Skip to the content
Global Data RulesData governance rules, country by country

Australia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Depends on your industryWork: MediumEnforcement: Active

Australia has no general rule that data must stay in the country. You may send personal information anywhere, and no destination is banned. The catch is that you stay legally responsible for whatever your overseas supplier does with it. Small businesses under A$3 million turnover are exempt from the main privacy law. Specific industries are far stricter, and one of them carries a prison sentence.

Eight questions about Australia

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Australia's rules apply to my company?

Yes, it reaches you even with no office in Australia. The national privacy law applies to any organisation that carries on business in Australia, whether or not the data is collected or stored here. But Australia has something most countries do not: a real size threshold you can fall below. A business with annual turnover of A$3 million (about US$2 million) or less is generally exempt. That exemption has big holes: it does not apply if you provide a health service, if you buy or sell personal information, or if you supply services under a federal government contract. No local representative and no registration are required.

High confidenceNational rulesController

Can I store my users' data outside Australia?

In general, yes. Australia has no national law saying personal data must be kept in the country, and no country is blacklisted. You can pick any cloud region you like. What you cannot do is hand off the risk: if your overseas supplier does something with the data that would break Australian rules, the law treats that as your own breach. The hard walls are industry by industry, and the health one is absolute.

High confidenceDepends on your industryNo restrictionPut a transfer safeguard in place

What do I need in place before data leaves Australia?

Before data leaves, you must take reasonable steps to make sure the overseas recipient will handle it the Australian way. In practice that means a contract with the right promises in it. There is no government form to file, no approval to wait for, and no list of approved countries to check. A power to approve countries was switched on in December 2024, but as of today the government has not named a single one. The alternative routes are narrow: you can rely on the recipient already being covered by a substantially similar law, or on the person's informed consent after you warn them you will no longer be responsible.

High confidenceNo restrictionStandard contract clausesOfficial 'this country is safe' decisionExplicit consentWritten vendor contract

Who enforces the rules in Australia, and what can they do?

The Office of the Australian Information Commissioner. It is staffed, it has a sitting Privacy Commissioner, and it is issuing decisions. In October 2025 the Federal Court ordered a pathology company to pay A$5.8 million (about US$3.8 million), the first court penalty in the law's history. The regulator sued Optus in August 2025, settled with Meta for A$50 million in December 2024, and in June 2026 alone published formal findings against Optus, American Express and two health providers. Banking, cyber security, online safety and open banking each have their own separate regulator, and all of them are working.

High confidenceActiveRegulator

How long do I have to keep the data?

There is a floor and a ceiling and they pull in opposite directions. The clearest floor is telecoms: phone and internet providers must keep call and connection records for two years, and must encrypt them. The general ceiling has no number attached — you must destroy or de-identify personal information once you genuinely no longer need it. Two ceilings are sharp. A social media platform must destroy age-check information as soon as it has finished using it. A digital identity provider must destroy a face or fingerprint scan immediately after the identity check is complete.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logsSecure the data

What happens if there is a breach?

Count four clocks, because they run at different speeds. If you pay a ransom and your Australian turnover is above A$3 million (about US$2 million), you have 72 hours to report the payment to the government. If you run critical infrastructure, you have 12 hours for an attack that seriously hits availability, and 72 hours for a lesser one. If you are a bank, insurer or superannuation fund, you have 72 hours for a security incident and only 24 hours if a critical service goes down beyond tolerance. For an ordinary personal data breach you get up to 30 days to assess whether it is serious, then you must tell the regulator and the affected people as soon as you practically can. There is no fixed hour count for that last one, which is the part people get wrong.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Australia?

Five things that will cost you a weekend. First, moving national electronic health record data offshore is a crime, not a fine: up to five years in prison. Second, you never stop owning your supplier's mistakes — a major bank had to get a special ruling from the Privacy Commissioner just to keep processing international money transfers. Third, since December 2025 social media platforms must keep under-16s off the service and then destroy the age-check data they collected. Fourth, Queensland's rule for state government data is stricter than the national one and is hidden in section 33 of the Act, not in the numbered principles — the principle numbered 8 says there is no equivalent. Fifth, the value of a penalty unit rose to A$364 (about US$240) on 1 July 2026, so every fine figure you looked up before then is now understated.

High confidenceCriminal liabilityGet a parent's consent for childrenDelete data after a periodState or provincial rule

What is changing soon in Australia?

One date dominates: 10 December 2026. On that day privacy policies must start explaining computer-made decisions that significantly affect people, and the new Children's Online Privacy Code must be finalised and registered. The draft of that code was out for public comment from 31 March to 5 June 2026. Further out, the tougher critical infrastructure duties made in June 2026 start biting from mid-2027 and mid-2028 as their grace periods run out. Watch three switches the government already holds and can flip with no consultation.

High confidencePartly in forceProposed

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    2 rules here

  2. Layer 2

    State or provincial rule

    Made by a state or province. Only binds you for people in that state.

    1 rule here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    9 rules here

  4. Layer 4

    Contract-imposed rule

    Binds you because you signed something, typically a government contract.

    1 rule here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules2 rules

Privacy Act 1988

Act of parliament · Act No. 119 of 1988, as amended by Act No. 128 of 2024; compilation of 4 June 2026

Partly in forceYes, with paperwork

Australia's general privacy law. It does not require data to stay in the country, but it makes you legally answerable for what your overseas supplier does. Businesses at or below A$3 million turnover are largely exempt. Two important pieces start on 10 December 2026: transparency about computer-made decisions, and a binding code for children's online privacy.

In force since 1 January 1989

Enforced by Office of the Australian Information Commissioner

Transfer model: No restriction (the list is currently empty) · Accepted routes: Standard contract clauses, Official 'this country is safe' decision, Explicit consent

High confidence

Cyber Security Act 2024, Part 3

Act of parliament · Act No. 98 of 2024, with the Cyber Security (Ransomware Payment Reporting) Rules 2025

In forceYes — store it anywhere

If your business turns over more than A$3 million in Australia and you pay a ransom, you have 72 hours to tell the government. The information is legally shielded: it can only be used for a short list of purposes and is not admissible against you in most proceedings.

In force since 29 May 2025

Enforced by Australian Signals Directorate (Australian Cyber Security Centre)

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

State or provincial rule1 rule

Information Privacy Act 2009 (Queensland), section 33

Act of parliament · Queensland Act No. 14 of 2009; reprint current as at 1 July 2026 · Government

In forceYes, with paperwork

Queensland state agencies face a tighter offshore rule than the national one, and it is easy to miss. The rule sits in section 33 of the Act, not in the numbered Queensland privacy principles, and the principle numbered 8 says only that there is no Queensland equivalent. Relying on the recipient being covered by a similar law is not enough by itself.

In force since 1 July 2009

Enforced by Office of the Information Commissioner Queensland

Transfer model: Approval each time · Accepted routes: Explicit consent, Standard contract clauses, Official 'this country is safe' decision

High confidence

Industry rules9 rules

My Health Records Act 2012, section 77

Act of parliament · Act No. 63 of 2012; compilation of 1 July 2026 · Health and social care

In forceNo — it stays put

Australia's hardest data wall. Data in the national My Health Record system may not be held, taken, processed or handled outside Australia at all, and doing so is a criminal offence carrying up to five years in prison. It binds the system operator and its registered repository, portal and contracted service providers, not every clinic in the country.

In force since 1 July 2012

Enforced by Australian Digital Health Agency

Transfer model: Not allowed

High confidence

Prudential Standard CPS 230 Operational Risk Management

Directly binding regulation · Banking, Insurance, Life Insurance, Health Insurance and Superannuation (prudential standard) determination No. 1 of 2026 · Finance

In forceYes, with paperwork

Banks, insurers and superannuation funds must tell the prudential regulator before they enter any material offshoring arrangement, including where the data or the people will sit outside Australia. Offshoring is not banned, but it is a notified, supervised decision rather than a private one.

In force since 1 July 2026

Enforced by Australian Prudential Regulation Authority

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses

High confidence

Prudential Standard CPS 234 Information Security

Directly binding regulation · CPS 234 · Finance

In forceYes — store it anywhere

Banks, insurers and superannuation funds must notify the prudential regulator within 72 hours of a material information security incident, and within 10 business days of a material control weakness they cannot fix in time. This clock runs separately from the privacy breach clock and usually starts earlier.

In force since 1 July 2019

Enforced by Australian Prudential Regulation Authority

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Contract-imposed rule1 rule

Hosting Certification Framework

Government policy document · Whole-of-Government Hosting Strategy; administered by the Department of Home Affairs since 1 May 2023 · Government

In forceYes, with paperwork

If you host Australian Government data, the buying rules bite before the privacy law does. Sensitive government data and anything at the PROTECTED classification must be hosted using certified services, with sovereignty and ownership controls attached. This is procurement policy rather than a statute, so it reaches you through the contract.

Enforced by Department of Home Affairs (Cyber and Infrastructure Security Centre)

Transfer model: Allowlist · Accepted routes: Certification scheme

Medium confidence

Who you would hear from

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That no country or binding scheme has been prescribed under Australian Privacy Principle 8.3

    We proved this by reading the whole of the Privacy Regulations 2025 and finding no such provision, and by checking the regulator's own guidance, which lists none. We cannot rule out a separate instrument made between 1 and 18 August 2026. Treat as a negative inferred from the primary text rather than a positive government statement.

  • The date Prudential Standard CPS 230 first applied to regulated entities

    The version now on the regulator's site is determination No. 1 of 2026, dated 23 April 2026 and commencing 1 July 2026. Earlier versions of the standard existed, but we did not open them, so the record shows only the current instrument's dates. Anyone tracing an obligation back before July 2026 should check the superseded determination.

  • Whether the Protective Security Policy Framework contains its own offshore storage restriction for Australian Government information

    The framework's own website blocked automated access beyond the home page. We could confirm the Hosting Certification Framework requirement but not the underlying protective security requirement text.

  • New South Wales health privacy rules on transferring health information outside the state

    The New South Wales legislation website returned an access-denied response to every attempt. Health Privacy Principle 14 of the Health Records and Information Privacy Act 2002 is widely reported to restrict transfers outside New South Wales, but we could not open the official text and have therefore left it out of the rules.

  • The exact date the 12-hour and 72-hour critical infrastructure incident reports first became enforceable

    The reporting duties were switched on for named asset classes by the Security of Critical Infrastructure (Application) Rules 2022, which we opened, but we did not verify the grace period that followed. The record therefore shows the Act's commencement and leaves the enforceable-from date blank rather than guessing.

  • The commencement date of the telecommunications data retention part (13 October 2015) and therefore the end of its 18-month implementation phase

    We verified from the statute that the implementation phase runs 18 months from commencement of the Part, but did not open the commencement instrument itself. The dates shown are consistent with the statute but the start date is not independently evidenced here.

  • Minimum retention periods for tax and company records

    Not verified in this pass. The floors quoted in commercial guidance (commonly five to seven years) were not checked against the Income Tax Assessment Act or the Corporations Act.

  • Whether any location rule exists for mapping and geospatial data, defence industry data, education data or online gambling data

    No rule found on a government source, checked 18 August 2026. This is an absence of evidence rather than evidence of absence; defence industry obligations in particular are largely contractual and not published.

  • eSafety Commissioner enforcement activity on the under-16 social media rule during 2026

    The regulator's website timed out and blocked automated fetching throughout this run. The statutory obligation and its start date are verified from the legislation itself; the enforcement record is not.

  • The exact status of the second tranche of Privacy Act reform

    The Attorney-General's Department privacy page appears not to have been updated since the 2023 review report and does not mention the 2024 amendment Act. We found no bill for a further tranche, but cannot confirm from a current government statement that none is before Parliament.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.