Australia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Australia has no general rule that data must stay in the country. You may send personal information anywhere, and no destination is banned. The catch is that you stay legally responsible for whatever your overseas supplier does with it. Small businesses under A$3 million turnover are exempt from the main privacy law. Specific industries are far stricter, and one of them carries a prison sentence.
Eight questions about Australia
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Australia's rules apply to my company?
Yes, it reaches you even with no office in Australia. The national privacy law applies to any organisation that carries on business in Australia, whether or not the data is collected or stored here. But Australia has something most countries do not: a real size threshold you can fall below. A business with annual turnover of A$3 million (about US$2 million) or less is generally exempt. That exemption has big holes: it does not apply if you provide a health service, if you buy or sell personal information, or if you supply services under a federal government contract. No local representative and no registration are required.
Section 5B(3) of the Privacy Act 1988 gives an organisation an 'Australian link' if it simply carries on business in Australia. Earlier drafting also required the information to be collected or held in Australia; the current compilation (No. 105, 4 June 2026) contains only the two limbs, so the extra hurdle is gone. Section 6D defines the small business operator exemption at A$3,000,000 annual turnover, with the carve-outs in s 6D(4) (health service providers holding health information, trading in personal information, contracted service providers for a Commonwealth contract, credit reporting bodies). Separate laws override the threshold in specific settings: telecommunications providers are treated as organisations for retained data under s 187LA of the Telecommunications (Interception and Access) Act 1979 regardless of size, and the ransomware payment reporting duty in the Cyber Security Act 2024 uses its own A$3 million test.
Sources
- Official sourceFederal Register of LegislationPrivacy Act 1988, sections 5B and 6D (compilation of 4 June 2026)
legislation.gov.au
“An organisation or small business operator also has an Australian link if all of the following apply: (a) the organisation or operator is not described in subsection (2); (b) the organisation or operator carries on business in Australia or an external Territory.”
Link checked 18 August 2026
- Official sourceOffice of the Australian Information CommissionerThe Privacy Act — who it covers
oaic.gov.au
Link checked 18 August 2026
Can I store my users' data outside Australia?
In general, yes. Australia has no national law saying personal data must be kept in the country, and no country is blacklisted. You can pick any cloud region you like. What you cannot do is hand off the risk: if your overseas supplier does something with the data that would break Australian rules, the law treats that as your own breach. The hard walls are industry by industry, and the health one is absolute.
Sector ratings as at 18 August 2026. HEALTH (national My Health Record system): data must stay in the country. Section 77 of the My Health Records Act 2012 bans holding, taking, processing or handling those records outside Australia, with a criminal offence attached. It binds the System Operator and registered repository, portal and contracted service providers, not every clinic. BANKING, INSURANCE, SUPERANNUATION: data can leave with the right paperwork. Prudential Standard CPS 230 requires prior notification to the banking regulator before any material offshoring arrangement, including where data will sit offshore. OPEN BANKING (Consumer Data Right): data can leave with the right paperwork. Privacy Safeguard 8 plus rules 7.8A and 7.8B make the accredited firm liable for its overseas outsourced providers, and its public policy must name the countries they sit in. CRITICAL INFRASTRUCTURE: data can leave with the right paperwork and tightening. From June 2026 nine asset classes must treat 'offshore or remote access to business critical data' as a material risk to be minimised or eliminated. AUSTRALIAN GOVERNMENT: data can leave with the right paperwork. Sensitive government data and anything at PROTECTED must be hosted with certified providers. QUEENSLAND STATE GOVERNMENT: data can leave with the right paperwork and stricter than the national rule. TELECOMS: data can leave freely on location, but retained data must be encrypted and kept two years. SOCIAL MEDIA, EDUCATION, GAMING, MAPPING AND GEOSPATIAL, DEFENCE INDUSTRY: no location rule found on a government source, checked 18 August 2026, confidence medium.
Sources
- Official sourceFederal Register of LegislationPrivacy Act 1988, Australian Privacy Principle 8.1 and section 16C
legislation.gov.au
“Before an APP entity discloses personal information about an individual to a person (the overseas recipient) ... the entity must take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles (other than Australian Privacy Principle 1) in relation to the information.”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationMy Health Records Act 2012, section 77 — requirement not to hold or take records outside Australia
legislation.gov.au
“The System Operator, a registered repository operator, a registered portal operator or a registered contracted service provider ... must not: (a) hold the records, or take the records, outside Australia; or (b) process or handle the information relating to the records outside Australia”
Link checked 18 August 2026
- Official sourceAustralian Prudential Regulation AuthorityPrudential Standard CPS 230 Operational Risk Management — notification of material offshoring arrangements
apra.gov.au
“prior to entering into any material offshoring arrangement, or when there is a significant change proposed to the arrangement, including in circumstances where data or personnel relevant to the service being provided will be located offshore.”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationSecurity of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026, section 6A
legislation.gov.au
“the following specified risks are additional material risks: ... (c) offshore or remote access to critical components; and (d) offshore or remote access to business critical data.”
Link checked 18 August 2026
What do I need in place before data leaves Australia?
Before data leaves, you must take reasonable steps to make sure the overseas recipient will handle it the Australian way. In practice that means a contract with the right promises in it. There is no government form to file, no approval to wait for, and no list of approved countries to check. A power to approve countries was switched on in December 2024, but as of today the government has not named a single one. The alternative routes are narrow: you can rely on the recipient already being covered by a substantially similar law, or on the person's informed consent after you warn them you will no longer be responsible.
The model is not a blocklist or an allowlist. Any destination is permitted; the control sits on the sender. Australian Privacy Principle 8.1 requires reasonable steps, and section 16C then deems the overseas recipient's breach to be the sender's breach. Australian Privacy Principle 8.3, inserted by the Privacy and Other Legislation Amendment Act 2024 and in force from 11 December 2024, lets regulations prescribe a country or binding scheme so that 8.1 no longer applies; section 100(1A) requires the Minister to be satisfied of substantially similar protection and accessible enforcement first. The Privacy Regulations 2025 (made 13 November 2025, commenced 1 April 2026) replaced the old regulation and contain no such prescription, so the list is empty. How tight the accountability rule really is can be seen in the Privacy Commissioner's Public Interest Determinations of 11 February 2025, which had to be issued so that a major bank could keep processing international money transfers without breaching Principle 8.1.
Sources
- Official sourceFederal Register of LegislationPrivacy and Other Legislation Amendment Act 2024 (No. 128, 2024), Schedule 1 Part 6 — overseas data flows
legislation.gov.au
“8.3 This subclause applies in relation to the disclosure of personal information ... if: (a) the recipient ... is: (i) subject to the laws of a country that is prescribed by the regulations; or (ii) a participant in a binding scheme that is prescribed by the regulations”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationPrivacy Regulations 2025 — full contents, containing no prescribed country or binding scheme
legislation.gov.au
Link checked 18 August 2026
- Official sourceOffice of the Australian Information CommissionerAustralian Privacy Principles guidelines, Chapter 8 — cross-border disclosure
oaic.gov.au
Link checked 18 August 2026
- Official sourceFederal Register of LegislationPrivacy (International Money Transfers) Public Interest Determination 2025 (No. 1), made by the Privacy Commissioner on 11 February 2025
legislation.gov.au
Link checked 18 August 2026
Who enforces the rules in Australia, and what can they do?
The Office of the Australian Information Commissioner. It is staffed, it has a sitting Privacy Commissioner, and it is issuing decisions. In October 2025 the Federal Court ordered a pathology company to pay A$5.8 million (about US$3.8 million), the first court penalty in the law's history. The regulator sued Optus in August 2025, settled with Meta for A$50 million in December 2024, and in June 2026 alone published formal findings against Optus, American Express and two health providers. Banking, cyber security, online safety and open banking each have their own separate regulator, and all of them are working.
Observable evidence of operation in 2026: determination against Optus over unlisted White Pages entries (11 June 2026); compensation order against American Express Australia (15 June 2026); findings against Medmate Australia and Monash IVF over third-party tracking pixels (24 June 2026); report of preliminary inquiries into the 2025 Qantas incident (16 July 2026); updated facial recognition guidance (29 July 2026); record annual data breach statistics published 6 July 2026. Rated active rather than aggressive because the very large penalties are still a handful of headline cases rather than routine, and the first court penalty only arrived in late 2025.
Sources
- Official sourceOffice of the Australian Information CommissionerAustralian Clinical Labs ordered to pay A$5.8 million in civil penalties, 9 October 2025 — first penalty under the Privacy Act
oaic.gov.au
Link checked 18 August 2026
- Official sourceOffice of the Australian Information CommissionerPrivacy Commissioner finds against Optus in White Pages breach, 11 June 2026
oaic.gov.au
Link checked 18 August 2026
- Official sourceOffice of the Australian Information CommissionerInformation Commissioner commences Federal Court civil penalty proceedings against Optus, 8 August 2025
oaic.gov.au
Link checked 18 August 2026
- Official sourceOffice of the Australian Information CommissionerData breach notifications increase to all-time high in 2025, 6 July 2026
oaic.gov.au
Link checked 18 August 2026
How long do I have to keep the data?
There is a floor and a ceiling and they pull in opposite directions. The clearest floor is telecoms: phone and internet providers must keep call and connection records for two years, and must encrypt them. The general ceiling has no number attached — you must destroy or de-identify personal information once you genuinely no longer need it. Two ceilings are sharp. A social media platform must destroy age-check information as soon as it has finished using it. A digital identity provider must destroy a face or fingerprint scan immediately after the identity check is complete.
Telecommunications (Interception and Access) Act 1979 s 187C sets the two-year period, running from creation, or from closure of the account for subscriber details; s 187BA requires the retained data to be encrypted and protected. Australian Privacy Principle 11.2 sets the general ceiling: where the entity no longer needs the information, it is not in a Commonwealth record and no law requires it to be kept, reasonable steps must be taken to destroy or de-identify it. Online Safety Act 2021 s 63F(3) requires destruction of information collected to check whether a user is under sixteen, and failure to destroy is deemed an interference with privacy under the Privacy Act. Digital ID Act 2024 s 51 requires biometric information to be destroyed immediately after verification or authentication is complete, with narrow exceptions for testing and fraud investigation. Where a floor and a ceiling conflict, the ceiling gives way: Principle 11.2 only applies where no Australian law requires the information to be kept. We did not verify the tax and corporate record floors in this pass.
Sources
- Official sourceFederal Register of LegislationTelecommunications (Interception and Access) Act 1979, sections 187BA and 187C (compilation of 4 June 2026)
legislation.gov.au
“the period ... ending 2 years after the closure of the account to which the information or document relates”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationPrivacy Act 1988, Australian Privacy Principle 11.2 — destruction or de-identification
legislation.gov.au
Link checked 18 August 2026
- Official sourceFederal Register of LegislationDigital ID Act 2024, section 51 — destruction of biometric information
legislation.gov.au
“the provider must destroy the information immediately after the verification is complete”
Link checked 18 August 2026
What happens if there is a breach?
Count four clocks, because they run at different speeds. If you pay a ransom and your Australian turnover is above A$3 million (about US$2 million), you have 72 hours to report the payment to the government. If you run critical infrastructure, you have 12 hours for an attack that seriously hits availability, and 72 hours for a lesser one. If you are a bank, insurer or superannuation fund, you have 72 hours for a security incident and only 24 hours if a critical service goes down beyond tolerance. For an ordinary personal data breach you get up to 30 days to assess whether it is serious, then you must tell the regulator and the affected people as soon as you practically can. There is no fixed hour count for that last one, which is the part people get wrong.
Cyber Security Act 2024 s 27, in force 29 May 2025, sets the 72-hour ransomware payment report; the A$3 million turnover threshold is set by the Cyber Security (Ransomware Payment Reporting) Rules 2025 s 6. Security of Critical Infrastructure Act 2018 s 30BC sets 12 hours for a critical cyber security incident and s 30BD sets 72 hours for other incidents with a relevant impact; both carry 50 penalty units. Prudential Standard CPS 234 requires notification within 72 hours of a material information security incident and within 10 business days of a material control weakness the entity cannot fix in time. CPS 230 adds 72 hours for a material operational risk incident and 24 hours for a disruption to a critical operation outside tolerance. Privacy Act 1988 s 26WH gives 30 days to assess a suspected eligible data breach; ss 26WK and 26WL then require the statement to the Commissioner and notification to individuals 'as soon as practicable'.
Sources
- Official sourceFederal Register of LegislationCyber Security Act 2024, section 27 — ransomware payment reporting within 72 hours
legislation.gov.au
“The reporting business entity must give the designated Commonwealth body a report (a ransomware payment report) that complies with the requirements of this section within 72 hours of making the ransomware payment”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationSecurity of Critical Infrastructure Act 2018, sections 30BC and 30BD — 12-hour and 72-hour cyber incident reports
legislation.gov.au
“do so as soon as practicable, and in any event within 12 hours, after the entity becomes so aware.”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationPrivacy Act 1988, sections 26WH, 26WK and 26WL — 30-day assessment then notification as soon as practicable
legislation.gov.au
“take all reasonable steps to ensure that the assessment is completed within 30 days after the entity becomes aware”
Link checked 18 August 2026
- Official sourceAustralian Prudential Regulation AuthorityPrudential Standard CPS 234 Information Security — 72-hour incident notification
apra.gov.au
“An APRA-regulated entity must notify APRA as soon as possible and, in any case, no later than 72 hours, after becoming aware of an information security incident”
Link checked 18 August 2026
What trips people up in Australia?
Five things that will cost you a weekend. First, moving national electronic health record data offshore is a crime, not a fine: up to five years in prison. Second, you never stop owning your supplier's mistakes — a major bank had to get a special ruling from the Privacy Commissioner just to keep processing international money transfers. Third, since December 2025 social media platforms must keep under-16s off the service and then destroy the age-check data they collected. Fourth, Queensland's rule for state government data is stricter than the national one and is hidden in section 33 of the Act, not in the numbered principles — the principle numbered 8 says there is no equivalent. Fifth, the value of a penalty unit rose to A$364 (about US$240) on 1 July 2026, so every fine figure you looked up before then is now understated.
(1) My Health Records Act 2012 s 77(2A): imprisonment for 5 years or 300 penalty units, plus a civil penalty of 1,500 penalty units (about A$546,000). (2) Privacy Act s 16C deems the overseas recipient's act to be the sender's breach; the Privacy (International Money Transfers) Public Interest Determinations 2025 (Nos 1 and 2) exist because a bank could not practically satisfy Principle 8.1 for correspondent banking. (3) Online Safety Act 2021 s 63D took effect 10 December 2025 by ministerial instrument; s 63F requires destruction of age assurance information and deems failure an interference with privacy; the platform penalty is 30,000 penalty units (about A$10.9 million). (4) Queensland Information Privacy Act 2009 s 33 permits disclosure outside Australia only on listed grounds, and the 'substantially similar law' route requires two or more of four conditions to be met, which is harder than the Commonwealth test. (5) Crimes (Amount of a Penalty Unit) Instrument 2026 set the unit at A$364 from 1 July 2026, up from A$330; the Privacy Act compilation of 4 June 2026 still prints the old figure in the Crimes Act, so a naive read gives the wrong number.
Sources
- Official sourceFederal Register of LegislationMy Health Records Act 2012, section 77(2A) — criminal offence for offshore handling
legislation.gov.au
“Penalty: Imprisonment for 5 years or 300 penalty units, or both.”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationOnline Safety Amendment (Social Media Minimum Age) Act 2024, section 63F — destruction of age assurance information
legislation.gov.au
“the entity must destroy the information after using or disclosing it for the purposes for which it was collected”
Link checked 18 August 2026
- Official sourceQueensland Parliamentary CounselInformation Privacy Act 2009 (Queensland), section 33 — disclosure of personal information outside Australia (current as at 1 July 2026)
legislation.qld.gov.au
“An agency may disclose an individual's personal information to an entity outside Australia only if— (a) the individual agrees to the disclosure; or (b) the disclosure is authorised or required under a law”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationCrimes (Amount of a Penalty Unit) Instrument 2026 — penalty unit set at A$364 from 1 July 2026
legislation.gov.au
“For the purposes of subsection 4AA(1A) of the Act, the amount of a penalty unit is $364.”
Link checked 18 August 2026
What is changing soon in Australia?
One date dominates: 10 December 2026. On that day privacy policies must start explaining computer-made decisions that significantly affect people, and the new Children's Online Privacy Code must be finalised and registered. The draft of that code was out for public comment from 31 March to 5 June 2026. Further out, the tougher critical infrastructure duties made in June 2026 start biting from mid-2027 and mid-2028 as their grace periods run out. Watch three switches the government already holds and can flip with no consultation.
Dormant switches. (1) Regulations may prescribe countries or binding schemes under Australian Privacy Principle 8.3, which would create an approved-destination list overnight; none has been made. (2) Section 77 of the Digital ID Act 2024 lets the Digital ID Rules prohibit, absolutely, the holding, storing, handling or transferring outside Australia of information generated by accredited entities in the Australian Government Digital ID System; the Digital ID Rules 2024 currently contain no such prohibition, so this is a fully drafted localisation power sitting unused. (3) Under Part IIIC Division 5 of the Privacy Act, inserted in December 2024, the Minister may make an eligible data breach declaration that authorises collection, use and disclosure of personal information after a major breach. Grace periods on the Enhanced Critical Infrastructure Risk Management Program Rules 2026 run 12 months for the additional material risks and 24 months for the cyber, personnel, supply chain and physical security requirements, measured from the instrument's commencement on 10 June 2026. We found no Australian data rule currently in abeyance or disapplied by a court, checked 18 August 2026.
Sources
- Official sourceFederal Register of LegislationPrivacy and Other Legislation Amendment Act 2024, commencement table item 7 and section 26GC(10)
legislation.gov.au
“7. Schedule 1, Part 15 — The day after the end of the period of 24 months beginning on the day this Act receives the Royal Assent. 10 December 2026”
Link checked 18 August 2026
- Official sourceOffice of the Australian Information CommissionerChildren's Online Privacy Code — status page, updated 5 August 2026
oaic.gov.au
“December 2026: The Code must be finalised and registered by 10 December 2026.”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationDigital ID Act 2024, section 77 — power to prohibit holding information outside Australia
legislation.gov.au
“the Digital ID Rules may: (a) prohibit (either absolutely or unless particular circumstances are met or conditions are complied with) the holding, storing, handling or transferring of such information outside Australia”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationEnhanced Critical Infrastructure Risk Management Program Rules 2026, section 4A(6) — 12 and 24 month grace periods
legislation.gov.au
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
2 rules here
Layer 2
State or provincial rule
Made by a state or province. Only binds you for people in that state.
1 rule here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
9 rules here
Layer 4
Contract-imposed rule
Binds you because you signed something, typically a government contract.
1 rule here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules2 rules
Privacy Act 1988
Act of parliament · Act No. 119 of 1988, as amended by Act No. 128 of 2024; compilation of 4 June 2026
Australia's general privacy law. It does not require data to stay in the country, but it makes you legally answerable for what your overseas supplier does. Businesses at or below A$3 million turnover are largely exempt. Two important pieces start on 10 December 2026: transparency about computer-made decisions, and a binding code for children's online privacy.
Enforced by Office of the Australian Information Commissioner
Transfer model: No restriction (the list is currently empty) · Accepted routes: Standard contract clauses, Official 'this country is safe' decision, Explicit consent
What it makes you do
- Tell people what you do
- Get consentConsent is required for sensitive information; other personal information generally turns on purpose and reasonable expectation rather than consent.
- Secure the data
- Let people see their data
- Let people correct their data
- Put a transfer safeguard in placeReasonable steps under Australian Privacy Principle 8.1, plus deemed liability for the overseas recipient under section 16C.
- Delete data after a periodDestroy or de-identify once no longer needed. No fixed period.
- Report breaches to the regulatorAssessment within 30 days; statement to the Commissioner as soon as practicable.
- Tell affected people
- Publish a complaints contact
- Get a parent's consent for children — applies at: under 18 (a 'child' is defined as an individual who has not reached 18 years), from 10 December 2026Detail sits in the Children's Online Privacy Code, which must be registered by 10 December 2026.
- Limit automated decisions — from 10 December 2026Privacy policies must describe computer-made decisions that could significantly affect a person's rights or interests.
What it costs if you get it wrong
- Fixed maximum fine: A$50,000,000 — about $33 millionSerious interference with privacy by a company
- Percentage of global turnover: 30% of adjusted turnover during the breach turnover periodSerious interference where the benefit cannot be valued
- Fixed maximum fine: 2,000 penalty units (about A$728,000) — about $480 thousandAny interference with privacy that is not serious
- Fixed maximum fine: 200 penalty units (about A$72,800) — about $48 thousandInfringement notice offences such as missing or defective privacy policy
- Claims by individualsStatutory tort of serious invasion of privacy, in force since 10 June 2025
Sources
- Official sourceFederal Register of LegislationPrivacy Act 1988 — current compilation (4 June 2026)
legislation.gov.au
“The amount of the penalty for a contravention of subsection (1) by a body corporate is an amount not more than the greatest of the following: (a) $50,000,000; (b) ... 3 times the value of that benefit; (c) ... 30% of the adjusted turnover of the body corporate during the breach turnover period”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationPrivacy and Other Legislation Amendment Act 2024 (No. 128, 2024) — commencement table and Schedules 1 to 3
legislation.gov.au
Link checked 18 August 2026
- Official sourceOffice of the Australian Information CommissionerAustralian Privacy Principles guidelines, Chapter 8
oaic.gov.au
Link checked 18 August 2026
Cyber Security Act 2024, Part 3
Act of parliament · Act No. 98 of 2024, with the Cyber Security (Ransomware Payment Reporting) Rules 2025
If your business turns over more than A$3 million in Australia and you pay a ransom, you have 72 hours to tell the government. The information is legally shielded: it can only be used for a short list of purposes and is not admissible against you in most proceedings.
Enforced by Australian Signals Directorate (Australian Cyber Security Centre)
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — applies at: Business carried on in Australia with annual turnover above A$3 million (about US$2 million) in the previous financial year, within 72 hoursReport the fact of the payment, the demand, the incident and the communications with the attacker.
What it costs if you get it wrong
- Fixed maximum fine: 60 penalty units (about A$21,840) — about $14 thousandFailing to report a ransomware payment within 72 hours
Sources
- Official sourceFederal Register of LegislationCyber Security Act 2024, sections 26 to 32 (Part 3 commenced 29 May 2025)
legislation.gov.au
“within 72 hours of making the ransomware payment or becoming aware that the ransomware payment has been made”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationCyber Security (Ransomware Payment Reporting) Rules 2025, section 6 — A$3 million turnover threshold
legislation.gov.au
“For the purposes of paragraph 26(3)(b) of the Act, the amount of turnover threshold for a business for the previous financial year is $3 million.”
Link checked 18 August 2026
State or provincial rule1 rule
Information Privacy Act 2009 (Queensland), section 33
Act of parliament · Queensland Act No. 14 of 2009; reprint current as at 1 July 2026 · Government
Queensland state agencies face a tighter offshore rule than the national one, and it is easy to miss. The rule sits in section 33 of the Act, not in the numbered Queensland privacy principles, and the principle numbered 8 says only that there is no Queensland equivalent. Relying on the recipient being covered by a similar law is not enough by itself.
Enforced by Office of the Information Commissioner Queensland
Transfer model: Approval each time · Accepted routes: Explicit consent, Standard contract clauses, Official 'this country is safe' decision
What it makes you do
- Put a transfer safeguard in placeThe comparable-protection route is not enough on its own. Two or more of four listed conditions must apply before a Queensland agency may send personal information abroad.
Sources
- Official sourceQueensland Parliamentary CounselInformation Privacy Act 2009 (Queensland), section 33 and Schedule 3 clause 8 (current as at 1 July 2026)
legislation.qld.gov.au
“QPP 8—cross-border disclosure of personal information. Editor's note— The Privacy Act 1988 (Cwlth), schedule 1 includes a privacy principle about requirements for cross-border disclosure of personal information (see APP 8). There is no equivalent QPP for APP 8.”
Link checked 18 August 2026
Industry rules9 rules
My Health Records Act 2012, section 77
Act of parliament · Act No. 63 of 2012; compilation of 1 July 2026 · Health and social care
Australia's hardest data wall. Data in the national My Health Record system may not be held, taken, processed or handled outside Australia at all, and doing so is a criminal offence carrying up to five years in prison. It binds the system operator and its registered repository, portal and contracted service providers, not every clinic in the country.
Enforced by Australian Digital Health Agency
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryNot just storage. Processing and handling the information outside Australia is banned too, and so is causing or permitting someone else to do it.
- Extra vendor secrecy termsThe ban follows the chain: registered contracted service providers are caught directly, so a standard cloud data processing agreement is not enough.
What it costs if you get it wrong
- Criminal liability: Imprisonment for 5 years or 300 penalty units (about A$109,200), or both — about $72 thousandHolding, taking, processing or handling My Health Record data outside Australia
- Fixed maximum fine: 1,500 penalty units (about A$546,000) — about $360 thousandCivil penalty for the same conduct
Sources
- Official sourceFederal Register of LegislationMy Health Records Act 2012, section 77 (compilation of 1 July 2026)
legislation.gov.au
“must not: (a) hold the records, or take the records, outside Australia; or (b) process or handle the information relating to the records outside Australia; or (c) cause or permit another person: (i) to hold the records, or take the records, outside Australia”
Link checked 18 August 2026
Prudential Standard CPS 230 Operational Risk Management
Directly binding regulation · Banking, Insurance, Life Insurance, Health Insurance and Superannuation (prudential standard) determination No. 1 of 2026 · Finance
Banks, insurers and superannuation funds must tell the prudential regulator before they enter any material offshoring arrangement, including where the data or the people will sit outside Australia. Offshoring is not banned, but it is a notified, supervised decision rather than a private one.
Enforced by Australian Prudential Regulation Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses
What it makes you do
- Register or notifyMaintain a register of material service providers and submit it to the regulator every year.
- Written vendor contractFormal agreements must cover sub-contracting and make the provider liable for its sub-contractors.
- Put a transfer safeguard in placeNotify the regulator before entering any material offshoring arrangement, or when significantly changing one, including where data will be located offshore.
- Report cyber incidents — within 72 hoursMaterial operational risk incident.
- Report cyber incidents — within 24 hoursDisruption to a critical operation outside tolerance.
What it costs if you get it wrong
- Loss of your licencePrudential standards are enforced through licence conditions and directions rather than a headline fine.
Sources
- Official sourceAustralian Prudential Regulation AuthorityPrudential Standard CPS 230 Operational Risk Management, determination No. 1 of 2026, commencing 1 July 2026
apra.gov.au
“Material offshoring arrangement means a material arrangement where the service provided is undertaken outside Australia. Offshoring includes arrangements where the service provider is incorporated in Australia, but the physical location of the service being provided is undertaken outside Australia.”
Link checked 18 August 2026
Prudential Standard CPS 234 Information Security
Directly binding regulation · CPS 234 · Finance
Banks, insurers and superannuation funds must notify the prudential regulator within 72 hours of a material information security incident, and within 10 business days of a material control weakness they cannot fix in time. This clock runs separately from the privacy breach clock and usually starts earlier.
Enforced by Australian Prudential Regulation Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the data
- Report cyber incidents — within 72 hoursMaterial information security incident.
- Independent auditInternal audit must review the design and operating effectiveness of information security controls, including those maintained by third parties.
Sources
- Official sourceAustralian Prudential Regulation AuthorityPrudential Standard CPS 234 Information Security, commencing 1 July 2019
apra.gov.au
“An APRA-regulated entity must notify APRA as soon as possible and, in any case, no later than 72 hours, after becoming aware of an information security incident”
Link checked 18 August 2026
Competition and Consumer (Consumer Data Right) Rules 2020
Directly binding regulation · F2020L00094, made 4 February 2020; version of 4 March 2025 · Account aggregators
Open banking data can go overseas, but the accredited Australian firm answers for its overseas suppliers, and its published data policy must list the countries those suppliers sit in. Failing to control an offshore supplier is itself a penalty offence for the Australian firm.
Enforced by Australian Competition and Consumer Commission
Transfer model: No restriction · Accepted routes: Standard contract clauses, Certification scheme
What it makes you do
- Put a transfer safeguard in placePrivacy Safeguard 8 in the Competition and Consumer Act 2010 governs overseas disclosure of open banking data.
- Tell people what you doThe public data policy must name the countries where overseas outsourced providers are likely to be based, where practicable.
- Written vendor contractAn accredited firm breaches the rules if its overseas outsourced provider fails to meet Privacy Safeguard 8; this is a civil penalty provision.
- Delete data after a periodRedundant consumer data must be deleted or de-identified.
Sources
- Official sourceFederal Register of LegislationCompetition and Consumer (Consumer Data Right) Rules 2020, rules 7.2, 7.8A and 7.8B
legislation.gov.au
“An accredited person breaches this subrule if a direct or indirect OSP of: (a) the accredited person; or (b) a CDR representative of the accredited person; fails to comply with section 56EK of the Act”
Link checked 18 August 2026
- Official sourceOffice of the Australian Information CommissionerConsumer Data Right Privacy Safeguard Guidelines, Chapter 8 — overseas disclosure
oaic.gov.au
Link checked 18 August 2026
Security of Critical Infrastructure Act 2018
Act of parliament · Act No. 29 of 2018, as amended by Act No. 100 of 2024; compilation of 4 June 2026
Critical infrastructure operators face the shortest incident clock in Australia: 12 hours for a serious cyber attack and 72 hours for a lesser one. Since 2025 a data storage system holding business critical data is treated as part of the asset itself, so a database can drag a company into this regime. Companies that store or process data for government are directly in scope as critical data storage or processing assets.
Enforced by Department of Home Affairs (Cyber and Infrastructure Security Centre)
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 12 hoursCyber incident with a significant impact on the availability of the asset.
- Report cyber incidents — within 72 hoursCyber incident with a relevant impact on the asset.
- Register or notifyOwnership and operational information must be given to the register of critical infrastructure assets.
What it costs if you get it wrong
- Fixed maximum fine: 50 penalty units (about A$18,200) per contravention — about $12 thousandFailure to report a cyber security incident in time
Sources
- Official sourceFederal Register of LegislationSecurity of Critical Infrastructure Act 2018, sections 9(7), 12F, 30BC and 30BD
legislation.gov.au
“If, under this section, an asset is a critical infrastructure asset, then a data storage system in respect of which all of the following requirements are satisfied is taken to be part of the critical infrastructure asset”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationSecurity of Critical Infrastructure (Telecommunications Security and Risk Management Program) Rules 2025
legislation.gov.au
Link checked 18 August 2026
Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026
Government rules · LIN 26/075, F2026L00701, made 4 June 2026
The closest thing Australia has to a creeping localisation rule. From June 2026, nine critical infrastructure classes must treat offshore or remote access to business critical data as a material risk and cut it down as far as they reasonably can. It is not a ban, but it pushes operators towards keeping data and access onshore. Grace periods mean it starts biting in June 2027 and June 2028.
Enforced by Department of Home Affairs (Cyber and Infrastructure Security Centre)
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Check your algorithms — applies at: Nine asset classes: broadcasting, domain name systems, electricity, energy market operators, freight infrastructure, freight services, gas, liquid fuel, water, from 10 June 2027Offshore or remote access to business critical data must be treated as a material risk and minimised or eliminated so far as reasonably practicable.
- Hold a security certificate — from 10 June 2028Comply with the international information security standard AS ISO/IEC 27001:2023 or reach maturity level two of the government's Essential Eight model.
- Written vendor contract — from 10 June 2028Map the supply chain and assess each major supplier for foreign ownership, control or influence, including the foreign laws that supplier is subject to.
Sources
- Official sourceFederal Register of LegislationEnhanced Critical Infrastructure Risk Management Program Rules 2026, sections 4A, 6A, 8A and 10A
legislation.gov.au
“For subsection 30AH(8) of the Act, the following specified risks are additional material risks: ... (c) offshore or remote access to critical components; and (d) offshore or remote access to business critical data.”
Link checked 18 August 2026
Telecommunications (Interception and Access) Act 1979, Part 5-1A
Act of parliament · Act No. 114 of 1979; compilation No. 133 of 4 June 2026 · Telecoms
Phone and internet providers must keep call and connection records for two years and must encrypt them. The law does not say where those records have to sit, but it does apply the national privacy law to them even for providers too small to be covered otherwise.
Enforced by Australian Communications and Media Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 2 yearsTwo years from creation, or from closure of the account for subscriber details.
- Secure the dataRetained data must be encrypted and protected from unauthorised access.
- Keep logs — 2 years
Sources
- Official sourceFederal Register of LegislationTelecommunications (Interception and Access) Act 1979, sections 187A, 187BA, 187C and 187LA
legislation.gov.au
“A service provider must protect the confidentiality of information that ... the service provider must keep, or cause to be kept, under section 187A by: (a) encrypting the information; and (b) protecting the information from unauthorised interference or unauthorised access.”
Link checked 18 August 2026
Online Safety Act 2021, Part 4A (inserted by the Online Safety Amendment (Social Media Minimum Age) Act 2024)
Act of parliament · Act No. 127 of 2024; day of effect fixed by the Online Safety (Day of Effect of Social Media Minimum Age) Instrument 2025 · Social media and online platforms
Since 10 December 2025 social media platforms must take reasonable steps to stop Australians under sixteen having accounts. The privacy sting is in the tail: whatever you collect to check someone's age must be destroyed afterwards, and keeping it is treated as a privacy breach.
Enforced by eSafety Commissioner
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Get a parent's consent for children — applies at: under 16, from 10 December 2025There is no parental consent route. Under-16s may not hold accounts on an age-restricted social media platform at all.
- Delete data after a period — from 10 December 2025Information collected to check age must be destroyed once it has been used for that purpose.
What it costs if you get it wrong
- Fixed maximum fine: 30,000 penalty units (about A$10.9 million) — about $7 millionPlatform failing to take reasonable steps to prevent under-16 accounts
Sources
- Official sourceFederal Register of LegislationOnline Safety Amendment (Social Media Minimum Age) Act 2024, sections 63C, 63D and 63F
legislation.gov.au
“age-restricted user means an Australian child who has not reached 16 years.”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationOnline Safety (Day of Effect of Social Media Minimum Age) Instrument 2025
legislation.gov.au
“specify 10 December 2025 as the day section 63D of that Act takes effect.”
Link checked 18 August 2026
Digital ID Act 2024, section 77
Act of parliament · Act No. 25 of 2024 · Government
A loaded gun that has not been fired. The law lets the government make rules that absolutely ban holding, storing, handling or transferring Australian Government digital identity data outside Australia. As at 18 August 2026 the rules contain no such ban, so digital identity data may currently go offshore. This can change by ministerial rule with no consultation.
Enforced by Australian Competition and Consumer Commission
Transfer model: No restriction (the list is currently empty) · Accepted routes: Nothing required
What it makes you do
- Delete data after a periodBiometric information must be destroyed immediately after the identity check is complete.
- Keep the data in the countryNot currently required. The power to require it exists and has not been used.
What it costs if you get it wrong
- Fixed maximum fine: 1,500 penalty units (about A$546,000) — about $360 thousandBreaching a localisation requirement, if one is ever made in the rules
Sources
- Official sourceFederal Register of LegislationDigital ID Act 2024, sections 51 and 77
legislation.gov.au
“The Digital ID Rules may make provision in relation to the holding, storing, handling or transfer of information outside Australia if the information is or was generated, collected, held or stored by accredited entities within the Australian Government Digital ID System.”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationDigital ID Rules 2024 — full text, containing no offshore prohibition
legislation.gov.au
Link checked 18 August 2026
Contract-imposed rule1 rule
Hosting Certification Framework
Government policy document · Whole-of-Government Hosting Strategy; administered by the Department of Home Affairs since 1 May 2023 · Government
If you host Australian Government data, the buying rules bite before the privacy law does. Sensitive government data and anything at the PROTECTED classification must be hosted using certified services, with sovereignty and ownership controls attached. This is procurement policy rather than a statute, so it reaches you through the contract.
Enforced by Department of Home Affairs (Cyber and Infrastructure Security Centre)
Transfer model: Allowlist · Accepted routes: Certification scheme
What it makes you do
- Hold a security certificateSensitive government data, whole-of-government systems and anything classified PROTECTED must sit with a certified hosting provider.
- Prove the data stays under local control
Sources
- Official sourceDepartment of Home AffairsHosting Certification Framework
hostingcertification.gov.au
“all sensitive government data, Whole-of-Government systems and systems rated at the classification level of PROTECTED must be hosted using certified services”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That no country or binding scheme has been prescribed under Australian Privacy Principle 8.3
We proved this by reading the whole of the Privacy Regulations 2025 and finding no such provision, and by checking the regulator's own guidance, which lists none. We cannot rule out a separate instrument made between 1 and 18 August 2026. Treat as a negative inferred from the primary text rather than a positive government statement.
The date Prudential Standard CPS 230 first applied to regulated entities
The version now on the regulator's site is determination No. 1 of 2026, dated 23 April 2026 and commencing 1 July 2026. Earlier versions of the standard existed, but we did not open them, so the record shows only the current instrument's dates. Anyone tracing an obligation back before July 2026 should check the superseded determination.
Whether the Protective Security Policy Framework contains its own offshore storage restriction for Australian Government information
The framework's own website blocked automated access beyond the home page. We could confirm the Hosting Certification Framework requirement but not the underlying protective security requirement text.
New South Wales health privacy rules on transferring health information outside the state
The New South Wales legislation website returned an access-denied response to every attempt. Health Privacy Principle 14 of the Health Records and Information Privacy Act 2002 is widely reported to restrict transfers outside New South Wales, but we could not open the official text and have therefore left it out of the rules.
The exact date the 12-hour and 72-hour critical infrastructure incident reports first became enforceable
The reporting duties were switched on for named asset classes by the Security of Critical Infrastructure (Application) Rules 2022, which we opened, but we did not verify the grace period that followed. The record therefore shows the Act's commencement and leaves the enforceable-from date blank rather than guessing.
The commencement date of the telecommunications data retention part (13 October 2015) and therefore the end of its 18-month implementation phase
We verified from the statute that the implementation phase runs 18 months from commencement of the Part, but did not open the commencement instrument itself. The dates shown are consistent with the statute but the start date is not independently evidenced here.
Minimum retention periods for tax and company records
Not verified in this pass. The floors quoted in commercial guidance (commonly five to seven years) were not checked against the Income Tax Assessment Act or the Corporations Act.
Whether any location rule exists for mapping and geospatial data, defence industry data, education data or online gambling data
No rule found on a government source, checked 18 August 2026. This is an absence of evidence rather than evidence of absence; defence industry obligations in particular are largely contractual and not published.
eSafety Commissioner enforcement activity on the under-16 social media rule during 2026
The regulator's website timed out and blocked automated fetching throughout this run. The statutory obligation and its start date are verified from the legislation itself; the enforcement record is not.
The exact status of the second tranche of Privacy Act reform
The Attorney-General's Department privacy page appears not to have been updated since the 2023 review report and does not mention the 2024 amendment Act. We found no bill for a further tranche, but cannot confirm from a current government statement that none is before Parliament.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Australia versus Argentina
- Australia versus Armenia
- Australia versus Austria
- Australia versus Azerbaijan
- Australia versus Brazil
- Australia versus Bulgaria
- Australia versus Cambodia
- Australia versus Canada
- Australia versus China
- Australia versus Croatia
- Australia versus Cyprus
- Australia versus Estonia
- Australia versus France
- Australia versus Georgia
- Australia versus Germany
- Australia versus Greece
- Australia versus Hong Kong SAR
- Australia versus Hungary
- Australia versus Iceland
- Australia versus India
- Australia versus Indonesia
- Australia versus Ireland
- Australia versus Israel
- Australia versus Italy
- Australia versus Japan
- Australia versus Latvia
- Australia versus Lithuania
- Australia versus Luxembourg
- Australia versus Malta
- Australia versus Mexico
- Australia versus Mongolia
- Australia versus Nepal
- Australia versus Netherlands
- Australia versus Poland
- Australia versus Russia
- Australia versus Saudi Arabia
- Australia versus Serbia
- Australia versus Singapore
- Australia versus Slovakia
- Australia versus Slovenia
- Australia versus South Korea
- Australia versus Spain
- Australia versus Sri Lanka
- Australia versus Sweden
- Australia versus Switzerland
- Australia versus Taiwan
- Australia versus Thailand
- Australia versus Turkey
- Australia versus Ukraine
- Australia versus United Arab Emirates
- Australia versus United Kingdom
- Australia versus United States
- Australia versus Uzbekistan