Where does your cloud data actually live?
In a specific data centre in a specific country, chosen when the service was set up and almost never revisited. Both major providers operate Australian regions, and Microsoft 365 tenants created for Australian businesses generally store core data onshore, but backups, logs and third-party tools often sit elsewhere, and nobody checks.
The reason this deserves attention is not that overseas storage is dangerous in itself, because it usually is not. It is that you can be asked, and the question arrives at inconvenient moments: a tender asking where client data resides, an insurer's renewal questionnaire, a client in a regulated industry conducting supplier due diligence, or a privacy complaint. In every case, not knowing is worse than the answer.
The distinction to hold is between the law and your contracts. Australian privacy law does not generally forbid a private business from storing personal information overseas; it makes you accountable for what happens to it and imposes obligations when you disclose it offshore. What actually constrains most businesses is narrower and more concrete: a government-connected contract specifying Australian residency, a client agreement with a data location clause, or sector-specific requirements. Those are the documents that decide your answer, and they are the ones worth reading before a vendor's marketing page.
Where data quietly ends up elsewhere is worth knowing, because it is rarely the main system. Your primary platform is usually onshore if it was set up that way. The leakage is in the periphery: a backup service defaulting to an overseas region, monitoring and logging platforms processing offshore, a support arrangement where staff in another country can access your environment, and the smaller SaaS tools the business has accumulated, each with its own hosting arrangement nobody has examined. A file-sharing tool someone signed up for in 2023 is as much a data location decision as your main platform.
So the practical job is an inventory with a location column. For each significant service, record which region it runs in, where its backups are held, and whether support staff outside Australia can access the data. Most of this is answerable from admin portals and vendor documentation in an afternoon, and the exercise usually surfaces one or two surprises. Then write it down, because the value is having a current answer ready when someone asks rather than assembling one under time pressure during a tender.
Region is also worth deciding deliberately at setup for a practical reason beyond compliance: it is one of the few cloud choices that is genuinely awkward to reverse. Some services can be migrated on request, others need rebuilding, and a few cannot move at all. Choosing the Australian region also keeps latency low, which matters for interactive workloads, so the default answer for an Australian business is usually straightforward and should simply be confirmed rather than assumed.
Support access is the part of this that most often goes unexamined, and it is a legitimate question rather than a suspicious one. Where data sits at rest is one issue; who can reach it is another, and plenty of vendors with Australian hosting provide support from offshore teams who can view customer environments. That may be entirely acceptable to you, and it may breach a client agreement you have signed. Ask the question explicitly, because a residency answer alone does not cover it.
One qualification worth making, because this topic attracts more heat than it deserves. Onshore does not mean secure. A poorly configured Australian environment with weak identity controls is far more exposed than a well-run overseas one, and data residency answers a question about jurisdiction rather than about protection. Treat it as a compliance and contractual matter, and keep the actual security work, multi-factor authentication, access control, tested backups, in its own column where it belongs.
A related question comes up in the same conversations and is worth settling at the same time: what happens to your data if you stop paying. Every cloud service has a retention period after cancellation, after which the data is deleted, and those periods are shorter than people assume. Knowing yours matters most in the situations where nobody is thinking clearly, a dispute with a provider or a lapsed card, which is exactly when a short window turns an administrative problem into a permanent loss.
If you cannot currently say which country each of your major systems stores data in, that is a short project with a durable payoff: the answer gets reused in every tender and questionnaire from then on. If you want it checked and documented properly, call 1800 456 567.
Confirm your data is where you think it is
We check the regions your services actually run in, document them, and put the answer in writing for your tender and insurance responses.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business