All rules

Australia is the location. The workload decides the rules.

A Sydney region answers where Boundry processes the message. It does not tell you which laws, standards, contracts, state rules, retention duties, and customer policies reach that message. This map does the second part.

Location
Australia · Sydney · ap-southeast-2
Workload
Your entity, data, industry, system, contract, and customer
Answer
Every applicable rule mapped to the real email path

There is no single Australian data-localisation rule.

Most Australian organisations are not subject to a blanket rule that every email or personal record must stay in Australia. Local processing becomes valuable because it can reduce cross-border disclosure, simplify third-party and offshoring reviews, and meet customer policy. Some narrower regimes create explicit Australian boundaries for covered participants and information. Section 77 of the My Health Records Act is the clearest example. The correct answer depends on who you are, what the message contains, and which system or contract it supports.

This is an engineering and vendor-evaluation guide, not legal advice. Confirm the rules that apply to your organisation, contract, and workload.

Three terms that change the answer

Data residency
Where a defined data class is stored or processed. A useful residency claim names the data, location, lifecycle stages, subprocessors, access paths, retention, and exceptions it covers.
Data sovereignty
The legal and governance consequences of the jurisdictions connected to data and its processing. Location matters, but ownership, access, contracts, applicable law, and operational control matter too.
Data localisation
A rule or policy requiring specified data or processing to remain in a place. Australia has narrow, workload-specific examples. It does not have one localisation mandate for every organisation and email.

Start with the entity, the data, and the complete path

  1. 01

    Identify who is regulated.

    Turnover is only one trigger. Health providers, government agencies, APRA-regulated entities, accredited CDR participants, and critical-infrastructure operators can enter different regimes.

  2. 02

    Classify the exact workload.

    A recipient address, appointment context, reset link, CDR field, My Health Record fact, delivery event, and application log can carry different sensitivity and handling consequences.

  3. 03

    Trace processing, not hosting copy.

    Map API ingress, queues, delivery, metadata, webhooks, logs, backups, support access, subprocessors, retention, deletion, and the recipient's mailbox provider.

Every rule that can change the Australian answer

Location is one coordinate. Each framework below changes a different part of the decision. Open the rules that reach your entity and workload, then connect them to the real email path.

Privacy Act 1988 and Australian Privacy Principles

Federal baseline · No blanket localisation

The Act does not say that every Australian workload must be hosted in Australia. An in-country path can reduce the number of overseas disclosures and make the remaining processors, support paths, retention, and contracts easier to assess.

Scope. Australian Government agencies and many private-sector organisations, generally including organisations above the turnover threshold and specifically covered businesses such as private health providers.

Requirement. APP 8 creates duties around disclosure to overseas recipients and can preserve accountability for their handling. APP 11 requires reasonable security and, when information is no longer needed, reasonable destruction or de-identification steps.

How Boundry changes the path. A project is fixed to Sydney and the regional plane is designed to own message content, recipients, queues, events, and provider state. Boundry documents known control-plane and operational exceptions instead of treating a sending-region selector as the whole answer.

Your remaining work. Boundry does not decide whether APP 8 applies to a particular transfer or replace the customer's privacy notices, purpose analysis, contracts, security program, or deletion duties.

Notifiable Data Breaches scheme

Incident response · Security and evidence

The scheme does not mandate Australian hosting. Location, access paths, data sensitivity, encryption, logs, and the identity of processors all affect how quickly a team can contain and assess an incident.

Scope. Entities already covered by Privacy Act security obligations, including Australian Government agencies, many larger organisations, and specifically covered entities such as private health providers.

Requirement. An eligible breach generally involves unauthorised access, disclosure, or loss that is likely to cause serious harm and has not been neutralised by remedial action. Covered entities must assess and, where required, notify affected people and the OAIC.

How Boundry changes the path. Keeping the communication plane and its operational records together in one defined region can make the affected data classes and event trail easier to identify during an assessment.

Your remaining work. Boundry is one service provider in the response chain. The customer still owns its breach-response plan, legal threshold decision, multi-vendor investigation, and notifications.

My Health Records Act 2012 — section 77

Healthcare system · Explicit Australian boundary

This is a genuine localisation rule, but it is narrower than all healthcare data and all healthcare email. Applicability turns on the system, participant, record, and processing role.

Scope. The System Operator and specified registered repository, portal, and contracted service providers that hold records for the My Health Record system or access information relating to those records.

Requirement. Section 77 restricts covered participants from holding or taking relevant records outside Australia and from processing or handling related information outside Australia, subject to the Act's terms and limited exceptions.

How Boundry changes the path. Boundry offers a Sydney regional email plane that can be assessed when a notification workflow must avoid adding an offshore messaging path. Sensitive record content should still be minimised and kept behind an authenticated application boundary.

Your remaining work. Boundry does not claim registration as a My Health Record operator or automatic compliance with the Act. Do not place My Health Record information into email without a specific legal and architecture assessment.

State and territory privacy and health-record laws

Jurisdiction overlay · Scope varies by state

Selecting Australia is only the first layer. The customer's state, sector, public/private status, and the people whose information is handled can change the governing rule set.

Scope. State and territory public-sector agencies under their local regimes. Private health providers in NSW, Victoria, and the ACT can face both federal and local health-privacy requirements.

Requirement. The applicable principles vary across collection, security, use, disclosure, access, retention, and transborder flows. Western Australia's new public-sector privacy framework commenced in July 2026.

How Boundry changes the path. A common Sydney communication plane gives multi-state teams one provider data path to document, while the regional regulation map identifies where local legal analysis still needs to branch.

Your remaining work. One infrastructure region does not harmonise state laws or determine which regulator, health principle, retention period, or public-record rule applies.

CPS 230 Operational Risk Management

Financial services · Stronger offshore governance

CPS 230 is not a blanket data-localisation rule. It does make offshore service delivery, including the physical location of relevant data or personnel, a specific governance and notification consideration when the arrangement is material.

Scope. APRA-regulated banks, insurers, private health insurers, and superannuation entities when managing operational risk and material service-provider arrangements.

Requirement. Regulated entities must identify and manage material arrangements, maintain appropriate agreements and oversight, and notify APRA before entering or materially changing a material offshoring arrangement.

How Boundry changes the path. A defined Australian processing path can reduce ambiguity in the offshoring assessment and give vendor-risk teams a narrower architecture, service location, and subprocessor surface to review.

Your remaining work. Boundry cannot determine materiality, critical-operation impact, APRA notification duties, or whether the customer's wider arrangement remains offshore through other services or personnel.

CPS 234 Information Security

Financial services · Third-party assurance

CPS 234 focuses on control effectiveness rather than a country pin. Residency becomes useful when it reduces an untrusted environment and produces clearer evidence about access, lifecycle, and third parties.

Scope. APRA-regulated entities and the information assets they manage directly or through related parties and third parties.

Requirement. Entities must maintain information-security capability and controls proportionate to threats and asset sensitivity, test control effectiveness, evaluate relevant third-party controls, and notify APRA of material incidents.

How Boundry changes the path. Boundry's architecture and planned Region Manifest are structured around the data classes a third-party review asks about: content, metadata, queues, events, logs, support, subprocessors, retention, and exceptions.

Your remaining work. Boundry is not 'CPS 234 certified'. The regulated entity remains responsible for classifying the asset, evaluating Boundry's controls, testing reliance, and governing the complete service chain.

Consumer Data Right Privacy Safeguards

Consumer data · Restricted overseas disclosure

The CDR framework creates stronger controls around overseas disclosure than a generic preference for local hosting. The full outsourced-service-provider chain and the data placed into a message still need to be assessed.

Scope. Accredited persons, accredited data recipients, data holders, and outsourced service-provider arrangements handling CDR data under the CDR framework.

Requirement. Privacy Safeguard 8 restricts overseas disclosure of CDR data unless an exception applies. CDR outsourcing arrangements also bring specific consent, use, disclosure, security, deletion, and chain-of-provider requirements.

How Boundry changes the path. A Sydney email plane may remove an unnecessary overseas messaging provider from a CDR-adjacent notification workflow and make the remaining outsourcing chain easier to enumerate.

Your remaining work. Boundry does not claim CDR accreditation or that every use of its API forms a compliant CDR outsourcing arrangement. Do not send CDR data until the role, contract, consent, disclosure, and deletion design is reviewed.

Security of Critical Infrastructure Act 2018

Critical infrastructure · Risk and incident governance

The SOCI Act is not a general Australian-hosting mandate. It raises the importance of knowing which providers process business-critical data, where dependencies sit, and how incidents are detected and reported.

Scope. Responsible entities and direct-interest holders for critical infrastructure assets, with additional obligations for specified data-storage and processing arrangements and Systems of National Significance.

Requirement. Relevant entities may need to provide register information, report cyber incidents, maintain a critical-infrastructure risk-management program, and notify data-service providers when they process business-critical data for an asset.

How Boundry changes the path. A discrete regional messaging path helps an operator enumerate the provider, region, message data, and event path for communication workloads connected to a critical operation.

Your remaining work. Boundry does not determine whether an asset or dataset is covered, operate the customer's risk program, or satisfy incident and register obligations for the broader critical-infrastructure system.

Australian Government cloud security assessment framework

Government procurement · Classification and assurance

Australian location can be a procurement requirement or risk treatment, but a Sydney region alone does not make a service suitable for classified or government information.

Scope. Commonwealth entities and suppliers handling government information, according to the relevant entity's classification, risk assessment, procurement, PSPF, ISM, and authorisation requirements.

Requirement. Government cloud consumers assess whether a service is suitable to store, process, and communicate the intended data. The assessment considers classification, architecture, controls, provider access, contractual requirements, and independent assurance such as IRAP where required.

How Boundry changes the path. Boundry can provide an Australian regional architecture and a data-path account that a government supplier can include in its own cloud and vendor assessment.

Your remaining work. Boundry is not IRAP assessed and does not claim Australian Government certification. The customer must obtain the authorisation and assurance required for its information and contract.

Spam Act 2003

Message conduct · Consent and unsubscribe

Residency does not solve Spam Act compliance. Consent evidence, message classification, sender identity, suppression handling, and timely unsubscribe processing are separate operational requirements.

Scope. Senders of commercial electronic messages with an Australian link. Whether a message is commercial depends on its content and purpose, not the name of the email product used to send it.

Requirement. Commercial messages generally require consent, accurate sender identification and contact details, and a functional unsubscribe mechanism. The sender remains responsible when another provider sends on its behalf.

How Boundry changes the path. Boundry provides transactional delivery primitives and regional suppression/event data that can form part of the customer's messaging controls.

Your remaining work. Boundry does not infer consent, decide whether content is commercial, author the required sender information, or operate the customer's complete unsubscribe and marketing-governance process.

One country, several jurisdictional overlays

Public-sector and health rules vary by state and territory. A single Australian region simplifies the provider path; it does not make the underlying regimes identical.

Commonwealth

The Privacy Act and APPs cover Australian Government agencies and many organisations, with specific coverage and exceptions. Sector laws and regulator standards can add to that baseline.

Practical effect. Begin with APP 8, APP 11, NDB, and any sector-specific overlay. Do not convert that baseline into a fictional universal localisation rule.

New South Wales

NSW public-sector privacy laws apply locally, and private health providers can face both the federal Privacy Act and the Health Records and Information Privacy Act.

Practical effect. Health workflows need the federal and NSW health-principle analysis, including security, use, disclosure, retention, and transborder questions.

Victoria

Victorian public-sector information is covered by state privacy law, while the Health Records Act can apply to private health providers alongside federal law.

Practical effect. Treat health information and transborder flows as a distinct local overlay rather than relying on a Commonwealth-only vendor review.

Australian Capital Territory

ACT agencies operate under territory privacy law, and private health providers can also face the ACT Health Records framework alongside federal obligations.

Practical effect. Public-sector and health-record workflows require an ACT-specific applicability check before selecting message content and providers.

Queensland

Queensland's Information Privacy Act covers the state public sector, including public-sector health services; private health providers remain within the federal health-provider rules.

Practical effect. The public/private status of the organisation changes the primary privacy regime even when the application and email workflow look identical.

Northern Territory

The Information Act provides the territory public-sector privacy framework. Private health providers remain subject to the applicable federal framework.

Practical effect. Confirm whether the customer is a territory agency, contractor, or private provider before mapping the communication path.

Tasmania

Tasmania's personal-information legislation covers its public sector, including public hospitals, while private health providers are covered federally.

Practical effect. Public hospital and private-provider workloads can have different legal owners even when both use the same software supplier.

South Australia

South Australia uses administrative Information Privacy Principles for state-government agencies rather than a general state privacy statute, with other health and confidentiality rules potentially applying.

Practical effect. Government contracts and agency policy can impose requirements that are not visible from the federal Privacy Act alone.

Western Australia

The Privacy and Responsible Information Sharing Act 2024 introduced a new Western Australian public-sector privacy framework, with core provisions commencing on 1 July 2026.

Practical effect. WA public-sector vendor reviews now need to account for the commenced state framework as well as contractual, health, records, and federal rules that may apply.

A regional provider narrows the problem. It does not own all of it.

The most credible vendor answer separates the infrastructure contribution from the customer's legal and operational work.

Where is the project anchored?

Boundry. The project region is fixed at creation. Sydney is the only live regional communication plane.

Your team. Confirm the selected region matches the workload and document any systems outside that plane.

Which communication data is regional?

Boundry. The regional architecture is designed around messages, recipients, queues, delivery events, suppressions, inbound content, and provider state.

Your team. Minimise the fields placed in email and classify links, attachments, templates, and event metadata.

What evidence exists today?

Boundry. Boundry publishes its architecture, current retention status, and known exceptions. The complete production Region Manifest remains work in progress.

Your team. Keep the final vendor assessment, contract, data-flow diagram, and legal applicability decision in your own evidence pack.

What happens after delivery?

Boundry. Boundry can define its path up to delivery. The recipient's mailbox provider and the recipient's own handling sit outside that infrastructure boundary.

Your team. Keep sensitive content behind an authenticated application boundary and use the email as a minimal notification where appropriate.

How long is data retained?

Boundry. Automated per-data-class retention enforcement is not yet a public product guarantee; the current status is documented explicitly.

Your team. Set the required retention outcome by data class and do not claim it until implementation, provider behaviour, and backup expiry are verified.

Seven questions before approving an email path

These questions turn a vague residency promise into a reviewable architecture.

  1. 01Which entity, industry, system, contract, and state or territory make this rule applicable?
  2. 02Which data classes enter the email request, message, queue, event, webhook, log, backup, and support path?
  3. 03Does an advertised region govern sending, primary storage, all processing, or only one component?
  4. 04Which overseas recipients or administrators can access personal information, and under what contract and purpose?
  5. 05What retention and deletion outcome applies to live stores, logs, caches, support tools, and backups?
  6. 06Which incident evidence can the provider supply quickly enough for the customer's response obligations?
  7. 07What remains outside the provider boundary after delivery to the recipient's mailbox?

Common questions

What is data sovereignty in Australia?

Data sovereignty describes the legal and governance consequences of the jurisdictions connected to data and its processing. Australian location can reduce offshore exposure, but sovereignty also depends on access, control, contracts, subprocessors, applicable law, and the complete data path.

Does Australian privacy law require all data to stay in Australia?

No. The Privacy Act creates security and cross-border-disclosure obligations rather than one universal localisation rule. Specific systems, regulated arrangements, customer contracts, government classifications, and organisational policy can create stronger requirements.

Which providers offer data residency in Australia?

Do not decide from an Australian hosting or sending claim alone. Ask each provider which content, recipients, metadata, logs, webhooks, backups, support systems, and subprocessors stay in Australia; what leaves; and what the contract actually guarantees. Boundry publishes its current architecture and limitations so that assessment can be made explicitly.

Does using Boundry make an organisation compliant?

No provider can determine compliance for an unknown workload. Boundry can reduce and document the regional messaging path; the customer still owns applicability, data minimisation, lawful use, contracts, access controls, incident response, retention, and the rest of its system.

Can My Health Record information be sent through Boundry?

Do not assume so. Section 77 contains a real Australian boundary for covered participants and information, but location is not the only rule. Boundry does not claim My Health Record registration or automatic authorisation for record data in email.

Is a Sydney sending region enough for APRA or government review?

No. Location may simplify the assessment, but reviewers also need the service scope, information classification, controls, contracts, access paths, subprocessors, incident process, retention, assurance, and known exceptions.

Does the Spam Act apply to transactional email?

It applies to commercial electronic messages, and that classification depends on content and purpose. A transactional label does not override the Act. The sender remains responsible for consent and unsubscribe obligations where the message is commercial.

How current is this map?

Every source on this page was checked on 16 August 2026. Laws, standards, regulator guidance, and Boundry's own implementation can change, so the linked primary source should be checked for a live procurement or legal decision.

Make the decision from the source

This guide is a map. The primary material remains the authority for a live procurement or legal decision.

Privacy Act rights and responsibilitiesOffice of the Australian Information Commissioner · checked 2026-08-16APP 8 — cross-border disclosure of personal informationOffice of the Australian Information Commissioner · checked 2026-08-16APP 11 — security of personal informationOffice of the Australian Information Commissioner · checked 2026-08-16Notifiable Data Breaches schemeOffice of the Australian Information Commissioner · checked 2026-08-16My Health Records Act 2012 — section 77Federal Register of Legislation · checked 2026-08-16State and territory privacy legislationOffice of the Australian Information Commissioner · checked 2026-08-16Privacy and Responsible Information Sharing Act 2024Western Australian Legislation · checked 2026-08-16CPS 230 Operational Risk ManagementAustralian Prudential Regulation Authority · checked 2026-08-16CPS 234 Information SecurityAustralian Prudential Regulation Authority · checked 2026-08-16Privacy Safeguard 8 — overseas disclosure of CDR dataOffice of the Australian Information Commissioner · checked 2026-08-16SOCI Act 2018 for data storage and processingCyber and Infrastructure Security Centre · checked 2026-08-16Australian Government Information Security ManualAustralian Signals Directorate · checked 2026-08-16Cloud assessment and authorisationAustralian Signals Directorate · checked 2026-08-16Avoid sending spamAustralian Communications and Media Authority · checked 2026-08-16Regional architectureBoundry · checked 2026-08-16Retention statusBoundry · checked 2026-08-16

Laws, standards, regulator guidance, contracts, and Boundry's implementation can change. Recheck the primary source for a live procurement or legal decision.

One location. Every rule. One explainable path.

Start with one Australian transactional workflow. Classify the data, map the path, and give the reviewer evidence instead of a region slogan.