Identify who is regulated.
Turnover is only one trigger. Health providers, government agencies, APRA-regulated entities, accredited CDR participants, and critical-infrastructure operators can enter different regimes.
Australia / Regulation map / Email
Australian regulation is not one data-residency rule. It is a stack of federal principles, system-specific localisation, industry standards, state overlays, contracts, and procurement requirements. Start with the workload, then trace every byte.

The short answer
Most Australian organisations are not subject to a blanket rule that every email or personal record must stay in Australia. Local processing becomes valuable because it can reduce cross-border disclosure, simplify third-party and offshoring reviews, and meet customer policy. Some narrower regimes—most clearly section 77 of the My Health Records Act—create explicit Australian boundaries for covered participants and information. The correct answer depends on who you are, what the message contains, and which system or contract it supports.
This is an engineering and vendor-evaluation guide, not legal advice. Confirm the rules that apply to your organisation, contract, and workload.
Applicability
Turnover is only one trigger. Health providers, government agencies, APRA-regulated entities, accredited CDR participants, and critical-infrastructure operators can enter different regimes.
A recipient address, appointment context, reset link, CDR field, My Health Record fact, delivery event, and application log can carry different sensitivity and handling consequences.
Map API ingress, queues, delivery, metadata, webhooks, logs, backups, support access, subprocessors, retention, deletion, and the recipient's mailbox provider.
Regulation map
Federal baseline
A project is fixed to Sydney and the regional plane is designed to own message content, recipients, queues, events, and provider state. Boundry documents known control-plane and operational exceptions instead of treating a sending-region selector as the whole answer.
Boundry does not decide whether APP 8 applies to a particular transfer or replace the customer's privacy notices, purpose analysis, contracts, security program, or deletion duties.
Incident response
Keeping the communication plane and its operational records together in one defined region can make the affected data classes and event trail easier to identify during an assessment.
Boundry is one service provider in the response chain. The customer still owns its breach-response plan, legal threshold decision, multi-vendor investigation, and notifications.
Healthcare system
Boundry offers a Sydney regional email plane that can be assessed when a notification workflow must avoid adding an offshore messaging path. Sensitive record content should still be minimised and kept behind an authenticated application boundary.
Boundry does not claim registration as a My Health Record operator or automatic compliance with the Act. Do not place My Health Record information into email without a specific legal and architecture assessment.
Jurisdiction overlay
A common Sydney communication plane gives multi-state teams one provider data path to document, while the regional regulation map identifies where local legal analysis still needs to branch.
One infrastructure region does not harmonise state laws or determine which regulator, health principle, retention period, or public-record rule applies.
Financial services
A defined Australian processing path can reduce ambiguity in the offshoring assessment and give vendor-risk teams a narrower architecture, service location, and subprocessor surface to review.
Boundry cannot determine materiality, critical-operation impact, APRA notification duties, or whether the customer's wider arrangement remains offshore through other services or personnel.
Financial services
Boundry's architecture and planned Region Manifest are structured around the data classes a third-party review asks about: content, metadata, queues, events, logs, support, subprocessors, retention, and exceptions.
Boundry is not 'CPS 234 certified'. The regulated entity remains responsible for classifying the asset, evaluating Boundry's controls, testing reliance, and governing the complete service chain.
Consumer data
A Sydney email plane may remove an unnecessary overseas messaging provider from a CDR-adjacent notification workflow and make the remaining outsourcing chain easier to enumerate.
Boundry does not claim CDR accreditation or that every use of its API forms a compliant CDR outsourcing arrangement. Do not send CDR data until the role, contract, consent, disclosure, and deletion design is reviewed.
Critical infrastructure
A discrete regional messaging path helps an operator enumerate the provider, region, message data, and event path for communication workloads connected to a critical operation.
Boundry does not determine whether an asset or dataset is covered, operate the customer's risk program, or satisfy incident and register obligations for the broader critical-infrastructure system.
Government procurement
Boundry can provide an Australian regional architecture and a data-path account that a government supplier can include in its own cloud and vendor assessment.
Boundry is not IRAP assessed and does not claim Australian Government certification. The customer must obtain the authorisation and assurance required for its information and contract.
Message conduct
Boundry provides transactional delivery primitives and regional suppression/event data that can form part of the customer's messaging controls.
Boundry does not infer consent, decide whether content is commercial, author the required sender information, or operate the customer's complete unsubscribe and marketing-governance process.
State and territory overlay
The Privacy Act and APPs cover Australian Government agencies and many organisations, with specific coverage and exceptions. Sector laws and regulator standards can add to that baseline.
Begin with APP 8, APP 11, NDB, and any sector-specific overlay. Do not convert that baseline into a fictional universal localisation rule.
NSW public-sector privacy laws apply locally, and private health providers can face both the federal Privacy Act and the Health Records and Information Privacy Act.
Health workflows need the federal and NSW health-principle analysis, including security, use, disclosure, retention, and transborder questions.
Victorian public-sector information is covered by state privacy law, while the Health Records Act can apply to private health providers alongside federal law.
Treat health information and transborder flows as a distinct local overlay rather than relying on a Commonwealth-only vendor review.
ACT agencies operate under territory privacy law, and private health providers can also face the ACT Health Records framework alongside federal obligations.
Public-sector and health-record workflows require an ACT-specific applicability check before selecting message content and providers.
Queensland's Information Privacy Act covers the state public sector, including public-sector health services; private health providers remain within the federal health-provider rules.
The public/private status of the organisation changes the primary privacy regime even when the application and email workflow look identical.
The Information Act provides the territory public-sector privacy framework. Private health providers remain subject to the applicable federal framework.
Confirm whether the customer is a territory agency, contractor, or private provider before mapping the communication path.
Tasmania's personal-information legislation covers its public sector, including public hospitals, while private health providers are covered federally.
Public hospital and private-provider workloads can have different legal owners even when both use the same software supplier.
South Australia uses administrative Information Privacy Principles for state-government agencies rather than a general state privacy statute, with other health and confidentiality rules potentially applying.
Government contracts and agency policy can impose requirements that are not visible from the federal Privacy Act alone.
The Privacy and Responsible Information Sharing Act 2024 introduced a new Western Australian public-sector privacy framework, with core provisions commencing on 1 July 2026.
WA public-sector vendor reviews now need to account for the commenced state framework as well as contractual, health, records, and federal rules that may apply.
The honest boundary
| Review question | Boundry's contribution | Customer responsibility |
|---|---|---|
| Where is the project anchored? | The project region is fixed at creation. Sydney is the only live regional communication plane. | Confirm the selected region matches the workload and document any systems outside that plane. |
| Which communication data is regional? | The regional architecture is designed around messages, recipients, queues, delivery events, suppressions, inbound content, and provider state. | Minimise the fields placed in email and classify links, attachments, templates, and event metadata. |
| What evidence exists today? | Boundry publishes its architecture, current retention status, and known exceptions. The complete production Region Manifest remains work in progress. | Keep the final vendor assessment, contract, data-flow diagram, and legal applicability decision in your own evidence pack. |
| What happens after delivery? | Boundry can define its path up to delivery. The recipient's mailbox provider and the recipient's own handling sit outside that infrastructure boundary. | Keep sensitive content behind an authenticated application boundary and use the email as a minimal notification where appropriate. |
| How long is data retained? | Automated per-data-class retention enforcement is not yet a public product guarantee; the current status is documented explicitly. | Set the required retention outcome by data class and do not claim it until implementation, provider behaviour, and backup expiry are verified. |
Apply the map
Trace patient invitations, results-ready messages, authentication, delivery events, state overlays, and My Health Record boundaries.
Open the healthcare guide →Vendor review
FAQ
No. The Privacy Act creates security and cross-border-disclosure obligations rather than one universal localisation rule. Specific systems, regulated arrangements, customer contracts, government classifications, and organisational policy can create stronger requirements.
No provider can determine compliance for an unknown workload. Boundry can reduce and document the regional messaging path; the customer still owns applicability, data minimisation, lawful use, contracts, access controls, incident response, retention, and the rest of its system.
Do not assume so. Section 77 contains a real Australian boundary for covered participants and information, but location is not the only rule. Boundry does not claim My Health Record registration or automatic authorisation for record data in email.
No. Location may simplify the assessment, but reviewers also need the service scope, information classification, controls, contracts, access paths, subprocessors, incident process, retention, assurance, and known exceptions.
It applies to commercial electronic messages, and that classification depends on content and purpose. A transactional label does not override the Act. The sender remains responsible for consent and unsubscribe obligations where the message is commercial.
Every source on this page was checked on 16 August 2026. Laws, standards, regulator guidance, and Boundry's own implementation can change, so the linked primary source should be checked for a live procurement or legal decision.
Primary sources
Laws, standards, regulator guidance, contracts, and Boundry's own implementation can change. Recheck the primary source for a live procurement or legal decision.
Sydney · ap-southeast-2
Start with one Australian transactional workflow. Classify the data, map the path, and give the reviewer evidence instead of a region slogan.