Australia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Australia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Australia has no general rule that data must stay in the country. You may send personal information anywhere, and no destination is banned. The catch is that you stay legally responsible for what your overseas supplier does with it. Small businesses under 3 million Australian dollars turnover are exempt from the main privacy law. Some industries are far stricter, and one of them carries a prison sentence.
Data governance in Australia
The eight things that decide how you handle data about people in Australia. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, it reaches you even with no office in Australia. The national privacy law applies to any organisation that carries on business in Australia. It does not matter whether the data is collected or stored here. But Australia has something most countries do not: a real size cut-off you can fall below. A business with annual turnover of 3 million Australian dollars (about 2 million US dollars) or less is usually exempt. That exemption has big holes. It does not apply if you provide a health service. It does not apply if you buy or sell personal information. And it does not apply if you supply services under a federal government contract. You need no local representative and no registration.
Section 5B(3) of the Privacy Act 1988 gives an organisation an 'Australian link' if it simply carries on business in Australia. Earlier wording also required the information to be collected or held in Australia. The current compilation (No. 105, 4 June 2026) has only the two limbs, so that extra hurdle is gone. Section 6D sets the small business exemption at 3,000,000 Australian dollars annual turnover. Section 6D(4) then takes the exemption away in four cases. They are health service providers holding health information, anyone trading in personal information, service providers under a Commonwealth contract, and credit reporting bodies. Separate laws override the size cut-off in specific settings. Telecommunications providers are treated as organisations for retained data under s 187LA of the Telecommunications (Interception and Access) Act 1979, whatever their size. The duty to report ransomware payments in the Cyber Security Act 2024 uses its own 3 million Australian dollar test.
Sources
- Official sourceFederal Register of LegislationPrivacy Act 1988, sections 5B and 6D (compilation of 4 June 2026)
legislation.gov.au
“An organisation or small business operator also has an Australian link if all of the following apply: (a) the organisation or operator is not described in subsection (2); (b) the organisation or operator carries on business in Australia or an external Territory.”
Link checked 18 August 2026
- Official sourceOffice of the Australian Information CommissionerThe Privacy Act — who it covers
oaic.gov.au
Link checked 18 August 2026
Where the data is allowed to live
In general, yes. Australia has no national law saying personal data must be kept in the country. No country is banned. You can pick any cloud region you like. What you cannot do is hand off the risk. If your overseas supplier does something with the data that would break Australian rules, the law treats that as your own breach. The strict rules are industry by industry, and the health one is absolute.
- What you have to do here:
- Put a transfer safeguard in place
Industry ratings as at 18 August 2026. HEALTH, meaning the national My Health Record system: closed. Section 77 of the My Health Records Act 2012 bans holding, taking, using or handling those records outside Australia. A criminal offence is attached. It binds the System Operator, and registered repository, portal and contracted service providers. It does not bind every clinic. BANKING, INSURANCE, SUPERANNUATION: conditional. Prudential Standard CPS 230 makes you tell the banking regulator before any material overseas arrangement. That includes any arrangement where data will sit overseas. OPEN BANKING, meaning the Consumer Data Right: conditional. Privacy Safeguard 8, plus rules 7.8A and 7.8B, make the accredited firm answerable for its overseas outsourced providers. Its public policy must name the countries those providers sit in. CRITICAL INFRASTRUCTURE: conditional, and tightening. From June 2026 nine asset classes must treat overseas or remote access to business critical data as a material risk. They must cut it down or remove it. AUSTRALIAN GOVERNMENT: conditional. Sensitive government data, and anything at PROTECTED, must be hosted with certified providers. QUEENSLAND STATE GOVERNMENT: conditional, and stricter than the national rule. TELECOMS: open on where data sits. But retained data must be encrypted and kept two years. SOCIAL MEDIA, EDUCATION, GAMING, MAPPING AND GEOSPATIAL, DEFENCE INDUSTRY. We found no rule on a government source about where data must sit. Checked 18 August 2026, medium confidence.
Sources
- Official sourceFederal Register of LegislationPrivacy Act 1988, Australian Privacy Principle 8.1 and section 16C
legislation.gov.au
“Before an APP entity discloses personal information about an individual to a person (the overseas recipient) ... the entity must take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles (other than Australian Privacy Principle 1) in relation to the information.”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationMy Health Records Act 2012, section 77 — requirement not to hold or take records outside Australia
legislation.gov.au
“The System Operator, a registered repository operator, a registered portal operator or a registered contracted service provider ... must not: (a) hold the records, or take the records, outside Australia; or (b) process or handle the information relating to the records outside Australia”
Link checked 18 August 2026
- Official sourceAustralian Prudential Regulation AuthorityPrudential Standard CPS 230 Operational Risk Management — notification of material offshoring arrangements
apra.gov.au
“prior to entering into any material offshoring arrangement, or when there is a significant change proposed to the arrangement, including in circumstances where data or personnel relevant to the service being provided will be located offshore.”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationSecurity of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026, section 6A
legislation.gov.au
“the following specified risks are additional material risks: ... (c) offshore or remote access to critical components; and (d) offshore or remote access to business critical data.”
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
Before data leaves, you must take reasonable steps to make sure the overseas recipient handles it the Australian way. That usually means a contract with the right promises in it. There is no government form to file, no approval to wait for, and no list of approved countries to check. A power to approve countries was switched on in December 2024. The government has not named a single one. The other routes are narrow. You can rely on the recipient already being covered by a substantially similar law. Or you can rely on the person's informed consent, after you warn them you will no longer be responsible.
- What you have to do here:
- Written vendor contract
- Ways to send data out:
- Standard contract clauses · Official 'this country is safe' decision · Explicit consent
Australia neither bans destinations nor approves them. Any destination is allowed. The control sits on the sender. Australian Privacy Principle 8.1 makes you take reasonable steps. Section 16C then treats the overseas recipient's breach as your breach. Australian Privacy Principle 8.3 was added by the Privacy and Other Legislation Amendment Act 2024 and started on 11 December 2024. It lets regulations name a country or a binding scheme, so that 8.1 no longer applies. Section 100(1A) first requires the Minister to be satisfied of substantially similar protection and accessible enforcement. The Privacy Regulations 2025 were made on 13 November 2025 and started on 1 April 2026. They replaced the old regulation and name no country or scheme, so the list is empty. You can see how tight the accountability rule is in the Privacy Commissioner's Public Interest Determinations of 11 February 2025. They had to be issued so that a major bank could keep handling international money transfers without breaking Principle 8.1.
Sources
- Official sourceFederal Register of LegislationPrivacy and Other Legislation Amendment Act 2024 (No. 128, 2024), Schedule 1 Part 6 — overseas data flows
legislation.gov.au
“8.3 This subclause applies in relation to the disclosure of personal information ... if: (a) the recipient ... is: (i) subject to the laws of a country that is prescribed by the regulations; or (ii) a participant in a binding scheme that is prescribed by the regulations”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationPrivacy Regulations 2025 — full contents, containing no prescribed country or binding scheme
legislation.gov.au
Link checked 18 August 2026
- Official sourceOffice of the Australian Information CommissionerAustralian Privacy Principles guidelines, Chapter 8 — cross-border disclosure
oaic.gov.au
Link checked 18 August 2026
- Official sourceFederal Register of LegislationPrivacy (International Money Transfers) Public Interest Determination 2025 (No. 1), made by the Privacy Commissioner on 11 February 2025
legislation.gov.au
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Office of the Australian Information Commissioner. It is staffed, it has a sitting Privacy Commissioner, and it is issuing decisions. In October 2025 the Federal Court ordered a pathology company to pay 5.8 million Australian dollars (about 3.8 million US dollars). That was the first court penalty in the law's history. The regulator sued Optus in August 2025 and settled with Meta for 50 million Australian dollars in December 2024. In June 2026 alone it published formal findings against Optus, American Express and two health providers. Banking, cyber security, online safety and open banking each have their own separate regulator, and all of them are working.
What we can see it doing in 2026. A determination against Optus over unlisted White Pages entries on 11 June 2026. A compensation order against American Express Australia on 15 June 2026. Findings against Medmate Australia and Monash IVF over third-party tracking pixels on 24 June 2026. A report of preliminary inquiries into the 2025 Qantas incident on 16 July 2026. Updated facial recognition guidance on 29 July 2026. Record annual data breach statistics published on 6 July 2026. We rate it active rather than aggressive. The very large penalties are still a handful of big cases rather than routine. And the first court penalty only arrived in late 2025.
Sources
- Official sourceOffice of the Australian Information CommissionerAustralian Clinical Labs ordered to pay A$5.8 million in civil penalties, 9 October 2025 — first penalty under the Privacy Act
oaic.gov.au
Link checked 18 August 2026
- Official sourceOffice of the Australian Information CommissionerPrivacy Commissioner finds against Optus in White Pages breach, 11 June 2026
oaic.gov.au
Link checked 18 August 2026
- Official sourceOffice of the Australian Information CommissionerInformation Commissioner commences Federal Court civil penalty proceedings against Optus, 8 August 2025
oaic.gov.au
Link checked 18 August 2026
- Official sourceOffice of the Australian Information CommissionerData breach notifications increase to all-time high in 2025, 6 July 2026
oaic.gov.au
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a minimum and a maximum, and they pull in opposite directions. The clearest minimum is telecoms. Phone and internet providers must keep call and connection records for two years, and must encrypt them. The general maximum has no number attached. You must destroy or de-identify personal information once you truly no longer need it. Two maximums are sharp. A social media platform must destroy age-check information as soon as it has finished using it. A digital identity provider must destroy a face or fingerprint scan immediately after the identity check is complete.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Secure the data
Telecommunications (Interception and Access) Act 1979 s 187C sets the two-year period. It runs from creation, or from closure of the account for subscriber details. Section 187BA makes you encrypt and protect the data you keep. Australian Privacy Principle 11.2 sets the general maximum. It applies where you no longer need the information, it is not in a Commonwealth record, and no law requires you to keep it. You must then take reasonable steps to destroy or de-identify it. Online Safety Act 2021 s 63F(3) makes you destroy information collected to check whether a user is under sixteen. Failing to destroy it counts as a breach of the Privacy Act. Digital ID Act 2024 s 51 makes you destroy biometric information immediately after the check is complete. There are narrow exceptions for testing and fraud investigation. Where a minimum and a maximum clash, the maximum gives way. Principle 11.2 only applies where no Australian law requires the information to be kept. We did not check the tax and company record minimums this time.
Sources
- Official sourceFederal Register of LegislationTelecommunications (Interception and Access) Act 1979, sections 187BA and 187C (compilation of 4 June 2026)
legislation.gov.au
“the period ... ending 2 years after the closure of the account to which the information or document relates”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationPrivacy Act 1988, Australian Privacy Principle 11.2 — destruction or de-identification
legislation.gov.au
Link checked 18 August 2026
- Official sourceFederal Register of LegislationDigital ID Act 2024, section 51 — destruction of biometric information
legislation.gov.au
“the provider must destroy the information immediately after the verification is complete”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count four deadlines, because they run at different speeds. Say you pay a ransom, and your Australian turnover is above 3 million Australian dollars (about 2 million US dollars). You then have 72 hours to report the payment to the government. If you run critical infrastructure, you have 12 hours for an attack that seriously hits availability, and 72 hours for a lesser one. If you are a bank, insurer or superannuation fund, you have 72 hours for a security incident. You have only 24 hours if a critical service goes down beyond tolerance. For an ordinary personal data breach you get up to 30 days to assess whether it is serious. You must then tell the regulator and the affected people as soon as you practically can. There is no fixed hour count for that last one, which is the part people get wrong.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Cyber Security Act 2024 s 27, in force 29 May 2025, sets the 72-hour ransomware payment report. The 3 million Australian dollar turnover cut-off is set by the Cyber Security (Ransomware Payment Reporting) Rules 2025 s 6. Security of Critical Infrastructure Act 2018 s 30BC sets 12 hours for a critical cyber security incident. Section 30BD sets 72 hours for other incidents with a relevant impact. Both carry 50 penalty units. Prudential Standard CPS 234 makes you notify within 72 hours of a material information security incident. It also gives you 10 business days for a material control weakness you cannot fix in time. CPS 230 adds 72 hours for a material operational risk incident. It adds 24 hours for a disruption to a critical operation beyond tolerance. Privacy Act 1988 s 26WH gives you 30 days to assess a suspected eligible data breach. Sections 26WK and 26WL then make you send a statement to the Commissioner and tell individuals 'as soon as practicable'.
Sources
- Official sourceFederal Register of LegislationCyber Security Act 2024, section 27 — ransomware payment reporting within 72 hours
legislation.gov.au
“The reporting business entity must give the designated Commonwealth body a report (a ransomware payment report) that complies with the requirements of this section within 72 hours of making the ransomware payment”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationSecurity of Critical Infrastructure Act 2018, sections 30BC and 30BD — 12-hour and 72-hour cyber incident reports
legislation.gov.au
“do so as soon as practicable, and in any event within 12 hours, after the entity becomes so aware.”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationPrivacy Act 1988, sections 26WH, 26WK and 26WL — 30-day assessment then notification as soon as practicable
legislation.gov.au
“take all reasonable steps to ensure that the assessment is completed within 30 days after the entity becomes aware”
Link checked 18 August 2026
- Official sourceAustralian Prudential Regulation AuthorityPrudential Standard CPS 234 Information Security — 72-hour incident notification
apra.gov.au
“An APRA-regulated entity must notify APRA as soon as possible and, in any case, no later than 72 hours, after becoming aware of an information security incident”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out. First, moving national electronic health record data overseas is a crime, not a fine. It carries up to five years in prison. Second, you never stop owning your supplier's mistakes. A major bank had to get a special ruling from the Privacy Commissioner just to keep handling international money transfers. Third, since December 2025 social media platforms must keep under-16s off the service. They must then destroy the age-check data they collected. Fourth, Queensland's rule for state government data is stricter than the national one. It hides in section 33 of the Act, not in the numbered principles. The principle numbered 8 says there is no equivalent. Fifth, the value of a penalty unit rose to 364 Australian dollars (about 240 US dollars) on 1 July 2026. So every fine figure you looked up before then is now too low.
- What you have to do here:
- Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability
(1) My Health Records Act 2012 s 77(2A): imprisonment for 5 years or 300 penalty units. There is also a civil penalty of 1,500 penalty units, about 546,000 Australian dollars. (2) Privacy Act s 16C treats the overseas recipient's act as your breach. The Privacy (International Money Transfers) Public Interest Determinations 2025 (Nos 1 and 2) exist for a reason. A bank could not practically meet Principle 8.1 for correspondent banking. (3) Online Safety Act 2021 s 63D took effect on 10 December 2025 by ministerial instruction. Section 63F makes you destroy age assurance information, and treats failure as a privacy breach. The platform penalty is 30,000 penalty units, about 10.9 million Australian dollars. (4) Queensland Information Privacy Act 2009 s 33 allows disclosure outside Australia only on listed grounds. The 'substantially similar law' route requires two or more of four conditions to be met. That is harder than the Commonwealth test. (5) A 2026 rule set the penalty unit at 364 Australian dollars from 1 July 2026, up from 330. The Privacy Act compilation of 4 June 2026 still prints the old figure in the Crimes Act. So a quick read gives you the wrong number.
Sources
- Official sourceFederal Register of LegislationMy Health Records Act 2012, section 77(2A) — criminal offence for offshore handling
legislation.gov.au
“Penalty: Imprisonment for 5 years or 300 penalty units, or both.”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationOnline Safety Amendment (Social Media Minimum Age) Act 2024, section 63F — destruction of age assurance information
legislation.gov.au
“the entity must destroy the information after using or disclosing it for the purposes for which it was collected”
Link checked 18 August 2026
- Official sourceQueensland Parliamentary CounselInformation Privacy Act 2009 (Queensland), section 33 — disclosure of personal information outside Australia (current as at 1 July 2026)
legislation.qld.gov.au
“An agency may disclose an individual's personal information to an entity outside Australia only if— (a) the individual agrees to the disclosure; or (b) the disclosure is authorised or required under a law”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationCrimes (Amount of a Penalty Unit) Instrument 2026 — penalty unit set at A$364 from 1 July 2026
legislation.gov.au
“For the purposes of subsection 4AA(1A) of the Act, the amount of a penalty unit is $364.”
Link checked 18 August 2026
What's changing next
One date dominates: 10 December 2026. From that day, privacy policies must explain computer-made decisions that significantly affect people. The new Children's Online Privacy Code must also be finalised and registered by then. The draft of that code was out for public comment from 31 March to 5 June 2026. Further out, the tougher critical infrastructure duties made in June 2026 start to apply from mid-2027 and mid-2028, as their grace periods run out. Watch three powers the government already holds and can use with no consultation.
Powers already held. (1) Regulations may name countries or binding schemes under Australian Privacy Principle 8.3. That would create an approved-destination list overnight. None has been made. (2) Section 77 of the Digital ID Act 2024 gives the Digital ID Rules a power. They can ban outright the holding, storing, handling or transferring of certain information outside Australia. That covers information generated by accredited bodies in the Australian Government Digital ID System. The Digital ID Rules 2024 contain no such ban today. So this is a fully drafted power to force data to stay in the country, sitting unused. (3) Under Part IIIC Division 5 of the Privacy Act, added in December 2024, the Minister may make an eligible data breach declaration. It authorises collecting, using and disclosing personal information after a major breach. Grace periods on the Enhanced Critical Infrastructure Risk Management Program Rules 2026 run 12 months for the extra material risks. They run 24 months for the cyber, personnel, supply chain and physical security requirements. Both are measured from the rules starting on 10 June 2026. We found no Australian data rule currently suspended or set aside by a court, checked 18 August 2026.
Sources
- Official sourceFederal Register of LegislationPrivacy and Other Legislation Amendment Act 2024, commencement table item 7 and section 26GC(10)
legislation.gov.au
“7. Schedule 1, Part 15 — The day after the end of the period of 24 months beginning on the day this Act receives the Royal Assent. 10 December 2026”
Link checked 18 August 2026
- Official sourceOffice of the Australian Information CommissionerChildren's Online Privacy Code — status page, updated 5 August 2026
oaic.gov.au
“December 2026: The Code must be finalised and registered by 10 December 2026.”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationDigital ID Act 2024, section 77 — power to prohibit holding information outside Australia
legislation.gov.au
“the Digital ID Rules may: (a) prohibit (either absolutely or unless particular circumstances are met or conditions are complied with) the holding, storing, handling or transferring of such information outside Australia”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationEnhanced Critical Infrastructure Risk Management Program Rules 2026, section 4A(6) — 12 and 24 month grace periods
legislation.gov.au
Link checked 18 August 2026
What to do: Diarise 10 December 2026 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries9 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Health data rules
Official name: My Health Records Act 2012, section 77 · Act No. 63 of 2012; compilation of 1 July 2026 · Act of parliament
This is Australia's strictest data rule. Data in the national My Health Record system may not be held, taken, used or handled outside Australia at all. Doing so is a crime carrying up to five years in prison. It binds the system operator and its registered repository, portal and contracted service providers. It does not bind every clinic in the country.
Enforced by Australian Digital Health Agency
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryThis is not only about storage. Using and handling the information outside Australia is banned too. So is causing or allowing someone else to do it.
- Extra vendor secrecy termsThe ban follows the chain. Registered contracted service providers are caught directly. So a standard cloud data agreement is not enough.
What it costs if you get it wrong
- Criminal liability: Imprisonment for 5 years or 300 penalty units (about A$109,200), or both — about $72 thousandHolding, taking, processing or handling My Health Record data outside Australia
- Fixed maximum fine: 1,500 penalty units (about A$546,000) — about $360 thousandCivil penalty for the same conduct
Sources
- Official sourceFederal Register of LegislationMy Health Records Act 2012, section 77 (compilation of 1 July 2026)
legislation.gov.au
“must not: (a) hold the records, or take the records, outside Australia; or (b) process or handle the information relating to the records outside Australia; or (c) cause or permit another person: (i) to hold the records, or take the records, outside Australia”
Link checked 18 August 2026
Banking rules
Official name: Prudential Standard CPS 230 Operational Risk Management · Banking, Insurance, Life Insurance, Health Insurance and Superannuation (prudential standard) determination No. 1 of 2026 · Directly binding regulation
Banks, insurers and superannuation funds must tell the prudential regulator before entering any material overseas arrangement. That includes arrangements where the data or the people will sit outside Australia. Going overseas is not banned. But it is a notified, supervised decision rather than a private one.
Enforced by Australian Prudential Regulation Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Standard contract clauses
What you have to do
- Register or notifyKeep a register of material service providers and send it to the regulator every year.
- Written vendor contractFormal agreements must cover sub-contracting and make the provider answerable for its sub-contractors.
- Put a transfer safeguard in placeTell the regulator before entering any material overseas arrangement, or when significantly changing one. That includes where data will sit overseas.
- Report cyber incidents — within 72 hoursA material operational risk incident.
- Report cyber incidents — within 24 hoursA disruption to a critical operation beyond tolerance.
What it costs if you get it wrong
- Loss of your licencePrudential standards are enforced through licence conditions and directions rather than a headline fine.
Sources
- Official sourceAustralian Prudential Regulation AuthorityPrudential Standard CPS 230 Operational Risk Management, determination No. 1 of 2026, commencing 1 July 2026
apra.gov.au
“Material offshoring arrangement means a material arrangement where the service provided is undertaken outside Australia. Offshoring includes arrangements where the service provider is incorporated in Australia, but the physical location of the service being provided is undertaken outside Australia.”
Link checked 18 August 2026
Banking rules (Finance)
Official name: Prudential Standard CPS 234 Information Security · CPS 234 · Directly binding regulation
Banks, insurers and superannuation funds must notify the prudential regulator within 72 hours of a material information security incident. They have 10 business days for a material control weakness they cannot fix in time. This deadline runs separately from the privacy breach deadline, and usually starts earlier.
Enforced by Australian Prudential Regulation Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the data
- Report cyber incidents — within 72 hoursA material information security incident.
- Independent auditInternal audit must review how well information security controls are designed and how well they work. That includes controls run by third parties.
Sources
- Official sourceAustralian Prudential Regulation AuthorityPrudential Standard CPS 234 Information Security, commencing 1 July 2019
apra.gov.au
“An APRA-regulated entity must notify APRA as soon as possible and, in any case, no later than 72 hours, after becoming aware of an information security incident”
Link checked 18 August 2026
Banking rules (Account aggregators)
Official name: Competition and Consumer (Consumer Data Right) Rules 2020 · F2020L00094, made 4 February 2020; version of 4 March 2025 · Directly binding regulation
Open banking data can go overseas. But the accredited Australian firm answers for its overseas suppliers. Its published data policy must list the countries those suppliers sit in. Failing to control an overseas supplier is itself a penalty offence for the Australian firm.
Enforced by Australian Competition and Consumer Commission
How this country controls where data goes: No restriction · Accepted routes: Standard contract clauses, Certification scheme
What you have to do
- Put a transfer safeguard in placePrivacy Safeguard 8 in the Competition and Consumer Act 2010 governs sending open banking data overseas.
- Tell people what you doThe public data policy must name the countries where overseas outsourced providers are likely to be based, where practicable.
- Written vendor contractAn accredited firm breaks the rules if its overseas outsourced provider fails to meet Privacy Safeguard 8. A civil penalty applies.
- Delete data after a periodConsumer data you no longer need must be deleted or de-identified.
Sources
- Official sourceFederal Register of LegislationCompetition and Consumer (Consumer Data Right) Rules 2020, rules 7.2, 7.8A and 7.8B
legislation.gov.au
“An accredited person breaches this subrule if a direct or indirect OSP of: (a) the accredited person; or (b) a CDR representative of the accredited person; fails to comply with section 56EK of the Act”
Link checked 18 August 2026
- Official sourceOffice of the Australian Information CommissionerConsumer Data Right Privacy Safeguard Guidelines, Chapter 8 — overseas disclosure
oaic.gov.au
Link checked 18 August 2026
Breach reporting rules
Official name: Security of Critical Infrastructure Act 2018 · Act No. 29 of 2018, as amended by Act No. 100 of 2024; compilation of 4 June 2026 · Act of parliament
Critical infrastructure operators face the shortest incident deadline in Australia. That is 12 hours for a serious cyber attack and 72 hours for a lesser one. Since 2025 a data storage system holding business critical data counts as part of the asset itself. So a database can pull a company into these rules. Companies that store or handle data for government are directly covered as critical data storage or handling assets.
Enforced by Department of Home Affairs (Cyber and Infrastructure Security Centre)
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 12 hoursA cyber incident with a significant impact on whether the asset is available.
- Report cyber incidents — within 72 hoursA cyber incident with a relevant impact on the asset.
- Register or notifyYou must give ownership and operational information to the register of critical infrastructure assets.
What it costs if you get it wrong
- Fixed maximum fine: 50 penalty units (about A$18,200) per contravention — about $12 thousandFailure to report a cyber security incident in time
Sources
- Official sourceFederal Register of LegislationSecurity of Critical Infrastructure Act 2018, sections 9(7), 12F, 30BC and 30BD
legislation.gov.au
“If, under this section, an asset is a critical infrastructure asset, then a data storage system in respect of which all of the following requirements are satisfied is taken to be part of the critical infrastructure asset”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationSecurity of Critical Infrastructure (Telecommunications Security and Risk Management Program) Rules 2025
legislation.gov.au
Link checked 18 August 2026
Data rules
Official name: Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 · LIN 26/075, F2026L00701, made 4 June 2026 · Government rules
This is the closest Australia comes to slowly forcing data to stay in the country. From June 2026, nine critical infrastructure classes must treat overseas or remote access to business critical data as a material risk. They must cut it down as far as they reasonably can. It is not a ban, but it pushes operators towards keeping data and access in Australia. Grace periods mean it starts to apply in June 2027 and June 2028.
It is already law, so plan for it — but nobody can be penalised under it until 10 June 2027. A contract you sign may still hold you to it sooner.
Enforced by Department of Home Affairs (Cyber and Infrastructure Security Centre)
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Check your algorithms — applies at: Nine asset classes: broadcasting, domain name systems, electricity, energy market operators, freight infrastructure, freight services, gas, liquid fuel, water, from 10 June 2027Overseas or remote access to business critical data must be treated as a material risk. You must reduce or remove it as far as is reasonably practicable.
- Hold a security certificate — from 10 June 2028Meet the international information security standard AS ISO/IEC 27001:2023, or reach maturity level two of the government's Essential Eight model.
- Written vendor contract — from 10 June 2028Map your supply chain. Assess each major supplier for foreign ownership, control or influence. That includes the foreign laws the supplier is subject to.
Sources
- Official sourceFederal Register of LegislationEnhanced Critical Infrastructure Risk Management Program Rules 2026, sections 4A, 6A, 8A and 10A
legislation.gov.au
“For subsection 30AH(8) of the Act, the following specified risks are additional material risks: ... (c) offshore or remote access to critical components; and (d) offshore or remote access to business critical data.”
Link checked 18 August 2026
Internet and platform rules
Official name: Telecommunications (Interception and Access) Act 1979, Part 5-1A · Act No. 114 of 1979; compilation No. 133 of 4 June 2026 · Act of parliament
Phone and internet providers must keep call and connection records for two years, and must encrypt them. The law does not say where those records have to sit. But it does apply the national privacy law to them, even for providers too small to be covered otherwise.
Enforced by Australian Communications and Media Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 2 yearsTwo years from creation, or from closure of the account for subscriber details.
- Secure the dataData you keep must be encrypted and protected from unauthorised access.
- Keep logs — 2 years
Sources
- Official sourceFederal Register of LegislationTelecommunications (Interception and Access) Act 1979, sections 187A, 187BA, 187C and 187LA
legislation.gov.au
“A service provider must protect the confidentiality of information that ... the service provider must keep, or cause to be kept, under section 187A by: (a) encrypting the information; and (b) protecting the information from unauthorised interference or unauthorised access.”
Link checked 18 August 2026
Breach reporting rules (Social media and online platforms)
Official name: Online Safety Act 2021, Part 4A (inserted by the Online Safety Amendment (Social Media Minimum Age) Act 2024) · Act No. 127 of 2024; day of effect fixed by the Online Safety (Day of Effect of Social Media Minimum Age) Instrument 2025 · Act of parliament
Since 10 December 2025 social media platforms must take reasonable steps to stop Australians under sixteen having accounts. The privacy catch comes afterwards. Whatever you collect to check someone's age must be destroyed once you are done. Keeping it counts as a privacy breach.
Enforced by eSafety Commissioner
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Get a parent's consent for children — applies at: under 16, from 10 December 2025There is no parental consent route. Under-16s may not hold accounts on an age-restricted social media platform at all.
- Delete data after a period — from 10 December 2025Information collected to check age must be destroyed once it has been used for that purpose.
What it costs if you get it wrong
- Fixed maximum fine: 30,000 penalty units (about A$10.9 million) — about $7 millionPlatform failing to take reasonable steps to prevent under-16 accounts
Sources
- Official sourceFederal Register of LegislationOnline Safety Amendment (Social Media Minimum Age) Act 2024, sections 63C, 63D and 63F
legislation.gov.au
“age-restricted user means an Australian child who has not reached 16 years.”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationOnline Safety (Day of Effect of Social Media Minimum Age) Instrument 2025
legislation.gov.au
“specify 10 December 2025 as the day section 63D of that Act takes effect.”
Link checked 18 August 2026
Rules for sending data abroad
Official name: Digital ID Act 2024, section 77 · Act No. 25 of 2024 · Act of parliament
A power that has never been used. The law lets the government make rules that completely ban holding, storing, handling or transferring Australian Government digital identity data outside Australia. As at 18 August 2026 the rules contain no such ban. So digital identity data may go overseas today. This can change by ministerial rule, with no consultation.
Enforced by Australian Competition and Consumer Commission
How this country controls where data goes: No restriction (no country is on the approved list yet) · Accepted routes: Nothing required
What you have to do
- Delete data after a periodBiometric information must be destroyed immediately after the identity check is complete.
- Keep the data in the countryNot required today. The power to require it exists and has not been used.
What it costs if you get it wrong
- Fixed maximum fine: 1,500 penalty units (about A$546,000) — about $360 thousandBreaching a localisation requirement, if one is ever made in the rules
Sources
- Official sourceFederal Register of LegislationDigital ID Act 2024, sections 51 and 77
legislation.gov.au
“The Digital ID Rules may make provision in relation to the holding, storing, handling or transfer of information outside Australia if the information is or was generated, collected, held or stored by accredited entities within the Australian Government Digital ID System.”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationDigital ID Rules 2024 — full text, containing no offshore prohibition
legislation.gov.au
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Children's data rules
Official name: Privacy Act 1988 · Act No. 119 of 1988, as amended by Act No. 128 of 2024; compilation of 4 June 2026 · Act of parliament
Australia's general privacy law. It does not require data to stay in the country. But it makes you legally answerable for what your overseas supplier does. Businesses at or below 3 million Australian dollars turnover are largely exempt. Two important pieces start on 10 December 2026. One is transparency about computer-made decisions. The other is a binding code for children's online privacy.
Enforced by Office of the Australian Information Commissioner
How this country controls where data goes: No restriction (no country is on the approved list yet) · Accepted routes: Standard contract clauses, Official 'this country is safe' decision, Explicit consent
What you have to do
- Tell people what you do
- Get consentYou need consent for sensitive information. For other personal information it usually turns on your purpose and what the person would reasonably expect, not on consent.
- Secure the data
- Let people see their data
- Let people correct their data
- Put a transfer safeguard in placeReasonable steps under Australian Privacy Principle 8.1. Section 16C then treats the overseas recipient's breach as yours.
- Delete data after a periodDestroy or de-identify once you no longer need it. There is no fixed period.
- Report breaches to the regulatorAssess within 30 days. Send the statement to the Commissioner as soon as practicable.
- Tell affected people
- Publish a complaints contact
- Get a parent's consent for children — applies at: under 18 (a 'child' is defined as an individual who has not reached 18 years), from 10 December 2026The detail sits in the Children's Online Privacy Code, which must be registered by 10 December 2026.
- Limit automated decisions — from 10 December 2026Privacy policies must describe computer-made decisions that could significantly affect a person's rights or interests.
What it costs if you get it wrong
- Fixed maximum fine: A$50,000,000 — about $33 millionSerious interference with privacy by a company
- Percentage of global turnover: 30% of adjusted turnover during the breach turnover periodSerious interference where the benefit cannot be valued
- Fixed maximum fine: 2,000 penalty units (about A$728,000) — about $480 thousandAny interference with privacy that is not serious
- Fixed maximum fine: 200 penalty units (about A$72,800) — about $48 thousandInfringement notice offences such as missing or defective privacy policy
- Claims by individualsStatutory tort of serious invasion of privacy, in force since 10 June 2025
Sources
- Official sourceFederal Register of LegislationPrivacy Act 1988 — current compilation (4 June 2026)
legislation.gov.au
“The amount of the penalty for a contravention of subsection (1) by a body corporate is an amount not more than the greatest of the following: (a) $50,000,000; (b) ... 3 times the value of that benefit; (c) ... 30% of the adjusted turnover of the body corporate during the breach turnover period”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationPrivacy and Other Legislation Amendment Act 2024 (No. 128, 2024) — commencement table and Schedules 1 to 3
legislation.gov.au
Link checked 18 August 2026
- Official sourceOffice of the Australian Information CommissionerAustralian Privacy Principles guidelines, Chapter 8
oaic.gov.au
Link checked 18 August 2026
Cyber security rules
Official name: Cyber Security Act 2024, Part 3 · Act No. 98 of 2024, with the Cyber Security (Ransomware Payment Reporting) Rules 2025 · Act of parliament
Say your business turns over more than 3 million Australian dollars in Australia, and you pay a ransom. You then have 72 hours to tell the government. The information is legally protected. It can only be used for a short list of purposes, and it cannot be used against you in most proceedings.
Enforced by Australian Signals Directorate (Australian Cyber Security Centre)
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — applies at: Business carried on in Australia with annual turnover above A$3 million (about US$2 million) in the previous financial year, within 72 hoursReport the fact of the payment, the demand, the incident, and your messages with the attacker.
What it costs if you get it wrong
- Fixed maximum fine: 60 penalty units (about A$21,840) — about $14 thousandFailing to report a ransomware payment within 72 hours
Sources
- Official sourceFederal Register of LegislationCyber Security Act 2024, sections 26 to 32 (Part 3 commenced 29 May 2025)
legislation.gov.au
“within 72 hours of making the ransomware payment or becoming aware that the ransomware payment has been made”
Link checked 18 August 2026
- Official sourceFederal Register of LegislationCyber Security (Ransomware Payment Reporting) Rules 2025, section 6 — A$3 million turnover threshold
legislation.gov.au
“For the purposes of paragraph 26(3)(b) of the Act, the amount of turnover threshold for a business for the previous financial year is $3 million.”
Link checked 18 August 2026
Applies only in certain states1 rule
Made by a state or province. It only binds you for the people living there.
Telecoms rules
Official name: Information Privacy Act 2009 (Queensland), section 33 · Queensland Act No. 14 of 2009; reprint current as at 1 July 2026 · Act of parliament
Queensland state agencies face a tighter overseas rule than the national one, and it is easy to miss. The rule sits in section 33 of the Act, not in the numbered Queensland privacy principles. The principle numbered 8 says only that there is no Queensland equivalent. Relying on the recipient being covered by a similar law is not enough on its own.
Enforced by Office of the Information Commissioner Queensland
How this country controls where data goes: Approval each time · Accepted routes: Explicit consent, Standard contract clauses, Official 'this country is safe' decision
What you have to do
- Put a transfer safeguard in placeThe comparable-protection route is not enough on its own. Two or more of four listed conditions must apply before a Queensland agency may send personal information abroad.
Sources
- Official sourceQueensland Parliamentary CounselInformation Privacy Act 2009 (Queensland), section 33 and Schedule 3 clause 8 (current as at 1 July 2026)
legislation.qld.gov.au
“QPP 8—cross-border disclosure of personal information. Editor's note— The Privacy Act 1988 (Cwlth), schedule 1 includes a privacy principle about requirements for cross-border disclosure of personal information (see APP 8). There is no equivalent QPP for APP 8.”
Link checked 18 August 2026
Applies only if you signed a contract1 rule
Usually a government or enterprise contract that adds rules of its own.
Government data needs a sovereign cloud
Official name: Hosting Certification Framework · Whole-of-Government Hosting Strategy; administered by the Department of Home Affairs since 1 May 2023 · Government policy document
If you host Australian Government data, the buying rules apply before the privacy law does. Sensitive government data, and anything at the PROTECTED classification, must be hosted using certified services. Sovereignty and ownership controls come with that. This is buying policy rather than a law, so it reaches you through your contract.
Enforced by Department of Home Affairs (Cyber and Infrastructure Security Centre)
How this country controls where data goes: Only approved countries · Accepted routes: Certification scheme
What you have to do
- Hold a security certificateSensitive government data, whole-of-government systems and anything classified PROTECTED must sit with a certified hosting provider.
- Prove the data stays under local control
Sources
- Official sourceDepartment of Home AffairsHosting Certification Framework
hostingcertification.gov.au
“all sensitive government data, Whole-of-Government systems and systems rated at the classification level of PROTECTED must be hosted using certified services”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That no country or binding scheme has been prescribed under Australian Privacy Principle 8.3
We read the whole of the Privacy Regulations 2025 and found no such rule. We also checked the regulator's own guidance, which lists none. We cannot rule out a separate rule made between 1 and 18 August 2026. Treat this as our reading of the law, not a government statement.
The date Prudential Standard CPS 230 first applied to regulated entities
The version now on the regulator's site is determination No. 1 of 2026, dated 23 April 2026 and starting 1 July 2026. Earlier versions of the standard existed, and we did not open them. So this record shows only the current dates. If you need to trace a duty back before July 2026, check the earlier determination.
Whether the Protective Security Policy Framework contains its own offshore storage restriction for Australian Government information
We could not read the protective security policy pages beyond the home page. We confirmed the Hosting Certification requirement, but not the underlying protective security text. If you host Australian Government information, check that policy directly.
New South Wales health privacy rules on transferring health information outside the state
We could not open the New South Wales legislation website. Health Privacy Principle 14 of the Health Records and Information Privacy Act 2002 is widely reported to limit transfers outside New South Wales. We could not read the official text, so we have left it out of the rules. If you handle New South Wales health data, check this before you rely on our answer.
The exact date the 12-hour and 72-hour critical infrastructure incident reports first became enforceable
The reporting duties were switched on for named asset classes by the Security of Critical Infrastructure (Application) Rules 2022, which we read. We did not confirm the grace period that followed. So this record shows the Act's start date and leaves the enforceable-from date blank rather than guessing.
The commencement date of the telecommunications data retention part (13 October 2015) and therefore the end of its 18-month implementation phase
We confirmed from the law that the phase-in runs 18 months from the day that Part starts. We did not open the commencement rule itself. The dates shown match the law, but the start date is not independently evidenced here.
Minimum retention periods for tax and company records
We did not check this. Commercial guidance commonly quotes five to seven years. We did not check that against the Income Tax Assessment Act or the Corporations Act. Confirm the period with your accountant before you delete records.
Whether any location rule exists for mapping and geospatial data, defence industry data, education data or online gambling data
We found no rule on a government source, checked 18 August 2026. We could not confirm this against every source, so treat it as 'none found' rather than 'none exists'. Defence industry duties in particular usually sit in contracts and are not published. Check your contract.
eSafety Commissioner enforcement activity on the under-16 social media rule during 2026
We could not reach the regulator's website, so we cannot show what it has enforced. The duty itself and its start date are confirmed from the legislation. Check the regulator's site for its current enforcement position.
The exact status of the second tranche of Privacy Act reform
The Attorney-General's Department privacy page appears not to have been updated since the 2023 review report and does not mention the 2024 amendment Act. We found no bill for a further tranche, but cannot confirm from a current government statement that none is before Parliament.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.