Australian organisations are told, often by vendors, that data is “sovereign” because it sits in a Sydney or Melbourne data centre. That claim answers one question (where are the disks?) and skips the more important one: who can be compelled to hand the data over, and under which country’s law?
This guide walks through the US Clarifying Lawful Overseas Use of Data Act (the CLOUD Act), how it interacts with Australia’s Privacy Act 1988 (Cth), what changed when the Australia–US data access agreement came into force in January 2024, and what a realistic sovereignty posture looks like for a firm that wants to run AI models over sensitive data. It is general information, not legal advice. If you are making a decision that matters, take the primary sources below to your lawyer.
What the CLOUD Act actually says
The CLOUD Act was enacted in March 2018 as Division V of the Consolidated Appropriations Act, 2018 (Pub. L. 115-141). It was a response to United States v. Microsoft Corp., the long-running dispute over whether a US warrant could reach Microsoft customer emails stored on servers in Ireland. Once the Act passed, the Supreme Court dismissed that case as moot.
The core provision is now codified at 18 U.S.C. § 2713. It is short enough to quote in full:
A provider of electronic communication service or remote computing service shall comply with the obligations of this chapter to preserve, backup, or disclose the contents of a wire or electronic communication and any record or other information pertaining to a customer or subscriber within such provider’s possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States.
Three phrases do the work:
- “Electronic communication service or remote computing service.” These are terms from the Stored Communications Act. Cloud storage, hosted email, SaaS and hosted AI inference services generally fall within them.
- “Possession, custody, or control.” The test is control, not geography. If the provider can technically and legally retrieve the data, it is likely within scope.
- “Regardless of whether … located within or outside of the United States.” Data residency, on its own, is not a defence.
The Act does not create a free-for-all. US authorities still need the ordinary legal process under the Stored Communications Act (for content, generally a warrant based on probable cause). The Act also gave providers a limited avenue to challenge a request. Under 18 U.S.C. § 2703(h), a provider can move to modify or quash legal process where the customer is not a US person and does not reside in the US, and disclosure would create a material risk of breaching the law of a “qualifying foreign government”. A qualifying foreign government is one that has an executive agreement with the US under the Act. Since 2024, Australia is one.
The Department of Justice keeps a collection of official material, including a white paper on the Act’s purpose and scope, on its CLOUD Act resources page.
The Australia–US Data Access Agreement
The CLOUD Act’s second half lets the US enter executive agreements under which foreign governments can serve orders directly on US providers, and the reverse. Australia and the United States signed theirs, formally the Agreement on Access to Electronic Data for the Purpose of Countering Serious Crime, on 15 December 2021. It came into force on 30 January 2024, announced in a joint statement by the two Attorneys-General.
On the Australian side, the agreement runs through the International Production Order (IPO) framework in Schedule 1 of the Telecommunications (Interception and Access) Act 1979 (Cth). That schedule was inserted by the Telecommunications Legislation Amendment (International Production Orders) Act 2021. The Attorney-General’s Department explains that the agreement lets Australian and US agencies obtain orders for data held by communications providers in the partner country directly, without separate sign-off from their own government for each request. Australian IPOs pass through the Australian Designated Authority, which checks them against the agreement before forwarding them to the US provider.
Two points are often misunderstood:
- The agreement is about serious crime and national security, not commercial surveillance. It includes safeguards, oversight and targeting restrictions. Read the agreement text yourself rather than relying on summaries, including this one.
- It works in both directions. It speeds up Australian agencies’ access to data held by US providers. It does not stop US process under domestic US law from reaching data that a US provider controls in Australia.
Where the Privacy Act fits
Australia’s Privacy Act 1988 applies to “APP entities”: Australian Government agencies and most organisations with annual turnover above 3 million dollars, plus some smaller businesses such as health service providers. The current compilation is on the Federal Register of Legislation. The provisions that matter most for cloud and AI decisions are these.
APP 8 and section 16C: cross-border disclosure
APP 8 requires an entity, before it discloses personal information to an overseas recipient, to take reasonable steps to ensure that recipient does not breach the APPs. Section 16C then makes the Australian entity accountable for the overseas recipient’s acts that would breach the APPs.
The OAIC’s guidance draws a useful distinction. Giving personal information to an overseas cloud provider only to store it, under a contract that keeps the entity in effective control, may be a “use” rather than a “disclosure” (para 8.14). The guidance also says routing data through overseas servers in transit is usually a use. Once a provider can access and handle the information for its own purposes, it starts to look like a disclosure.
Section 6A(4): when a foreign law compels disclosure
This is the part most sovereignty discussions miss. Section 6A(4) provides that an act done outside Australia that is required by an applicable foreign law does not breach the APPs. The OAIC’s APP 8 guidance (paras 8.64–8.67) gives the example of a US statute requiring an overseas recipient to hand information to the US Government. In that case the Australian entity is not accountable under s 16C for the disclosure.
Read carefully, this is not reassuring. It means the Privacy Act will not give your customers a remedy if a foreign provider is compelled to disclose their information overseas. The OAIC suggests organisations consider telling individuals that this can happen. In other words, the Privacy Act manages the risk by making it visible, not by stopping it.
Security, breaches and the newer enforcement tools
- APP 11 requires reasonable steps to protect personal information from misuse, interference, loss and unauthorised access.
- The Notifiable Data Breaches scheme requires notification to affected individuals and the OAIC when an eligible data breach is likely to result in serious harm.
- Maximum civil penalties for serious or repeated interferences with privacy were raised in late 2022. For a body corporate, the maximum is now the greater of 50 million dollars, three times the benefit obtained, or 30% of adjusted turnover during the breach period.
- The Privacy and Other Legislation Amendment Act 2024 added a statutory tort for serious invasions of privacy, which commenced on 10 June 2025. The same Act introduced a mechanism for prescribing countries and binding schemes for APP 8 purposes.
Why AI makes the question sharper
Traditional SaaS stores records. AI systems read them. A retrieval-augmented generation (RAG) assistant over your document management system, a model fine-tuned on support tickets, or an agent with access to email and CRM all concentrate sensitive data into a small number of high-value places:
- Prompts and completions, which often contain personal and commercially confidential information pasted in by staff.
- Embeddings and vector stores, which are derived from your documents and can leak their content.
- Fine-tuning datasets and fine-tuned weights.
- Logs and abuse-monitoring stores kept by the platform operator.
Each of these is a record “pertaining to a customer” that may sit in a provider’s possession, custody or control. When you assess a hosted AI service, ask where each category is processed, where it is stored, for how long, and who can access it. Our companion guide on local LLMs versus Azure OpenAI works through one major provider’s documentation in detail.
What “sovereign” can realistically mean
No architecture puts data beyond the reach of every legal system. Australian data in an Australian facility is still subject to Australian law, including the TIA Act and the industry assistance powers added in 2018. A sensible definition of sovereignty is narrower and more useful:
Your data is governed by Australian law, held on infrastructure you control, and any compelled access has to come to you, through Australian process, where you can see it and respond.
Measured against that definition, the options line up roughly like this:
| Deployment model | Where data sits | Who holds the keys | Who receives a foreign order | Visibility to you |
|---|---|---|---|---|
| Global SaaS / global AI endpoint | Anywhere the provider chooses | Provider | Provider | Possibly none |
| US hyperscaler, Australian region | Australia (at rest) | Provider, or customer-managed key held in provider’s key service | Provider | Depends on provider policy and any gag order |
| US hyperscaler, Australian region, external key management under your control | Australia | You (keys outside the provider) | Provider, but it may not be able to decrypt | Better |
| Australian-owned cloud or managed host | Australia | Australian operator | Australian operator, under Australian law | Contractual |
| Your own hardware in Australian colocation | Australia, in your rack | You | You, under Australian law | Direct |
The last row is not automatically better. You take on patching, physical security assurance, capacity planning and incident response. For many firms the right answer is a split. Keep commodity workloads on a hyperscaler, and move the sensitive core (the model, the vector store and the logs that touch personal or privileged information) onto hardware you own, in a facility you can visit.
A practical checklist
Use this as a starting point for a conversation with your lawyer and your IT provider.
- Classify the data. Which workloads touch personal information, sensitive information under s 6(1), legally privileged material, or information covered by contractual confidentiality? For government work, check the Protective Security Policy Framework and any Hosting Certification Framework requirements.
- Map every copy. For each AI workload, list where prompts, outputs, embeddings, fine-tuning data, logs and backups are processed and stored. Get this from the provider’s documentation, not its marketing.
- Identify the controlling entity. Who is the contracting party, and is it, or its parent, subject to US jurisdiction? The CLOUD Act turns on control, so a local subsidiary of a US company is usually still in scope.
- Check processing location, not only storage. “Global” or multi-region processing options can move prompts offshore even when data at rest stays onshore.
- Take custody of the keys. Where you stay with a hyperscaler, consider external key management with hardware you control, and test what happens to the service if you revoke access.
- Update your APP 5 notice and privacy policy. If foreign-law disclosure is possible, say so plainly, as the OAIC suggests.
- Contract for notice. Ask providers to commit to notify you of government data requests where they lawfully can, and to challenge overbroad ones. Read their transparency reports.
- Plan an exit. Make sure you can export data and delete it, including from backups and logs, within a defined time.
- Keep the sensitive core local. For workloads where none of the above is good enough, run the model yourself on hardware you own, in an Australian facility you can inspect.
How Green Racks fits
Green Racks is an Australian colocation and AI hosting operator, serving customers Australia-wide. Our facility in Osborne Park, WA has 10 racks, 2N UPS (150kVA), dual A/B feeds per rack, N+1 cooling, NOVEC fire suppression, a 10GbE Telstra handoff and 24/7 access, with an on-site generator coming soon. If you want to run inference on your own GPUs under Australian control, you can bring your hardware or have us help you specify it. You hold the keys.
Take the Sovereignty Audit to score your current setup in about three minutes.
Sources
- 18 U.S.C. § 2713, Required preservation and disclosure of communications and records (Cornell LII)
- US Department of Justice, CLOUD Act resources
- Joint statement on entry into force of the AUS-US Data Access Agreement, 30 January 2024 (US DOJ)
- International production order framework (Attorney-General’s Department)
- Privacy Act 1988 (Cth), current compilation (Federal Register of Legislation)
- APP Guidelines Chapter 8: Cross-border disclosure of personal information (OAIC)
- Notifiable Data Breaches scheme (OAIC)
- Statutory tort for serious invasions of privacy (OAIC)