Article

What the CLOUD Act means if you buy US software

Most Australian businesses run on American software and have never had reason to think about this. It takes about ten minutes to understand, and it changes which vendor questions are worth asking.

The one-paragraph version

A US law lets US authorities compel American technology companies to hand over data those companies hold — including data stored on servers outside the United States. If your vendor is a US company, choosing their Australian region does not place your data beyond that reach. The region is a fact about geography; the obligation is a fact about the company.

Where it came from

It came out of a genuine legal deadlock. US authorities sought emails held by a major provider in an Irish data centre. The provider argued a US warrant could not reach Ireland. The case ran for years and reached the Supreme Court without a clean answer.

Congress ended the argument in 2018 by legislating. The CLOUD Act made it explicit: a provider subject to US jurisdiction must produce data in its possession, custody or control, wherever in the world it happens to be stored.

It is worth being fair about the intent. This is a lawful-process statute, not a surveillance free-for-all — it is about serving valid legal orders on companies that undeniably hold the data. The point for a buyer is simply that the geography argument no longer works.

Three things people get wrong

"Our data is in Sydney, so we're fine." Location is not the test. Control is. A US company with control over data in Sydney is within scope.

"We'd be told if it happened." Not necessarily. Orders can carry non-disclosure obligations. Transparency reports are published in aggregate, long after the fact, and usually not broken down by country.

"We're a small business, nobody cares about us." Probably true, and beside the point. The question is not whether you are a target. It is whether you have made a cross-border disclosure of your customers' personal information — because under APP 8 that is your accountability whether or not anyone ever acts on it.

When it genuinely does not matter

Not every system needs this analysis, and pretending otherwise is how security advice gets tuned out. If a tool holds no personal information — your CI pipeline, your design files, your internal wiki — the CLOUD Act question is close to irrelevant and there are better things to spend attention on.

It matters where the system holds personal information about Australians, and it matters most where that information is sensitive: health, finance, legal, anything about children. Support desks land in that category by accident rather than design, which is exactly why they get missed in the review.

What to actually do

  1. Inventory what holds personal information. Most organisations are surprised, and the support desk is usually the surprise.
  2. For each, ask where the vendor is incorporated — not where the data sits.
  3. Ask where AI inference runs. This is the live gap: data resident in Sydney, every ticket sent to a US model to be classified. It is rarely volunteered.
  4. Ask what happens on failover. Does processing move offshore if the local region is unavailable? A silent failover undoes the guarantee at the worst moment.
  5. Decide deliberately. Sometimes the right answer is to accept it and write down why. That is a decision. Not knowing is not.

Read next

Common questions

Does the CLOUD Act apply to Australian companies?

Not directly. It applies to providers subject to US jurisdiction. It affects Australian businesses indirectly, because if you use a US provider then your data is held by a company that is within its reach — and under APP 8 you remain accountable for that disclosure.

Can I avoid the CLOUD Act by choosing an Australian region?

No. The Act reaches data in a provider's possession, custody or control regardless of where it is stored. Choosing an Australian region of a US provider gives you data residency, lower latency and a residency compliance story — it does not remove the provider from US jurisdiction.

What should I ask a vendor about this?

Where the company is incorporated, which jurisdictions can compel it, where AI inference runs specifically, whether processing fails over to another country if the local region is unavailable, and whether they publish government request figures. The inference question is the one most often left unanswered.