Article
Most Australian businesses run on American software and have never had reason to think about this. It takes about ten minutes to understand, and it changes which vendor questions are worth asking.
A US law lets US authorities compel American technology companies to hand over data those companies hold — including data stored on servers outside the United States. If your vendor is a US company, choosing their Australian region does not place your data beyond that reach. The region is a fact about geography; the obligation is a fact about the company.
It came out of a genuine legal deadlock. US authorities sought emails held by a major provider in an Irish data centre. The provider argued a US warrant could not reach Ireland. The case ran for years and reached the Supreme Court without a clean answer.
Congress ended the argument in 2018 by legislating. The CLOUD Act made it explicit: a provider subject to US jurisdiction must produce data in its possession, custody or control, wherever in the world it happens to be stored.
It is worth being fair about the intent. This is a lawful-process statute, not a surveillance free-for-all — it is about serving valid legal orders on companies that undeniably hold the data. The point for a buyer is simply that the geography argument no longer works.
"Our data is in Sydney, so we're fine." Location is not the test. Control is. A US company with control over data in Sydney is within scope.
"We'd be told if it happened." Not necessarily. Orders can carry non-disclosure obligations. Transparency reports are published in aggregate, long after the fact, and usually not broken down by country.
"We're a small business, nobody cares about us." Probably true, and beside the point. The question is not whether you are a target. It is whether you have made a cross-border disclosure of your customers' personal information — because under APP 8 that is your accountability whether or not anyone ever acts on it.
Not every system needs this analysis, and pretending otherwise is how security advice gets tuned out. If a tool holds no personal information — your CI pipeline, your design files, your internal wiki — the CLOUD Act question is close to irrelevant and there are better things to spend attention on.
It matters where the system holds personal information about Australians, and it matters most where that information is sensitive: health, finance, legal, anything about children. Support desks land in that category by accident rather than design, which is exactly why they get missed in the review.
Not directly. It applies to providers subject to US jurisdiction. It affects Australian businesses indirectly, because if you use a US provider then your data is held by a company that is within its reach — and under APP 8 you remain accountable for that disclosure.
No. The Act reaches data in a provider's possession, custody or control regardless of where it is stored. Choosing an Australian region of a US provider gives you data residency, lower latency and a residency compliance story — it does not remove the provider from US jurisdiction.
Where the company is incorporated, which jurisdictions can compel it, where AI inference runs specifically, whether processing fails over to another country if the local region is unavailable, and whether they publish government request figures. The inference question is the one most often left unanswered.