Australia / Regulation map / Email

Know which rules create a boundary. And which do not.

Australian regulation is not one data-residency rule. It is a stack of federal principles, system-specific localisation, industry standards, state overlays, contracts, and procurement requirements. Start with the workload, then trace every byte.

A matte-black containment instrument showing a single ember signal held inside a defined processing boundary.
AU · Regulation map · Checked 16 Aug 2026

The short answer

Australian hosting is not one universal legal requirement.

Most Australian organisations are not subject to a blanket rule that every email or personal record must stay in Australia. Local processing becomes valuable because it can reduce cross-border disclosure, simplify third-party and offshoring reviews, and meet customer policy. Some narrower regimes—most clearly section 77 of the My Health Records Act—create explicit Australian boundaries for covered participants and information. The correct answer depends on who you are, what the message contains, and which system or contract it supports.

This is an engineering and vendor-evaluation guide, not legal advice. Confirm the rules that apply to your organisation, contract, and workload.

Applicability

Start with the entity, the data, and the complete path.

01 / Entity

Identify who is regulated.

Turnover is only one trigger. Health providers, government agencies, APRA-regulated entities, accredited CDR participants, and critical-infrastructure operators can enter different regimes.

02 / Data

Classify the exact workload.

A recipient address, appointment context, reset link, CDR field, My Health Record fact, delivery event, and application log can carry different sensitivity and handling consequences.

03 / Path

Trace processing, not hosting copy.

Map API ingress, queues, delivery, metadata, webhooks, logs, backups, support access, subprocessors, retention, deletion, and the recipient's mailbox provider.

Regulation map

What applies, what it changes, and where Boundry helps.

01

Federal baseline

Privacy Act + APPs

No blanket localisation

Privacy Act 1988 and Australian Privacy Principles

Applies to
Australian Government agencies and many private-sector organisations, generally including organisations above the turnover threshold and specifically covered businesses such as private health providers.
What it requires
APP 8 creates duties around disclosure to overseas recipients and can preserve accountability for their handling. APP 11 requires reasonable security and, when information is no longer needed, reasonable destruction or de-identification steps.
Regional effect
The Act does not say that every Australian workload must be hosted in Australia. An in-country path can reduce the number of overseas disclosures and make the remaining processors, support paths, retention, and contracts easier to assess.
How Boundry helps

A project is fixed to Sydney and the regional plane is designed to own message content, recipients, queues, events, and provider state. Boundry documents known control-plane and operational exceptions instead of treating a sending-region selector as the whole answer.

What it does not replace

Boundry does not decide whether APP 8 applies to a particular transfer or replace the customer's privacy notices, purpose analysis, contracts, security program, or deletion duties.

02

Incident response

NDB scheme

Security and evidence

Notifiable Data Breaches scheme

Applies to
Entities already covered by Privacy Act security obligations, including Australian Government agencies, many larger organisations, and specifically covered entities such as private health providers.
What it requires
An eligible breach generally involves unauthorised access, disclosure, or loss that is likely to cause serious harm and has not been neutralised by remedial action. Covered entities must assess and, where required, notify affected people and the OAIC.
Regional effect
The scheme does not mandate Australian hosting. Location, access paths, data sensitivity, encryption, logs, and the identity of processors all affect how quickly a team can contain and assess an incident.
How Boundry helps

Keeping the communication plane and its operational records together in one defined region can make the affected data classes and event trail easier to identify during an assessment.

What it does not replace

Boundry is one service provider in the response chain. The customer still owns its breach-response plan, legal threshold decision, multi-vendor investigation, and notifications.

03

Healthcare system

My Health Record

Explicit Australian boundary

My Health Records Act 2012 — section 77

Applies to
The System Operator and specified registered repository, portal, and contracted service providers that hold records for the My Health Record system or access information relating to those records.
What it requires
Section 77 restricts covered participants from holding or taking relevant records outside Australia and from processing or handling related information outside Australia, subject to the Act's terms and limited exceptions.
Regional effect
This is a genuine localisation rule, but it is narrower than all healthcare data and all healthcare email. Applicability turns on the system, participant, record, and processing role.
How Boundry helps

Boundry offers a Sydney regional email plane that can be assessed when a notification workflow must avoid adding an offshore messaging path. Sensitive record content should still be minimised and kept behind an authenticated application boundary.

What it does not replace

Boundry does not claim registration as a My Health Record operator or automatic compliance with the Act. Do not place My Health Record information into email without a specific legal and architecture assessment.

04

Jurisdiction overlay

State privacy laws

Scope varies by state

State and territory privacy and health-record laws

Applies to
State and territory public-sector agencies under their local regimes. Private health providers in NSW, Victoria, and the ACT can face both federal and local health-privacy requirements.
What it requires
The applicable principles vary across collection, security, use, disclosure, access, retention, and transborder flows. Western Australia's new public-sector privacy framework commenced in July 2026.
Regional effect
Selecting Australia is only the first layer. The customer's state, sector, public/private status, and the people whose information is handled can change the governing rule set.
How Boundry helps

A common Sydney communication plane gives multi-state teams one provider data path to document, while the regional regulation map identifies where local legal analysis still needs to branch.

What it does not replace

One infrastructure region does not harmonise state laws or determine which regulator, health principle, retention period, or public-record rule applies.

05

Financial services

APRA CPS 230

Stronger offshore governance

CPS 230 Operational Risk Management

Applies to
APRA-regulated banks, insurers, private health insurers, and superannuation entities when managing operational risk and material service-provider arrangements.
What it requires
Regulated entities must identify and manage material arrangements, maintain appropriate agreements and oversight, and notify APRA before entering or materially changing a material offshoring arrangement.
Regional effect
CPS 230 is not a blanket data-localisation rule. It does make offshore service delivery, including the physical location of relevant data or personnel, a specific governance and notification consideration when the arrangement is material.
How Boundry helps

A defined Australian processing path can reduce ambiguity in the offshoring assessment and give vendor-risk teams a narrower architecture, service location, and subprocessor surface to review.

What it does not replace

Boundry cannot determine materiality, critical-operation impact, APRA notification duties, or whether the customer's wider arrangement remains offshore through other services or personnel.

06

Financial services

APRA CPS 234

Third-party assurance

CPS 234 Information Security

Applies to
APRA-regulated entities and the information assets they manage directly or through related parties and third parties.
What it requires
Entities must maintain information-security capability and controls proportionate to threats and asset sensitivity, test control effectiveness, evaluate relevant third-party controls, and notify APRA of material incidents.
Regional effect
CPS 234 focuses on control effectiveness rather than a country pin. Residency becomes useful when it reduces an untrusted environment and produces clearer evidence about access, lifecycle, and third parties.
How Boundry helps

Boundry's architecture and planned Region Manifest are structured around the data classes a third-party review asks about: content, metadata, queues, events, logs, support, subprocessors, retention, and exceptions.

What it does not replace

Boundry is not 'CPS 234 certified'. The regulated entity remains responsible for classifying the asset, evaluating Boundry's controls, testing reliance, and governing the complete service chain.

07

Consumer data

CDR safeguards

Restricted overseas disclosure

Consumer Data Right Privacy Safeguards

Applies to
Accredited persons, accredited data recipients, data holders, and outsourced service-provider arrangements handling CDR data under the CDR framework.
What it requires
Privacy Safeguard 8 restricts overseas disclosure of CDR data unless an exception applies. CDR outsourcing arrangements also bring specific consent, use, disclosure, security, deletion, and chain-of-provider requirements.
Regional effect
The CDR framework creates stronger controls around overseas disclosure than a generic preference for local hosting. The full outsourced-service-provider chain and the data placed into a message still need to be assessed.
How Boundry helps

A Sydney email plane may remove an unnecessary overseas messaging provider from a CDR-adjacent notification workflow and make the remaining outsourcing chain easier to enumerate.

What it does not replace

Boundry does not claim CDR accreditation or that every use of its API forms a compliant CDR outsourcing arrangement. Do not send CDR data until the role, contract, consent, disclosure, and deletion design is reviewed.

08

Critical infrastructure

SOCI Act

Risk and incident governance

Security of Critical Infrastructure Act 2018

Applies to
Responsible entities and direct-interest holders for critical infrastructure assets, with additional obligations for specified data-storage and processing arrangements and Systems of National Significance.
What it requires
Relevant entities may need to provide register information, report cyber incidents, maintain a critical-infrastructure risk-management program, and notify data-service providers when they process business-critical data for an asset.
Regional effect
The SOCI Act is not a general Australian-hosting mandate. It raises the importance of knowing which providers process business-critical data, where dependencies sit, and how incidents are detected and reported.
How Boundry helps

A discrete regional messaging path helps an operator enumerate the provider, region, message data, and event path for communication workloads connected to a critical operation.

What it does not replace

Boundry does not determine whether an asset or dataset is covered, operate the customer's risk program, or satisfy incident and register obligations for the broader critical-infrastructure system.

09

Government procurement

PSPF / ISM / IRAP

Classification and assurance

Australian Government cloud security assessment framework

Applies to
Commonwealth entities and suppliers handling government information, according to the relevant entity's classification, risk assessment, procurement, PSPF, ISM, and authorisation requirements.
What it requires
Government cloud consumers assess whether a service is suitable to store, process, and communicate the intended data. The assessment considers classification, architecture, controls, provider access, contractual requirements, and independent assurance such as IRAP where required.
Regional effect
Australian location can be a procurement requirement or risk treatment, but a Sydney region alone does not make a service suitable for classified or government information.
How Boundry helps

Boundry can provide an Australian regional architecture and a data-path account that a government supplier can include in its own cloud and vendor assessment.

What it does not replace

Boundry is not IRAP assessed and does not claim Australian Government certification. The customer must obtain the authorisation and assurance required for its information and contract.

10

Message conduct

Spam Act

Consent and unsubscribe

Spam Act 2003

Applies to
Senders of commercial electronic messages with an Australian link. Whether a message is commercial depends on its content and purpose, not the name of the email product used to send it.
What it requires
Commercial messages generally require consent, accurate sender identification and contact details, and a functional unsubscribe mechanism. The sender remains responsible when another provider sends on its behalf.
Regional effect
Residency does not solve Spam Act compliance. Consent evidence, message classification, sender identity, suppression handling, and timely unsubscribe processing are separate operational requirements.
How Boundry helps

Boundry provides transactional delivery primitives and regional suppression/event data that can form part of the customer's messaging controls.

What it does not replace

Boundry does not infer consent, decide whether content is commercial, author the required sender information, or operate the customer's complete unsubscribe and marketing-governance process.

State and territory overlay

One country. Different public-sector and health regimes.

Commonwealth

The Privacy Act and APPs cover Australian Government agencies and many organisations, with specific coverage and exceptions. Sector laws and regulator standards can add to that baseline.

Practical effect

Begin with APP 8, APP 11, NDB, and any sector-specific overlay. Do not convert that baseline into a fictional universal localisation rule.

New South Wales

NSW public-sector privacy laws apply locally, and private health providers can face both the federal Privacy Act and the Health Records and Information Privacy Act.

Practical effect

Health workflows need the federal and NSW health-principle analysis, including security, use, disclosure, retention, and transborder questions.

Victoria

Victorian public-sector information is covered by state privacy law, while the Health Records Act can apply to private health providers alongside federal law.

Practical effect

Treat health information and transborder flows as a distinct local overlay rather than relying on a Commonwealth-only vendor review.

Australian Capital Territory

ACT agencies operate under territory privacy law, and private health providers can also face the ACT Health Records framework alongside federal obligations.

Practical effect

Public-sector and health-record workflows require an ACT-specific applicability check before selecting message content and providers.

Queensland

Queensland's Information Privacy Act covers the state public sector, including public-sector health services; private health providers remain within the federal health-provider rules.

Practical effect

The public/private status of the organisation changes the primary privacy regime even when the application and email workflow look identical.

Northern Territory

The Information Act provides the territory public-sector privacy framework. Private health providers remain subject to the applicable federal framework.

Practical effect

Confirm whether the customer is a territory agency, contractor, or private provider before mapping the communication path.

Tasmania

Tasmania's personal-information legislation covers its public sector, including public hospitals, while private health providers are covered federally.

Practical effect

Public hospital and private-provider workloads can have different legal owners even when both use the same software supplier.

South Australia

South Australia uses administrative Information Privacy Principles for state-government agencies rather than a general state privacy statute, with other health and confidentiality rules potentially applying.

Practical effect

Government contracts and agency policy can impose requirements that are not visible from the federal Privacy Act alone.

Western Australia

The Privacy and Responsible Information Sharing Act 2024 introduced a new Western Australian public-sector privacy framework, with core provisions commencing on 1 July 2026.

Practical effect

WA public-sector vendor reviews now need to account for the commenced state framework as well as contractual, health, records, and federal rules that may apply.

The honest boundary

What Boundry contributes—and what remains yours.

Review questionBoundry's contributionCustomer responsibility
Where is the project anchored?The project region is fixed at creation. Sydney is the only live regional communication plane.Confirm the selected region matches the workload and document any systems outside that plane.
Which communication data is regional?The regional architecture is designed around messages, recipients, queues, delivery events, suppressions, inbound content, and provider state.Minimise the fields placed in email and classify links, attachments, templates, and event metadata.
What evidence exists today?Boundry publishes its architecture, current retention status, and known exceptions. The complete production Region Manifest remains work in progress.Keep the final vendor assessment, contract, data-flow diagram, and legal applicability decision in your own evidence pack.
What happens after delivery?Boundry can define its path up to delivery. The recipient's mailbox provider and the recipient's own handling sit outside that infrastructure boundary.Keep sensitive content behind an authenticated application boundary and use the email as a minimal notification where appropriate.
How long is data retained?Automated per-data-class retention enforcement is not yet a public product guarantee; the current status is documented explicitly.Set the required retention outcome by data class and do not claim it until implementation, provider behaviour, and backup expiry are verified.

Apply the map

Regulation becomes useful when attached to a workload.

Australia / Healthcare / EmailApply this regulation map to healthcare notifications.

Trace patient invitations, results-ready messages, authentication, delivery events, state overlays, and My Health Record boundaries.

Open the healthcare guide →

Vendor review

Seven questions before approving an email path.

  1. 01Which entity, industry, system, contract, and state or territory make this rule applicable?
  2. 02Which data classes enter the email request, message, queue, event, webhook, log, backup, and support path?
  3. 03Does an advertised region govern sending, primary storage, all processing, or only one component?
  4. 04Which overseas recipients or administrators can access personal information, and under what contract and purpose?
  5. 05What retention and deletion outcome applies to live stores, logs, caches, support tools, and backups?
  6. 06Which incident evidence can the provider supply quickly enough for the customer's response obligations?
  7. 07What remains outside the provider boundary after delivery to the recipient's mailbox?

FAQ

Common Australian regulation and residency questions.

Does Australian privacy law require all data to stay in Australia?

No. The Privacy Act creates security and cross-border-disclosure obligations rather than one universal localisation rule. Specific systems, regulated arrangements, customer contracts, government classifications, and organisational policy can create stronger requirements.

Does using Boundry make an organisation compliant?

No provider can determine compliance for an unknown workload. Boundry can reduce and document the regional messaging path; the customer still owns applicability, data minimisation, lawful use, contracts, access controls, incident response, retention, and the rest of its system.

Can My Health Record information be sent through Boundry?

Do not assume so. Section 77 contains a real Australian boundary for covered participants and information, but location is not the only rule. Boundry does not claim My Health Record registration or automatic authorisation for record data in email.

Is a Sydney sending region enough for APRA or government review?

No. Location may simplify the assessment, but reviewers also need the service scope, information classification, controls, contracts, access paths, subprocessors, incident process, retention, assurance, and known exceptions.

Does the Spam Act apply to transactional email?

It applies to commercial electronic messages, and that classification depends on content and purpose. A transactional label does not override the Act. The sender remains responsible for consent and unsubscribe obligations where the message is commercial.

How current is this map?

Every source on this page was checked on 16 August 2026. Laws, standards, regulator guidance, and Boundry's own implementation can change, so the linked primary source should be checked for a live procurement or legal decision.

Primary sources

Use the map. Make the decision from the source.

Privacy Act rights and responsibilitiesOffice of the Australian Information Commissioner · checked 2026-08-16APP 8 — cross-border disclosure of personal informationOffice of the Australian Information Commissioner · checked 2026-08-16APP 11 — security of personal informationOffice of the Australian Information Commissioner · checked 2026-08-16Notifiable Data Breaches schemeOffice of the Australian Information Commissioner · checked 2026-08-16My Health Records Act 2012 — section 77Federal Register of Legislation · checked 2026-08-16State and territory privacy legislationOffice of the Australian Information Commissioner · checked 2026-08-16Privacy and Responsible Information Sharing Act 2024Western Australian Legislation · checked 2026-08-16CPS 230 Operational Risk ManagementAustralian Prudential Regulation Authority · checked 2026-08-16CPS 234 Information SecurityAustralian Prudential Regulation Authority · checked 2026-08-16Privacy Safeguard 8 — overseas disclosure of CDR dataOffice of the Australian Information Commissioner · checked 2026-08-16SOCI Act 2018 for data storage and processingCyber and Infrastructure Security Centre · checked 2026-08-16Australian Government Information Security ManualAustralian Signals Directorate · checked 2026-08-16Cloud assessment and authorisationAustralian Signals Directorate · checked 2026-08-16Avoid sending spamAustralian Communications and Media Authority · checked 2026-08-16Regional architectureBoundry · checked 2026-08-16Retention statusBoundry · checked 2026-08-16

Laws, standards, regulator guidance, contracts, and Boundry's own implementation can change. Recheck the primary source for a live procurement or legal decision.

Sydney · ap-southeast-2

Turn the requirement into a defined email boundary.

Start with one Australian transactional workflow. Classify the data, map the path, and give the reviewer evidence instead of a region slogan.