the environment.
Even when infrastructure and data remain in Australia, organisations should understand where administrators are located, who can access sensitive systems and what controls exist over privileged access. For highly regulated environments, limiting operational access to Australian-based personnel can be an important part of a broader sovereignty strategy.
Taken together, these three layers provide a practical framework for evaluating any provider or cloud architecture.
Additionally, it’s also why some commonly promoted solutions only solve part of the problem. A global hyperscaler’s Australian sovereign region may provide Australian data residency and local operations, but if the provider remains governed by foreign laws, the jurisdiction layer is still missing. Likewise, data stored in Australia but processed offshore through connected services or AI platforms may satisfy residency while falling short of full sovereignty.
Certainly, the important lesson is that data sovereignty isn’t achieved by meeting one requirement. It comes from understanding how jurisdiction, residency and operational control work together. Evaluating all three layers gives organisations a far clearer view of where sensitive information sits, who can access it and which legal framework ultimately applies.
Data sovereignty laws and requirements in Australia
Australia doesn’t have a single law called the Data Sovereignty Act. Instead, data sovereignty sits at the intersection of several laws, prudential standards and regulatory obligations that together shape how organisations manage sensitive information.
For many organisations, particularly those operating in regulated industries, data sovereignty has become the most practical way to demonstrate compliance across a range of overlapping requirements.
Some of the key obligations include:
Privacy Act and Australian Privacy Principles (APPs)
The Privacy Act 1988 and the Australian Privacy Principles (APPs) govern how organisations collect, use, store and disclose personal information. They also place obligations on organisations when personal information is disclosed to overseas recipients, making offshore processing and foreign provider relationships an important governance consideration.
Notifiable Data Breaches (NDB) scheme
Australia’s Notifiable Data Breaches scheme requires organisations to notify eligible data breaches that are likely to result in serious harm. Understanding where sensitive data resides, who has access to it and how it is protected becomes critical when managing both risk and regulatory obligations.
Consumer Data Right (CDR)
The Consumer Data Right establishes rules for how consumer data is shared across sectors such as banking and energy. As data sharing expands, organisations need confidence that information remains appropriately governed throughout its lifecycle.
Security of Critical Infrastructure Act (SOCI)
For organisations operating critical infrastructure, the Security of Critical Infrastructure Act introduces additional obligations around identifying, managing and reducing cyber and operational risk. Understanding third-party providers, supply chains and data handling practices forms part of that broader resilience picture.
APRA CPS 230 and CPS 234
For APRA-regulated organisations, CPS 230 focuses on operational resilience and the management of material service providers, while CPS 234 requires organisations to maintain and demonstrate effective information security controls, including where services are delivered by third parties.
Neither prudential standard explicitly mandates data sovereignty. However, sovereign arrangements can make both standards easier to evidence by simplifying data flows, reducing foreign jurisdiction exposure and strengthening visibility across critical services.
The common thread across all of these obligations is governance. None requires organisations to pursue data sovereignty by name, but together they reinforce the importance of understanding where sensitive data is stored, where it is processed, who controls it and which legal framework ultimately applies.
For a deeper look at APRA’s prudential standards, explore our guides to CPS 230 and CPS 234.
Who must comply, and why it matters most in financial services, health and government
Data sovereignty is relevant to any organisation that collects, stores or processes sensitive information. But for some sectors, the expectations are significantly higher because of the nature of the data they hold and the regulatory obligations they operate under.
Financial services and superannuation
Financial institutions and superannuation funds manage some of Australia’s most sensitive financial and personal information. At the same time, they operate under increasing regulatory scrutiny, with APRA expecting stronger evidence of operational resilience, third-party risk management and information security.
For superannuation funds in particular, the stakes are especially high. Australia’s superannuation system now manages around $4.5 trillion in assets, making it one of the world’s largest pools of retirement savings.
Protecting the data that supports those members is an IT responsibility, but has also become a governance, operational resilience and trustee issue. As funds continue to consolidate, technology environments become larger and more complex, making data sovereignty an increasingly important part of how trustees manage risk, resilience and member outcomes.
Healthcare
Healthcare organisations manage highly sensitive personal and clinical information, making privacy, security and trust central to patient care. Understanding where health data is stored, processed and accessed is critical to maintaining compliance and protecting patient confidence in an increasingly digital healthcare system.
Government
Government agencies are responsible for information that underpins essential public services, national capability and community trust. Procurement requirements, security classifications and sovereign capability considerations are placing greater emphasis on keeping sensitive government information under Australian jurisdiction and operational control.
While each sector faces different regulatory obligations, the underlying challenge is the same. The more sensitive the information, the greater the need to understand not just where data resides, but who controls it, who can access it and which legal framework ultimately applies. That’s why data sovereignty has become a strategic governance issue across Australia’s most highly regulated industries.
Data sovereignty and the cloud: what to ask a provider
Most data sovereignty decisions are ultimately cloud decisions because that’s where critical business data now lives.
Indeed, one of the biggest misconceptions is that choosing an Australian cloud region automatically delivers data sovereignty. It doesn’t. An Australian region provides data residency by keeping information onshore, but if the provider is governed by foreign laws, the jurisdiction layer remains unchanged. Even a dedicated sovereign cloud region operated by a global hyperscaler doesn’t alter the legal framework governing the company itself.
That’s why organisations need to look beyond where data is stored and ask broader questions about ownership, control and operational access.
When evaluating a cloud provider, consider asking:
- Who owns the company, and which country’s laws govern it?
- Where is my data stored, and where is it processed?
- Who can access the environment, and from where?
- Can overseas personnel administer or support the platform?
- Can you contractually guarantee where data is stored, processed and accessed?
- How do you support operational resilience and regulatory obligations for Australian organisations?
The answers to these questions provide a much clearer picture of whether a provider delivers data residency, genuine data sovereignty or a combination of the two.
The right answer will also depend on the workload. Some organisations require full sovereignty across jurisdiction, data residency and operations. Others may adopt a hybrid approach, keeping their most sensitive information under Australian jurisdiction while using offshore capability where the data and risk profile allow.
The important point is that sovereignty isn’t an all-or-nothing decision. In fact, it’s about understanding the sensitivity of your data, the obligations your organisation operates under, and selecting an operating model that reflects both.
If your organisation is assessing cloud providers or reviewing its current environment, Interactive’s team can help you evaluate the options and determine the level of data sovereignty that’s right for your business.
How data sovereignty connects to CPS 230 and CPS 234
For APRA-regulated organisations, data sovereignty supports broader operational resilience and information security obligations under CPS 230 and CPS 234.
CPS 234 requires regulated entities to maintain the security of information assets, including those managed by third-party providers, and to demonstrate that security controls are effective. CPS 230 focuses on operational resilience, requiring organisations to manage material service providers and maintain the continuity of critical business services.
Neither prudential standard explicitly requires data sovereignty. However, sovereign arrangements can make both significantly easier to evidence.
Keeping data under Australian jurisdiction, storing and processing it onshore, and maintaining Australian-based operational control can simplify governance, improve visibility across third-party providers and reduce the complexity of demonstrating how sensitive information is protected and critical services are supported.
In that sense, data sovereignty becomes more than a technology decision. It becomes a practical way of strengthening governance, operational resilience and third-party risk management while supporting compliance with APRA’s prudential standards.
For organisations subject to CPS 230 and CPS 234, the question is no longer simply whether controls exist, but whether they can be clearly demonstrated. Data sovereignty doesn’t replace good governance, but it can make governance, assurance and regulatory reporting considerably easier.
For a deeper look at each prudential standard, explore Interactive’s guides to CPS 230 and CPS 234.
How Interactive helps organisations build sovereign cloud environments
If anything, data sovereignty isn’t achieved through a single technology decision. On the flip side, it comes from designing an environment where jurisdiction, data residency and operational control work together to meet an organisation’s business, governance and regulatory requirements.
Interactive helps organisations build that environment through Australian-owned cloud infrastructure, Australian data centres and Australian-based operations, giving customers greater confidence over where sensitive information is stored, processed and managed.
Rather than taking a one-size-fits-all approach, Interactive works with organisations to determine the level of sovereignty that’s appropriate for each workload. For some, that means a fully sovereign cloud environment. For others, it means a carefully designed hybrid model that balances sovereignty, flexibility, performance and cost.
The goal is to help organisations understand where their data resides, who controls it, how it’s processed and which legal framework applies throughout its lifecycle. It’s not to simply keep data in Australia.
For organisations operating in highly regulated sectors such as financial services, superannuation, healthcare and government, that creates a stronger foundation for operational resilience, governance and long-term confidence.
If your organisation is reviewing its cloud strategy, evaluating providers or strengthening its approach to data sovereignty, Interactive can help you assess your current environment and design a cloud model aligned to your operational, regulatory and business priorities.
Explore One Interactive