"Our data is in Australia" is one of the most confidently incomplete statements in Australian tech procurement. It's usually true, and it answers a question about geography when the more useful question is about ownership. This guide untangles the two, gives you the plain facts on the US CLOUD Act and the 2024 Privacy Act reforms, and offers a checklist for a stack that is Australian-owned in fact, not just in marketing.

The core distinction

  • Residency = where the data physically sits (a Sydney data centre).
  • Sovereignty = whose laws govern the data (set by who owns the provider).
  • You can have Australian residency without Australian sovereignty.
  • A US-owned provider in Sydney = residency yes, Australian ownership no.
  • Sovereignty is verified by corporate ownership, not by a region dropdown.

Residency vs sovereignty, precisely

Data residency is a statement of physical fact: the bytes are stored on servers located in Australia. It's real and it matters for latency and for some localisation laws, but on its own it tells you nothing about who owns and governs the data.

Data sovereignty is a statement about ownership and law: which country's laws govern the data. That is set by the corporate ownership and home jurisdiction of the provider, not by where a hard drive spins. A company incorporated in the United States is subject to US law everywhere it operates, including its Australian region. An Australian-owned company, running Australian-owned infrastructure, answers first and foremost to Australian law and Australian courts.

Choosing an Australian region changes where your data rests. It does not change who owns and governs it. Only the provider's ownership does that.

The CLOUD Act, briefly, and why ownership settles it

A little background helps here. The Clarifying Lawful Overseas Use of Data (CLOUD) Act, passed in the US in 2018, provides that US-based technology companies can be required to produce data in their "possession, custody, or control", regardless of where in the world that data is stored. In plain terms, a US company's home-country law generally follows the data it holds. That is a neutral fact about how corporate jurisdiction works, not a reason to be anxious about the cloud.

Ownership is what changes the answer. Choose a provider with no US corporate parent anywhere in the chain, Australian-owned, Australian-operated and Australian-hosted, and the company holding your data answers first to Australian law, with one Australian company standing behind it. That's the point of Australian ownership: the company that holds your data, and the law that governs it, are both here. You get a clear answer for your customers and your compliance team, instead of a footnote about a foreign parent.

It's worth being precise about what that does and doesn't mean, because the honest version is the one that survives a procurement questionnaire. It does not mean your data is beyond the reach of any legal process anywhere. No provider can promise that, and you should be sceptical of one that does. Australia and the United States have a CLOUD Act agreement, and mutual legal assistance arrangements have existed for decades, so a foreign authority can still seek data held here — but through a treaty channel, for defined categories of serious crime, with Australian legal safeguards in the path rather than a foreign parent's compliance desk. Australian agencies have their own compulsory powers here too.

What Australian ownership removes is the direct route: an order served on a foreign parent, reaching data held by its Australian subsidiary, decided under another country's law, with no Australian court involved. That is a real difference and it is the one worth buying. It is not the same as immunity, and we would rather say so here than have you find the distinction yourself during a due-diligence review.

The Privacy Act 2024: the stakes went up

The Privacy and Other Legislation Amendment Act 2024 delivered the first tranche of the most significant reform to the Privacy Act 1988 in a generation. The direction of travel is unambiguous, tougher enforcement, real financial consequences, and new rights for individuals.

  • A statutory tort for serious invasions of privacy. Individuals now have a direct right to sue for serious invasions of privacy, a private right of action that didn't previously exist.
  • Penalties up to A$50 million. For serious or repeated interference with privacy, civil penalties reach A$50M (or, on alternative formulas, more) — a cap raised by the 2022 Enforcement Act and carried into the current regime, a scale designed to change board-level behaviour.
  • Stronger security and transparency expectations, with the regulator handed sharper enforcement teeth and greater ability to act.

Combine that with the existing Notifiable Data Breaches scheme, which obliges you to assess and report eligible breaches, and the cost of a poorly-governed data stack is no longer theoretical.

APP 8 and cross-border disclosure

Australian Privacy Principle 8 is the one most SaaS teams get to know well. It does not ban sending personal information overseas, but it makes you accountable for what an overseas recipient does with it. Keeping personal information onshore with an Australian-owned provider keeps that responsibility simple, everything sits under Australian law from the start, so there is no cross-border handoff to manage with contractual clauses.

Where Australian ownership is effectively mandatory

Beyond general good practice, several sectors face rules that make Australian ownership a practical requirement rather than a nice-to-have:

  • Health & aged care, My Health Records and state health records legislation impose strict handling and, in places, localisation of health information.
  • Financial services & the Consumer Data Right, CDR data carries localisation obligations; financial data is among the most tightly governed.
  • Government & govtech, Commonwealth and state procurement increasingly require onshore, sovereign hosting, reinforced by the direction of whole-of-government cloud policy.
  • Legal, education & childcare, professional confidentiality obligations and the sensitivity of records about children raise the bar well above the statutory minimum.

We break the specific rules down by sector in Industries.

The Australian-owned stack checklist

Use this to test any provider, including us. Ownership is a property you can verify, not a badge you take on trust.

  1. Corporate ownership. Is the provider an Australian entity with no foreign parent? Check the ABN and the ownership structure, not the marketing page.
  2. Australian ownership all the way down. Is every company in the chain, parent, processor, sub-processor and the underlying infrastructure, Australian-owned? One foreign link changes whose laws govern the data.
  3. Data location. Are primary storage and backups in Australian data centres? Ask specifically about backups and disaster recovery.
  4. Support & administration. Are the people with production access Australian citizens working onshore, under Australian law?
  5. Written commitments. Will they state their ownership and data-handling in a contract or DPA, not just a webpage?
Sovereignty isn't a region dropdown. It's an ownership question: name every company in the chain, and confirm each one is owned here and answers to Australian law.

How WattleDB is built for this

WattleDB is designed to pass that checklist by construction. It's a wholly Australian-owned Backend-as-a-Service, built by RR Sols Pty Ltd, an Australian company with no foreign parent, running entirely on Australian-owned infrastructure in Sydney and Melbourne, with backups kept cross-state within Australia. Ownership, operation and support are all Australian, and there is no foreign parent company anywhere in the picture, so your data stays in Australia, in Australian hands, with one Australian company behind it. The platform is architected for IRAP assessment at the PROTECTED level, giving regulated buyers a clear alignment story. For most teams it's the difference between explaining a foreign corporate parent in every procurement round and having a clean, one-line answer.