Field notes
Data Sovereignty · 28 September 2026 · 6 min read

Does Australian Law Require Financial Data to Stay Onshore?

No general rule keeps financial services data in Australia. The Privacy Act, CPS 230 and the licensee obligations ask for something harder: control you can prove.

Krish Singh
Krish Singh
Chief Executive Officer, BackPro AI

The first question a compliance team asks about an AI tool is where the data goes. The second is usually a statement dressed as a question: "It has to stay in Australia, doesn't it?"

For an advice licensee, a fund manager or a super fund, the answer is no. There is no general Australian law that requires financial services data, or personal information generally, to be stored or processed onshore. That is a negative finding, based on the regimes that govern these firms, and a contract, a licence condition or a client mandate can still impose a location rule on a particular firm. But as a matter of law, the regimes permit offshoring and attach conditions to it.

Those conditions are the part worth reading, because they are harder to meet than a hosting region.

What the Privacy Act actually regulates

The Privacy Act regulates cross-border disclosure, and it does so with a duty and an accountability rule rather than a ban.

Law. Before personal information is disclosed to an overseas recipient, Australian Privacy Principle 8.1 requires the entity to "take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles". If the recipient does breach them, section 16C treats its act as the Australian entity's own. Disclosure is allowed. The accountability travels with it.

Guidance. The Office of the Australian Information Commissioner (OAIC) defines disclosure by reference to control. In its APP Guidelines (para 8.8), an entity discloses information when it "releases the subsequent handling of the information from its effective control". Giving personal information to an overseas contractor is, "in most circumstances", a disclosure (para 8.12). The OAIC also describes one object of the Act as facilitating "the free flow of information across national borders" (para 8.1).

Paragraph 8.14 is where most vendor claims about cloud storage come from, so it deserves a careful reading. The OAIC says that "in limited circumstances providing personal information to an overseas contractor to perform services on behalf of the APP entity may be a use, rather than a disclosure", and that "in these circumstances, the entity would not need to comply with APP 8". The circumstances turn on control: a binding contract limiting the provider to storing the information and giving the entity access to it, subcontractors bound the same way, and the entity keeping the power to access, change, retrieve or permanently delete the information.

That is guidance, not a safe harbour. It says "may", it is fact specific, and it is written about storage. An AI system also processes information, and how far the reasoning reaches that has not been tested. Anyone who tells you "in-tenancy means APP 8 never applies" has read more into paragraph 8.14 than it contains.

What APRA asks of regulated entities

Law. For APRA-regulated entities, CPS 230 (the revised version commencing 1 July 2026) requires notice to APRA "prior to entering into any material offshoring arrangement", including where "data or personnel relevant to the service being provided will be located offshore" (para 60(b)). It is a notification requirement. It is not a prohibition. The detail of what counts as offshoring, and why the location of the service matters more than the provider's nationality, is set out in our note on notifying APRA before, not after.

Law. CPS 230 also names location as a risk to assess before entering a material arrangement, "including risks associated with geographic location or concentration of the service provider(s)" (para 52(b)), and requires agreements to address "ownership and control of data" (para 53(b)). APRA may require an entity to change an arrangement where it has "heightened prudential concerns" (para 56). A regulator that can require a change can, in effect, impose a location condition on a particular firm. That power is case by case, not a general rule.

What the licensee obligations ask

Guidance. ASIC's Regulatory Guide 104 treats outsourcing as ordinary. It lists "information technology (IT) systems for storing records in relation to the provision of financial services" among functions licensees commonly outsource (RG 104.33). It is equally direct about who stays responsible: "If you outsource functions that relate to your AFS licence, you remain responsible for complying with your obligations as a licensee: see s769B" (RG 104.34).

Law. Under section 912A of the Corporations Act, a licensee must have "adequate resources (including financial, technological and human resources)" and "adequate risk management systems". Contravening either is a civil penalty provision (s 912A(5A)). Neither says where a server must sit. Both assume you can show a regulator how your arrangements work.

Where hard location rules do exist

Australian law does contain hard location rules, which is what makes their absence here meaningful. The My Health Records Act 2012 prohibits the operators of the My Health Record system from holding its records outside Australia (s 77). No equivalent provision applies to advice licensees, fund managers or super funds.

So why does location still come up?

Because the obligations above are easier to meet when you control the environment. If an AI system runs inside a cloud account your firm holds, the logs, the access controls and the keys are yours, and a regulator's question about who can reach the data has a short answer. If it runs on a vendor's shared platform in another country, the same question needs a contract, a due diligence file and, for an APRA-regulated entity, possibly a notice before signing.

That is an argument about evidence, not about legality. BackPro deploys into the customer's own cloud account on AWS, Azure or Google Cloud, and residency follows the account and region the customer brings. There is no setting on our side that fixes data in Australia, and being in your own account does not make you compliant on its own. APP 11, CPS 234, CPS 230 and section 912A apply wherever the data sits.

The question to ask instead

Replace "is it onshore?" with three questions that map to the rules. Where is the service physically performed, including support and the AI processing itself? Who can access, change and delete the information, and can you revoke that access yourself? Can you show a regulator both, in writing, on the day they ask? The full analysis, with every obligation marked as law, guidance or a regulator's finding and cited to its source, is in our whitepaper, Where the data sits.

None of the three is answered by a hosting region. A system in Sydney can still be supported from overseas, send text to a model hosted in another country, or ship logs to a monitoring service elsewhere, and each of those is where the tests above actually apply.

Written by
Krish Singh
Krish Singh
Chief Executive Officer, BackPro AI
data residencyoffshoringAPP 8CPS 230Privacy Actlicensee obligations

Take this with you · Whitepaper · PDF, 11 pages

Where the data sits: in-tenancy AI under APRA and ASIC expectations

What the Privacy Act, CPS 230, CPS 234 and the licensee obligations actually require of an AI deployment, what they do not, and the questions to put to any vendor. Every obligation cited to its source.

Sent to your inbox. No call, and nothing else unless you ask.