Australian compliance conversations often treat the US CLOUD Act and the Australian Privacy Act as separate topics on separate desks. They're related. For any business running personal information on a US-owned cloud, it helps to understand what each law does and how they fit together. This piece explains both plainly, and shows why an Australian-owned provider gives you the simplest answer.

The essentials in five lines

  • The US CLOUD Act applies to US-incorporated providers and the data they hold, wherever it sits.
  • The Privacy Act penalises the Australian business when data is mishandled, up to A$50M (a cap raised by the 2022 Enforcement Act).
  • APP 8 keeps you accountable for data you disclose to an overseas-controlled recipient.
  • Contracts don't change where a provider is incorporated, so they shift paperwork, not ownership.
  • Choose an Australian-owned provider and you get one local company, under Australian law, behind your data.

How the two laws relate

The CLOUD Act is a disclosure law: it sets out how US authorities can request data from US-incorporated companies. The Privacy Act is a protection law: it sets the standard for handling personal information in Australia, and the penalties for getting it wrong. When the same customer database sits under a US-owned provider, both are relevant at once, which is why it's worth understanding how they fit together.

What the US CLOUD Act actually covers

The Clarifying Lawful Overseas Use of Data (CLOUD) Act (US, 2018) allows US authorities to request that US-based technology companies produce data in their "possession, custody, or control", regardless of where in the world it is stored. It applies to data a US company controls, so the choice of a Sydney region doesn't change which company the law applies to.

The Australia–US CLOUD Act agreement, in force since 31 January 2024, streamlines cross-border government access in both directions. It also means Australian providers can be reached through a treaty path, capped at serious crime and subject to the agreement's safeguards. The practical difference comes down to ownership: a US-incorporated provider answers to US law as a matter of course, while an Australian provider answers to Australian law, with the treaty path as the narrower exception.

What the Privacy Act 2024 now requires

The Privacy and Other Legislation Amendment Act 2024 delivered the sharpest privacy reform in a generation:

  • Civil penalties up to A$50 million for serious or repeated interference with privacy (with alternative formulas tied to benefit or turnover) — a cap raised by the 2022 Enforcement Act and retained under the 2024 reforms.
  • A statutory tort for serious invasions of privacy, individuals can now sue directly.
  • Stronger security and transparency duties, with a regulator handed sharper enforcement powers.

Alongside the existing Notifiable Data Breaches scheme, the cost of a poorly-governed stack is no longer theoretical, it is quantified, and it lands on the Australian business, not the offshore provider.

The two laws, side by side

 US CLOUD Act (2018)Privacy Act 2024 (Cth)
PurposeGoverns disclosure of data to US authoritiesProtect personal information; penalise mishandling
Who it bindsUS-incorporated providers, worldwideThe Australian business (APP entity)
TriggerA US legal requestInterference with privacy / a data breach
Where data sitsApplies regardless of where data is storedOnshore expected; overseas disclosure regulated (APP 8)
Consequence for youData may be disclosed under US processPenalties to A$50M, a tort, breach obligations

A worked example

Consider a Melbourne healthtech company storing patient records with a US-owned managed database, Sydney region. The data rests in Australia, but the company that runs the platform is US-incorporated and therefore answers to US law, while the healthtech company remains the accountable APP entity under Australian law. Nothing here is dramatic, it's simply two sets of rules applying at once. Choosing an Australian-owned provider collapses that into one: an Australian company, under Australian law, holding Australian data.

The simplest compliance story is the one you don't have to explain: one Australian company, under Australian law, behind your data.

Why contracts alone don't settle it

The instinct is to paper over the gap: data-processing addenda, standard clauses, region commitments. These matter, but they don't change where a provider is incorporated or who owns it. Under Australian Privacy Principle 8, you stay accountable for what an overseas-controlled recipient does with the personal information you disclose to it. Clauses move the paperwork; they don't move the ownership.

The simplest answer: an Australian-owned provider

There's a simpler way to line everything up rather than manage two sets of rules: choose a provider with no US (or other foreign) parent in the chain, just one Australian company under Australian law. Your data then sits with an Australian business, which lines up naturally with your Privacy Act obligations. Check this by ownership, not by a region dropdown: look at the ABN, the parent structure, and every sub-processor. We walk through that test in Data sovereignty in Australia.

How WattleDB keeps it simple

WattleDB is built to make this simple. It's a wholly Australian-owned Backend-as-a-Service, built by RR Sols Pty Ltd, an Australian company with no foreign parent, running entirely on Australian-owned infrastructure in Sydney with cross-state backups in Melbourne. There's one Australian company, under Australian law, behind your data, and no foreign parent to name in a procurement questionnaire. The platform is architected for IRAP assessment at the PROTECTED level, giving regulated buyers a clear alignment story. That turns a two-law compliance conversation into a one-line answer: owned here, hosted here, supported here.