Skip to the content
Global Data RulesData governance rules, country by country

Australia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Australia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: MediumEnforcement: Active

Australia has no general rule that data must stay in the country. You may send personal information anywhere, and no destination is banned. The catch is that you stay legally responsible for what your overseas supplier does with it. Small businesses under 3 million Australian dollars turnover are exempt from the main privacy law. Some industries are far stricter, and one of them carries a prison sentence.

Data governance in Australia

The eight things that decide how you handle data about people in Australia. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, it reaches you even with no office in Australia. The national privacy law applies to any organisation that carries on business in Australia. It does not matter whether the data is collected or stored here. But Australia has something most countries do not: a real size cut-off you can fall below. A business with annual turnover of 3 million Australian dollars (about 2 million US dollars) or less is usually exempt. That exemption has big holes. It does not apply if you provide a health service. It does not apply if you buy or sell personal information. And it does not apply if you supply services under a federal government contract. You need no local representative and no registration.

Where the data is allowed to live

In general, yes. Australia has no national law saying personal data must be kept in the country. No country is banned. You can pick any cloud region you like. What you cannot do is hand off the risk. If your overseas supplier does something with the data that would break Australian rules, the law treats that as your own breach. The strict rules are industry by industry, and the health one is absolute.

What you have to do here:
Put a transfer safeguard in place

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

Before data leaves, you must take reasonable steps to make sure the overseas recipient handles it the Australian way. That usually means a contract with the right promises in it. There is no government form to file, no approval to wait for, and no list of approved countries to check. A power to approve countries was switched on in December 2024. The government has not named a single one. The other routes are narrow. You can rely on the recipient already being covered by a substantially similar law. Or you can rely on the person's informed consent, after you warn them you will no longer be responsible.

What you have to do here:
Written vendor contract
Ways to send data out:
Standard contract clauses · Official 'this country is safe' decision · Explicit consent

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Office of the Australian Information Commissioner. It is staffed, it has a sitting Privacy Commissioner, and it is issuing decisions. In October 2025 the Federal Court ordered a pathology company to pay 5.8 million Australian dollars (about 3.8 million US dollars). That was the first court penalty in the law's history. The regulator sued Optus in August 2025 and settled with Meta for 50 million Australian dollars in December 2024. In June 2026 alone it published formal findings against Optus, American Express and two health providers. Banking, cyber security, online safety and open banking each have their own separate regulator, and all of them are working.

How long you must keep it — and when to delete it

There is a minimum and a maximum, and they pull in opposite directions. The clearest minimum is telecoms. Phone and internet providers must keep call and connection records for two years, and must encrypt them. The general maximum has no number attached. You must destroy or de-identify personal information once you truly no longer need it. Two maximums are sharp. A social media platform must destroy age-check information as soon as it has finished using it. A digital identity provider must destroy a face or fingerprint scan immediately after the identity check is complete.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Secure the data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count four deadlines, because they run at different speeds. Say you pay a ransom, and your Australian turnover is above 3 million Australian dollars (about 2 million US dollars). You then have 72 hours to report the payment to the government. If you run critical infrastructure, you have 12 hours for an attack that seriously hits availability, and 72 hours for a lesser one. If you are a bank, insurer or superannuation fund, you have 72 hours for a security incident. You have only 24 hours if a critical service goes down beyond tolerance. For an ordinary personal data breach you get up to 30 days to assess whether it is serious. You must then tell the regulator and the affected people as soon as you practically can. There is no fixed hour count for that last one, which is the part people get wrong.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. First, moving national electronic health record data overseas is a crime, not a fine. It carries up to five years in prison. Second, you never stop owning your supplier's mistakes. A major bank had to get a special ruling from the Privacy Commissioner just to keep handling international money transfers. Third, since December 2025 social media platforms must keep under-16s off the service. They must then destroy the age-check data they collected. Fourth, Queensland's rule for state government data is stricter than the national one. It hides in section 33 of the Act, not in the numbered principles. The principle numbered 8 says there is no equivalent. Fifth, the value of a penalty unit rose to 364 Australian dollars (about 240 US dollars) on 1 July 2026. So every fine figure you looked up before then is now too low.

What you have to do here:
Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability

What's changing next

One date dominates: 10 December 2026. From that day, privacy policies must explain computer-made decisions that significantly affect people. The new Children's Online Privacy Code must also be finalised and registered by then. The draft of that code was out for public comment from 31 March to 5 June 2026. Further out, the tougher critical infrastructure duties made in June 2026 start to apply from mid-2027 and mid-2028, as their grace periods run out. Watch three powers the government already holds and can use with no consultation.

What to do: Diarise 10 December 2026 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries9 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Health and social care

Health data rules

Official name: My Health Records Act 2012, section 77 · Act No. 63 of 2012; compilation of 1 July 2026 · Act of parliament

In forceNo — it stays put

This is Australia's strictest data rule. Data in the national My Health Record system may not be held, taken, used or handled outside Australia at all. Doing so is a crime carrying up to five years in prison. It binds the system operator and its registered repository, portal and contracted service providers. It does not bind every clinic in the country.

In force since 1 July 2012

Enforced by Australian Digital Health Agency

How this country controls where data goes: Not allowed

Finance

Banking rules

Official name: Prudential Standard CPS 230 Operational Risk Management · Banking, Insurance, Life Insurance, Health Insurance and Superannuation (prudential standard) determination No. 1 of 2026 · Directly binding regulation

In forceYes, with paperwork

Banks, insurers and superannuation funds must tell the prudential regulator before entering any material overseas arrangement. That includes arrangements where the data or the people will sit outside Australia. Going overseas is not banned. But it is a notified, supervised decision rather than a private one.

In force since 1 July 2026

Enforced by Australian Prudential Regulation Authority

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses

Finance

Banking rules (Finance)

Official name: Prudential Standard CPS 234 Information Security · CPS 234 · Directly binding regulation

In forceYes — store it anywhere

Banks, insurers and superannuation funds must notify the prudential regulator within 72 hours of a material information security incident. They have 10 business days for a material control weakness they cannot fix in time. This deadline runs separately from the privacy breach deadline, and usually starts earlier.

In force since 1 July 2019

Enforced by Australian Prudential Regulation Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Privacy Act 1988 · Act No. 119 of 1988, as amended by Act No. 128 of 2024; compilation of 4 June 2026 · Act of parliament

Partly in forceYes, with paperwork

Australia's general privacy law. It does not require data to stay in the country. But it makes you legally answerable for what your overseas supplier does. Businesses at or below 3 million Australian dollars turnover are largely exempt. Two important pieces start on 10 December 2026. One is transparency about computer-made decisions. The other is a binding code for children's online privacy.

In force since 1 January 1989

Enforced by Office of the Australian Information Commissioner

How this country controls where data goes: No restriction (no country is on the approved list yet) · Accepted routes: Standard contract clauses, Official 'this country is safe' decision, Explicit consent

Cyber security rules

Official name: Cyber Security Act 2024, Part 3 · Act No. 98 of 2024, with the Cyber Security (Ransomware Payment Reporting) Rules 2025 · Act of parliament

In forceYes — store it anywhere

Say your business turns over more than 3 million Australian dollars in Australia, and you pay a ransom. You then have 72 hours to tell the government. The information is legally protected. It can only be used for a short list of purposes, and it cannot be used against you in most proceedings.

In force since 29 May 2025

Enforced by Australian Signals Directorate (Australian Cyber Security Centre)

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies only in certain states1 rule

Made by a state or province. It only binds you for the people living there.

Government

Telecoms rules

Official name: Information Privacy Act 2009 (Queensland), section 33 · Queensland Act No. 14 of 2009; reprint current as at 1 July 2026 · Act of parliament

In forceYes, with paperwork

Queensland state agencies face a tighter overseas rule than the national one, and it is easy to miss. The rule sits in section 33 of the Act, not in the numbered Queensland privacy principles. The principle numbered 8 says only that there is no Queensland equivalent. Relying on the recipient being covered by a similar law is not enough on its own.

In force since 1 July 2009

Enforced by Office of the Information Commissioner Queensland

How this country controls where data goes: Approval each time · Accepted routes: Explicit consent, Standard contract clauses, Official 'this country is safe' decision

Applies only if you signed a contract1 rule

Usually a government or enterprise contract that adds rules of its own.

Government

Government data needs a sovereign cloud

Official name: Hosting Certification Framework · Whole-of-Government Hosting Strategy; administered by the Department of Home Affairs since 1 May 2023 · Government policy document

In forceYes, with paperwork

If you host Australian Government data, the buying rules apply before the privacy law does. Sensitive government data, and anything at the PROTECTED classification, must be hosted using certified services. Sovereignty and ownership controls come with that. This is buying policy rather than a law, so it reaches you through your contract.

Enforced by Department of Home Affairs (Cyber and Infrastructure Security Centre)

How this country controls where data goes: Only approved countries · Accepted routes: Certification scheme

Not fully verified — see “What we're not sure about” below.

Who you would hear from

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That no country or binding scheme has been prescribed under Australian Privacy Principle 8.3

    We read the whole of the Privacy Regulations 2025 and found no such rule. We also checked the regulator's own guidance, which lists none. We cannot rule out a separate rule made between 1 and 18 August 2026. Treat this as our reading of the law, not a government statement.

  • The date Prudential Standard CPS 230 first applied to regulated entities

    The version now on the regulator's site is determination No. 1 of 2026, dated 23 April 2026 and starting 1 July 2026. Earlier versions of the standard existed, and we did not open them. So this record shows only the current dates. If you need to trace a duty back before July 2026, check the earlier determination.

  • Whether the Protective Security Policy Framework contains its own offshore storage restriction for Australian Government information

    We could not read the protective security policy pages beyond the home page. We confirmed the Hosting Certification requirement, but not the underlying protective security text. If you host Australian Government information, check that policy directly.

  • New South Wales health privacy rules on transferring health information outside the state

    We could not open the New South Wales legislation website. Health Privacy Principle 14 of the Health Records and Information Privacy Act 2002 is widely reported to limit transfers outside New South Wales. We could not read the official text, so we have left it out of the rules. If you handle New South Wales health data, check this before you rely on our answer.

  • The exact date the 12-hour and 72-hour critical infrastructure incident reports first became enforceable

    The reporting duties were switched on for named asset classes by the Security of Critical Infrastructure (Application) Rules 2022, which we read. We did not confirm the grace period that followed. So this record shows the Act's start date and leaves the enforceable-from date blank rather than guessing.

  • The commencement date of the telecommunications data retention part (13 October 2015) and therefore the end of its 18-month implementation phase

    We confirmed from the law that the phase-in runs 18 months from the day that Part starts. We did not open the commencement rule itself. The dates shown match the law, but the start date is not independently evidenced here.

  • Minimum retention periods for tax and company records

    We did not check this. Commercial guidance commonly quotes five to seven years. We did not check that against the Income Tax Assessment Act or the Corporations Act. Confirm the period with your accountant before you delete records.

  • Whether any location rule exists for mapping and geospatial data, defence industry data, education data or online gambling data

    We found no rule on a government source, checked 18 August 2026. We could not confirm this against every source, so treat it as 'none found' rather than 'none exists'. Defence industry duties in particular usually sit in contracts and are not published. Check your contract.

  • eSafety Commissioner enforcement activity on the under-16 social media rule during 2026

    We could not reach the regulator's website, so we cannot show what it has enforced. The duty itself and its start date are confirmed from the legislation. Check the regulator's site for its current enforcement position.

  • The exact status of the second tranche of Privacy Act reform

    The Attorney-General's Department privacy page appears not to have been updated since the 2023 review report and does not mention the 2024 amendment Act. We found no bill for a further tranche, but cannot confirm from a current government statement that none is before Parliament.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.