SECTION 01The short answer
Most AI tools an Australian business uses process data in the United States. That is legal. APP 8 of the Privacy Act does not ban offshore processing, and there is no data localisation requirement for ordinary commercial data in Australia.
What APP 8 does is make you responsible for what happens over there. If your overseas provider mishandles personal information you sent them, you are generally treated as having done it yourself, unless you took reasonable steps to ensure they would handle it in line with the Australian Privacy Principles.
"Where is the data stored" is the question everyone asks. It is the less useful half. Ask instead: where is it processed, who can read it, how long is it kept, and is it used for training. A vendor can store your data in Sydney and still route every prompt through a US inference cluster.
SECTION 02What APP 8 actually requires
Before you disclose personal information to an overseas recipient, you must take reasonable steps to ensure they do not breach the APPs. You then remain accountable for their acts under section 16C, which is the part people miss.
There are exceptions. The two that apply in practice are:
- The recipient is bound by a comparable scheme or contract. You reasonably believe they are subject to a law or binding scheme that protects the information in a substantially similar way, and that there are mechanisms the person can access to enforce it
- Informed consent. You expressly tell the person that APP 8.1 will not apply, and they consent anyway. The disclosure has to be clear, not buried, and consent has to be a real choice
For a small business, the workable route is almost always the first one, satisfied through the vendor's contract terms, plus disclosure in your privacy policy of the countries involved.
Reasonable steps scale with the sensitivity of the information. For a mailing list, reading the vendor's data processing terms and recording that you did is probably enough. For health records or financial data, expect to need contractual commitments you can point to, an independent security certification, and a documented assessment of why you chose that vendor. Write it down at the time. Reconstructing it after an incident convinces nobody.
SECTION 03Where the major AI tools actually process data
This is the state of play as at August 2026. Vendors change regions and plan terms often, so verify against current documentation before you rely on any row of this table. That verification step is itself part of your reasonable steps.
| Tool | Default processing | Australian option | Trains on your data? |
|---|---|---|---|
| Claude (Anthropic API) | United States | Via AWS Bedrock or Google Vertex in Sydney for supported models | No, on commercial API terms by default |
| Claude (consumer plans) | United States | No | Check your account setting, and do not use it for client data |
| OpenAI API | United States, with regional options on some plans | Limited, verify per plan | No, on API terms by default |
| ChatGPT free and Plus | United States | No | Yes unless you opt out. Treat as unsuitable for customer data |
| ChatGPT Team and Enterprise | United States, with data residency options on Enterprise | Verify per contract | No, by default |
| Azure OpenAI | Region you select | Yes, Australia East | No |
| Microsoft 365 Copilot | Inside your Microsoft 365 tenant boundary | Yes, Australian tenants supported | No, tenant data is not used to train foundation models |
| Google Gemini in Workspace | Google Cloud regions, configurable on some plans | Partial, verify per plan | No for Workspace data |
| AI meeting notetakers | Commonly United States | Rarely | Varies wildly. Read the plan terms, not the marketing |
| Self-hosted open models | Wherever you run them | Yes, entirely under your control | No |
Three tiers exist across almost every vendor. The consumer tier trains on your input and gives you no controls. The business tier does not train and gives you retention settings. The cloud platform tier, meaning Bedrock, Vertex or Azure, gives you a region you choose and a contract your lawyer can read. Price rises across those tiers, and so does what you can actually promise a client.
SECTION 04The CLOUD Act question
Clients in legal, health and government work ask this one, and it deserves a straight answer.
The United States CLOUD Act lets US authorities compel a US-headquartered provider to produce data it controls, wherever in the world that data is stored. Choosing a Sydney region from a US company reduces latency and satisfies many contractual requirements. It does not, by itself, put the data beyond a US legal process directed at the parent company.
The Australia and United States CLOUD Act Agreement entered into force on 31 January 2026. It creates a bilateral framework for law enforcement data requests with conditions and oversight on both sides. It is a formalisation of a route that already existed, not a new exposure, and it applies to law enforcement requests rather than commercial fishing.
When this genuinely matters
- Legal practices holding privileged material
- Health providers holding patient records
- Government contracts with sovereignty clauses
- Defence and critical infrastructure suppliers
- Anything where a client contract specifies Australian-only processing
When it does not
- Marketing copy and content drafting
- Website and code work with no personal data in it
- Internal document summarisation of non-sensitive material
- General customer service where no sensitive information is involved
- Anything you would be comfortable emailing to a supplier today
Chasing sovereignty for workloads that do not need it costs money and slows delivery. Ignoring it where a contract requires it loses the contract. Decide per workload, not per company.
SECTION 05How to check any tool in ten minutes
SECTION 06Five ways to reduce exposure without giving up AI
SECTION 07What to put in your privacy policy
APP 8 disclosure is not satisfied by "we may transfer data overseas". Your policy needs enough detail that a reader knows what is happening. At minimum:
- The categories of overseas recipient, such as AI providers, hosting, payments and analytics
- The countries where those recipients are likely to be located
- The basis you rely on, whether contractual protections or consent
- Your position on model training, stated plainly
- How someone can ask for more detail or object
A table works better than paragraphs, because a reader can find their answer and a procurement officer can copy it. Our own privacy policy uses one, listing each provider category, what it receives and where it processes, if you want a working example to borrow the structure from.
SECTION 08The data residency checklist
SECTION 09Common questions
Is it illegal to store Australian customer data overseas?
No. There is no general data localisation law in Australia for commercial data. APP 8 permits overseas disclosure provided you take reasonable steps to ensure APP-equivalent handling, or you obtain informed consent. Specific sectors have stricter rules, notably some health records and certain government data, so check your own sector before assuming.
Does choosing a Sydney region make us sovereign?
It makes the data resident in Australia, which satisfies many contract clauses and reduces latency. It does not make a US-headquartered provider immune from US legal process directed at the parent company. If a contract requires genuine sovereignty, you need an Australian-owned provider or your own infrastructure.
How do we know whether a tool trains on our data?
Read the data processing addendum for the specific plan you are on, and look for language about model training or service improvement. If the terms are ambiguous, email the vendor and ask for a written answer. Keep the reply. Ambiguity that survives a direct question is itself a finding.
What about AI features inside tools we already use?
They count. An AI summarise button inside your CRM or helpdesk is an AI tool, often powered by a third party the vendor has added as a sub-processor. Check whether the feature is on by default, because many are, and whether it introduced a new country to your data flow.
Do we need to tell customers which countries their data goes to?
Yes, where you disclose personal information overseas. APP 8 and APP 1 together require you to describe in your privacy policy the countries in which overseas recipients are likely to be located, where it is practicable to specify them.
REFERENCESSources
[1] Privacy Act 1988 (Cth), Australian Privacy Principle 8 and section 16C.
[2] OAIC, Australian Privacy Principles guidelines, Chapter 8, cross-border disclosure of personal information.
[3] OAIC, Guidance on privacy and the use of commercially available AI products, 21 October 2024.
[4] Clarifying Lawful Overseas Use of Data Act (US), 18 USC 2713.
[5] Agreement between the Government of Australia and the Government of the United States of America on Access to Electronic Data for the Purpose of Countering Serious Crime, in force 31 January 2026.
[6] Vendor documentation for Anthropic, OpenAI, Microsoft and Google, reviewed August 2026. Verify current terms before relying on them.
Want the register built for you?
We map every AI tool running in your business, the plan each is on, where the data goes and whether it trains. You get the spreadsheet, the gaps and a fix list ordered by risk. Most businesses find at least one tool nobody approved.