AI Compliance · 11 min read

Where Does Your AI Tool Actually Send Your Data?

Sending Australian customer data offshore is legal. Staying accountable for what happens to it is the part businesses miss. Here is what APP 8 requires, where the major AI vendors really process data, and the ten minute check that keeps you out of trouble.

Published 19 Aug 2026
By Automatrix
Topic Data Residency · APP 8 · AI Vendors
Applies to Australian businesses
0 The Privacy Principle that governs offshore data
0 Plan tiers that decide your exposure
0 Minutes to assess any AI tool properly
0 Data localisation laws for ordinary commercial data

SECTION 01The short answer

Most AI tools an Australian business uses process data in the United States. That is legal. APP 8 of the Privacy Act does not ban offshore processing, and there is no data localisation requirement for ordinary commercial data in Australia.

What APP 8 does is make you responsible for what happens over there. If your overseas provider mishandles personal information you sent them, you are generally treated as having done it yourself, unless you took reasonable steps to ensure they would handle it in line with the Australian Privacy Principles.

The distinction that matters

"Where is the data stored" is the question everyone asks. It is the less useful half. Ask instead: where is it processed, who can read it, how long is it kept, and is it used for training. A vendor can store your data in Sydney and still route every prompt through a US inference cluster.

SECTION 02What APP 8 actually requires

Before you disclose personal information to an overseas recipient, you must take reasonable steps to ensure they do not breach the APPs. You then remain accountable for their acts under section 16C, which is the part people miss.

There are exceptions. The two that apply in practice are:

For a small business, the workable route is almost always the first one, satisfied through the vendor's contract terms, plus disclosure in your privacy policy of the countries involved.

"Reasonable steps" is not "we checked their website"

Reasonable steps scale with the sensitivity of the information. For a mailing list, reading the vendor's data processing terms and recording that you did is probably enough. For health records or financial data, expect to need contractual commitments you can point to, an independent security certification, and a documented assessment of why you chose that vendor. Write it down at the time. Reconstructing it after an incident convinces nobody.

SECTION 03Where the major AI tools actually process data

This is the state of play as at August 2026. Vendors change regions and plan terms often, so verify against current documentation before you rely on any row of this table. That verification step is itself part of your reasonable steps.

ToolDefault processingAustralian optionTrains on your data?
Claude (Anthropic API)United StatesVia AWS Bedrock or Google Vertex in Sydney for supported modelsNo, on commercial API terms by default
Claude (consumer plans)United StatesNoCheck your account setting, and do not use it for client data
OpenAI APIUnited States, with regional options on some plansLimited, verify per planNo, on API terms by default
ChatGPT free and PlusUnited StatesNoYes unless you opt out. Treat as unsuitable for customer data
ChatGPT Team and EnterpriseUnited States, with data residency options on EnterpriseVerify per contractNo, by default
Azure OpenAIRegion you selectYes, Australia EastNo
Microsoft 365 CopilotInside your Microsoft 365 tenant boundaryYes, Australian tenants supportedNo, tenant data is not used to train foundation models
Google Gemini in WorkspaceGoogle Cloud regions, configurable on some plansPartial, verify per planNo for Workspace data
AI meeting notetakersCommonly United StatesRarelyVaries wildly. Read the plan terms, not the marketing
Self-hosted open modelsWherever you run themYes, entirely under your controlNo
The pattern worth learning

Three tiers exist across almost every vendor. The consumer tier trains on your input and gives you no controls. The business tier does not train and gives you retention settings. The cloud platform tier, meaning Bedrock, Vertex or Azure, gives you a region you choose and a contract your lawyer can read. Price rises across those tiers, and so does what you can actually promise a client.

SECTION 04The CLOUD Act question

Clients in legal, health and government work ask this one, and it deserves a straight answer.

The United States CLOUD Act lets US authorities compel a US-headquartered provider to produce data it controls, wherever in the world that data is stored. Choosing a Sydney region from a US company reduces latency and satisfies many contractual requirements. It does not, by itself, put the data beyond a US legal process directed at the parent company.

The Australia and United States CLOUD Act Agreement entered into force on 31 January 2026. It creates a bilateral framework for law enforcement data requests with conditions and oversight on both sides. It is a formalisation of a route that already existed, not a new exposure, and it applies to law enforcement requests rather than commercial fishing.

When this genuinely matters

Design around it
  • Legal practices holding privileged material
  • Health providers holding patient records
  • Government contracts with sovereignty clauses
  • Defence and critical infrastructure suppliers
  • Anything where a client contract specifies Australian-only processing

When it does not

Do not over-engineer
  • Marketing copy and content drafting
  • Website and code work with no personal data in it
  • Internal document summarisation of non-sensitive material
  • General customer service where no sensitive information is involved
  • Anything you would be comfortable emailing to a supplier today

Chasing sovereignty for workloads that do not need it costs money and slows delivery. Ignoring it where a contract requires it loses the contract. Decide per workload, not per company.

SECTION 05How to check any tool in ten minutes

Find the sub-processor list, not the privacy page
Serious vendors publish a sub-processor list showing every third party that touches customer data and the country each operates in. Search the vendor name plus "sub-processors" or "trust center". If no such list exists, that tells you how mature their data governance is.
Read the data processing addendum, not the marketing
The DPA is the document that binds them. Look for the training position, retention period, breach notification timeframe, and whether they must tell you before adding a sub-processor. Marketing pages say "enterprise-grade security" and commit to nothing.
Confirm which plan tier you are actually on
This is where most audits find the problem. The company bought Enterprise, three people are still signed in on personal accounts they set up first. Check the billing portal and the identity provider, not what people tell you.
Check retention and turn it down
Default retention is set for the vendor's convenience. If the setting exists, shorten it. Prompts and transcripts you no longer need are pure liability sitting in someone else's system.
Write down what you found and when
One row per tool: name, plan, processing country, training position, retention, date checked. This spreadsheet is your APP 8 reasonable steps evidence, your procurement answer, and your breach response starting point. It takes an hour to build and it is the single highest value hour in this whole exercise.

SECTION 06Five ways to reduce exposure without giving up AI

Send less
The cheapest control there is. Strip names, addresses and account numbers before a prompt where the task does not need them. A summarisation job rarely needs to know who the customer is.
Choose the region
Where a vendor offers an Australian region, take it. Bedrock, Vertex and Azure all let you pin the region, and the difference in cost is usually small.
Keep it in the tenant
Copilot inside Microsoft 365 or Gemini inside Workspace keeps the content within a boundary you already control and already disclosed. For document work, that is often the lowest-friction answer.
Self-host for the sensitive slice
Open weight models running on your own infrastructure never leave the building. They are less capable than frontier models, which is fine for classification, extraction and redaction. Use them for the restricted tier and a hosted model for everything else.
Set retention to the minimum
You cannot lose data a vendor no longer holds. Shorten retention on prompts, transcripts and logs everywhere the setting exists.

SECTION 07What to put in your privacy policy

APP 8 disclosure is not satisfied by "we may transfer data overseas". Your policy needs enough detail that a reader knows what is happening. At minimum:

A table works better than paragraphs, because a reader can find their answer and a procurement officer can copy it. Our own privacy policy uses one, listing each provider category, what it receives and where it processes, if you want a working example to borrow the structure from.

SECTION 08The data residency checklist

Before you approve an AI tool
Processing and storage countries identified and written down
Sub-processor list located and reviewed
Data processing addendum read, with the training clause found and quoted
Plan tier confirmed in the billing portal, not assumed
Australian region selected where one exists
Retention set to the shortest period the work allows
Breach notification timeframe confirmed in writing
Sensitivity of the data matched to the tool, not the other way round
Privacy policy updated with recipient categories and countries
Assessment dated and filed, ready for the next procurement questionnaire

SECTION 09Common questions

Is it illegal to store Australian customer data overseas?

No. There is no general data localisation law in Australia for commercial data. APP 8 permits overseas disclosure provided you take reasonable steps to ensure APP-equivalent handling, or you obtain informed consent. Specific sectors have stricter rules, notably some health records and certain government data, so check your own sector before assuming.

Does choosing a Sydney region make us sovereign?

It makes the data resident in Australia, which satisfies many contract clauses and reduces latency. It does not make a US-headquartered provider immune from US legal process directed at the parent company. If a contract requires genuine sovereignty, you need an Australian-owned provider or your own infrastructure.

How do we know whether a tool trains on our data?

Read the data processing addendum for the specific plan you are on, and look for language about model training or service improvement. If the terms are ambiguous, email the vendor and ask for a written answer. Keep the reply. Ambiguity that survives a direct question is itself a finding.

What about AI features inside tools we already use?

They count. An AI summarise button inside your CRM or helpdesk is an AI tool, often powered by a third party the vendor has added as a sub-processor. Check whether the feature is on by default, because many are, and whether it introduced a new country to your data flow.

Do we need to tell customers which countries their data goes to?

Yes, where you disclose personal information overseas. APP 8 and APP 1 together require you to describe in your privacy policy the countries in which overseas recipients are likely to be located, where it is practicable to specify them.

REFERENCESSources

[1] Privacy Act 1988 (Cth), Australian Privacy Principle 8 and section 16C.
[2] OAIC, Australian Privacy Principles guidelines, Chapter 8, cross-border disclosure of personal information.
[3] OAIC, Guidance on privacy and the use of commercially available AI products, 21 October 2024.
[4] Clarifying Lawful Overseas Use of Data Act (US), 18 USC 2713.
[5] Agreement between the Government of Australia and the Government of the United States of America on Access to Electronic Data for the Purpose of Countering Serious Crime, in force 31 January 2026.
[6] Vendor documentation for Anthropic, OpenAI, Microsoft and Google, reviewed August 2026. Verify current terms before relying on them.

Written by Automatrix

Want the register built for you?

We map every AI tool running in your business, the plan each is on, where the data goes and whether it trains. You get the spreadsheet, the gaps and a fix list ordered by risk. Most businesses find at least one tool nobody approved.

0% read