Australian compliance conversations often treat the US CLOUD Act and the Australian Privacy Act as separate topics on separate desks. They're related. For any business running personal information on a US-owned cloud, it helps to understand what each law does and how they fit together. This piece explains both plainly, and shows why an Australian-owned provider gives you the simplest answer.
The essentials in five lines
- The US CLOUD Act applies to US-incorporated providers and the data they hold, wherever it sits.
- The Privacy Act penalises the Australian business when data is mishandled, up to A$50M (a cap raised by the 2022 Enforcement Act).
- APP 8 keeps you accountable for data you disclose to an overseas-controlled recipient.
- Contracts don't change where a provider is incorporated, so they shift paperwork, not ownership.
- Choose an Australian-owned provider and you get one local company, under Australian law, behind your data.
How the two laws relate
The CLOUD Act is a disclosure law: it sets out how US authorities can request data from US-incorporated companies. The Privacy Act is a protection law: it sets the standard for handling personal information in Australia, and the penalties for getting it wrong. When the same customer database sits under a US-owned provider, both are relevant at once, which is why it's worth understanding how they fit together.
What the US CLOUD Act actually covers
The Clarifying Lawful Overseas Use of Data (CLOUD) Act (US, 2018) allows US authorities to request that US-based technology companies produce data in their "possession, custody, or control", regardless of where in the world it is stored. It applies to data a US company controls, so the choice of a Sydney region doesn't change which company the law applies to.
The Australia–US CLOUD Act agreement, in force since 31 January 2024, streamlines cross-border government access in both directions. It also means Australian providers can be reached through a treaty path, capped at serious crime and subject to the agreement's safeguards. The practical difference comes down to ownership: a US-incorporated provider answers to US law as a matter of course, while an Australian provider answers to Australian law, with the treaty path as the narrower exception.
What the Privacy Act 2024 now requires
The Privacy and Other Legislation Amendment Act 2024 delivered the sharpest privacy reform in a generation:
- Civil penalties up to A$50 million for serious or repeated interference with privacy (with alternative formulas tied to benefit or turnover) — a cap raised by the 2022 Enforcement Act and retained under the 2024 reforms.
- A statutory tort for serious invasions of privacy, individuals can now sue directly.
- Stronger security and transparency duties, with a regulator handed sharper enforcement powers.
Alongside the existing Notifiable Data Breaches scheme, the cost of a poorly-governed stack is no longer theoretical, it is quantified, and it lands on the Australian business, not the offshore provider.
The two laws, side by side
| US CLOUD Act (2018) | Privacy Act 2024 (Cth) | |
|---|---|---|
| Purpose | Governs disclosure of data to US authorities | Protect personal information; penalise mishandling |
| Who it binds | US-incorporated providers, worldwide | The Australian business (APP entity) |
| Trigger | A US legal request | Interference with privacy / a data breach |
| Where data sits | Applies regardless of where data is stored | Onshore expected; overseas disclosure regulated (APP 8) |
| Consequence for you | Data may be disclosed under US process | Penalties to A$50M, a tort, breach obligations |
A worked example
Consider a Melbourne healthtech company storing patient records with a US-owned managed database, Sydney region. The data rests in Australia, but the company that runs the platform is US-incorporated and therefore answers to US law, while the healthtech company remains the accountable APP entity under Australian law. Nothing here is dramatic, it's simply two sets of rules applying at once. Choosing an Australian-owned provider collapses that into one: an Australian company, under Australian law, holding Australian data.
The simplest compliance story is the one you don't have to explain: one Australian company, under Australian law, behind your data.
Why contracts alone don't settle it
The instinct is to paper over the gap: data-processing addenda, standard clauses, region commitments. These matter, but they don't change where a provider is incorporated or who owns it. Under Australian Privacy Principle 8, you stay accountable for what an overseas-controlled recipient does with the personal information you disclose to it. Clauses move the paperwork; they don't move the ownership.
The simplest answer: an Australian-owned provider
There's a simpler way to line everything up rather than manage two sets of rules: choose a provider with no US (or other foreign) parent in the chain, just one Australian company under Australian law. Your data then sits with an Australian business, which lines up naturally with your Privacy Act obligations. Check this by ownership, not by a region dropdown: look at the ABN, the parent structure, and every sub-processor. We walk through that test in Data sovereignty in Australia.
How WattleDB keeps it simple
WattleDB is built to make this simple. It's a wholly Australian-owned Backend-as-a-Service, built by RR Sols Pty Ltd, an Australian company with no foreign parent, running entirely on Australian-owned infrastructure in Sydney with cross-state backups in Melbourne. There's one Australian company, under Australian law, behind your data, and no foreign parent to name in a procurement questionnaire. The platform is architected for IRAP assessment at the PROTECTED level, giving regulated buyers a clear alignment story. That turns a two-law compliance conversation into a one-line answer: owned here, hosted here, supported here.