New privacy laws and the Cloud

Summary

This post explains the Australian privacy law changes that took effect on 12 March 2014 and what they mean for organisations using offshore cloud or data centre providers. It is written for IT and compliance decision-makers weighing where to host business data under the Australian Privacy Principles (APPs), particularly APP 8 on cross-border disclosure. Published in 2014, the post reflects the law as it stood at that time; for current guidance on data residency and privacy obligations, see the linked service pages. The underlying issue it raises, that an organisation stays accountable for personal information it discloses to an overseas cloud or hosting provider, has not gone away: the Australian Privacy Principles are still the operative framework for Australian entities in 2026, and cross-border data-handling questions remain a standard part of any cloud sourcing decision.

Key facts

Label Value
Publication year 2014
Topic Australian Privacy Principles and offshore disclosure of personal information
Regulator named Office of the Australian Information Commissioner (OAIC)
Penalty cited (2014 legislation) Up to $340,000 for individuals and up to $1.7 million for companies for a serious privacy breach
Services referenced emPOWER Cloud, governance and compliance advisory
Data residency claim blueAPACHE states emPOWER Cloud is hosted entirely in Australia, with no data stored, replicated or backed up overseas

Article

On March 12, 2014, new privacy laws in Australia made it compulsory to notify new and existing customers about the data you collect and what you do with it. The new data privacy laws introduces harsh financial penalties for individuals and companies found guilty of serious information breaches. Under the new legislation, the Australian Privacy Commissioner can seek civil penalties of up to $340,000 for individuals and up to $1.7 million for companies in the case of a serious privacy breach. Australian organisations should already have their houses in order by building privacy and data protection in the design specifications and architectures of their IT systems to facilitate compliance. They should also be aware of Australian Privacy Principal 8, which requires an entity – before they ‘disclose’ information to an overseas recipient such as an offshore data centre or cloud providers – is required take reasonable steps to ensure the receiver does not breach the new rules. The challenge with overseas data centres or cloud providers (or local companies that aggregate or resell overseas cloud products) will be ensuring contracts are robust enough to ensure the data is going to be handled in accordance with Australian Privacy Principles. The Office of the Australian Information Commissioner (OAIC) suggests that a ‘disclosure’ occurs when information is released from an entity’s effective control. Providers that store, replicate or back up data to overseas data centres (including Google and Amazon) are potentially breaching this. Further compounding the negativity around overseas providers is their own obligation to meet their local laws. Any data stored in the US for example, is subject to US privacy laws and the Patriot Act; meaning US agencies can potentially access to the data. We are yet to see the ramifications this has Australian businesses and their new data obligations. blueAPACHE’s emPOWER Cloud is entirely located in Australia. No data is stored, replicated or backed up overseas. For current guidance, see the Australian Privacy Principles guidelines (current OAIC guidance). This link provides current guidance rather than the original historical announcement. To better understand your data privacy compliance requirements or to learn more about blueAPACHE’s emPOWER Cloud, contact our Account Management team.

Related

Frequently asked questions

Why does it matter where a cloud provider stores personal information?

Under the Australian Privacy Principles, an organisation remains responsible for personal information even after it hands that information to a third party such as a cloud or data centre provider. APP 8 specifically covers cross-border disclosure, requiring reasonable steps to ensure an overseas recipient does not breach the Australian Privacy Principles before information is sent offshore. That obligation does not disappear because the infrastructure is owned and operated by someone else.

What counts as a 'disclosure' of data to an overseas recipient?

The post cites OAIC guidance that a disclosure occurs when information is released from an entity's effective control, which can include a provider that stores, replicates or backs up data to an offshore data centre. That definition captures common cloud architectures, including services that mirror data to overseas regions for redundancy, even where the customer never explicitly authorised an overseas transfer.

What penalties applied under the 2014 Australian privacy law changes?

The post states that under the legislation in force from March 2014, the Australian Privacy Commissioner could seek civil penalties of up to $340,000 for individuals and up to $1.7 million for companies found guilty of a serious information breach. These figures reflect the law as it stood in 2014; current penalty settings should be confirmed against the Privacy Act 1988 (Cth) as amended.

Why is offshore hosting treated as a compliance risk?

Data held in another country is generally subject to that country's own laws. The post gives the example of the United States, where data stored locally can potentially be accessed under US law, including the Patriot Act, regardless of the Australian entity's own privacy obligations. That layering of foreign legal access on top of Australian privacy duties is the core risk the post is warning about.

Where does blueAPACHE host emPOWER Cloud data?

blueAPACHE states that emPOWER Cloud is located entirely in Australia, with no data stored, replicated or backed up overseas. That is a data-residency claim made in blueAPACHE's own cloud brochure rather than a specific privacy-law compliance certification, so it should be read as one input into a broader compliance assessment, not a substitute for it.

Does keeping data onshore automatically make an organisation compliant?

No. The post's underlying argument is that organisations need privacy and data protection built into system design and architecture from the outset, not just a choice of hosting location. Data residency reduces one category of risk, cross-border disclosure, but obligations such as notification, access controls and data handling practices still apply regardless of where infrastructure sits.

What should a business check in a cloud or hosting contract regarding overseas providers?

The post argues that the real challenge is ensuring contracts with overseas providers, or local resellers of overseas cloud products, are robust enough to guarantee data will be handled in line with the Australian Privacy Principles. That means checking for explicit data-location commitments, sub-processor disclosure and contractual flow-down of privacy obligations rather than assuming compliance from a vendor's general reputation.

Has anything changed in Australian privacy regulation since this post was published?

Yes. Since 2014, Australia introduced the Notifiable Data Breaches scheme under the Privacy Amendment (Notifiable Data Breaches) Act 2017, which took effect in February 2018 and created a standalone obligation to notify affected individuals and the OAIC of eligible data breaches. Readers relying on this 2014 post for current compliance obligations should treat it as background context and confirm today's requirements separately.

Source

https://www.blueapache.com/blog/new-privacy-laws-and-the-cloud-2/

Knowledge Base

When did the new privacy laws in Australia mentioned in this blueAPACHE article take effect?

The new privacy laws in Australia took effect on March 12, 2014, making it compulsory to notify new and existing customers about the data collected and what is done with it.

What financial penalties can the Australian Privacy Commissioner seek for serious privacy breaches under the new legislation?

Under the new legislation, the Australian Privacy Commissioner can seek civil penalties of up to $340,000 for individuals and up to $1.7 million for companies in the case of a serious privacy breach.

What does Australian Privacy Principle 8 require of entities regarding overseas data recipients?

Australian Privacy Principle 8 requires an entity, before it 'discloses' information to an overseas recipient such as an offshore data centre or cloud provider, to take reasonable steps to ensure the receiver does not breach the new rules.

According to the Office of the Australian Information Commissioner (OAIC), when does a 'disclosure' of information occur?

The OAIC suggests that a 'disclosure' occurs when information is released from an entity's effective control. Providers that store, replicate, or back up data to overseas data centres (including Google and Amazon) are potentially breaching this.

What risk does the article highlight about storing data with overseas providers, such as those in the US?

The article notes that overseas providers have their own obligation to meet local laws — for example, data stored in the US is subject to US privacy laws and the Patriot Act, meaning US agencies can potentially access the data, and the ramifications of this for Australian businesses and their new data obligations were not yet known at the time.

How does blueAPACHE's emPOWER Cloud address the data sovereignty concerns raised in the article?

blueAPACHE's emPOWER Cloud is entirely located in Australia, and no data is stored, replicated, or backed up overseas.

Where can readers learn more about the new Australian privacy laws mentioned in the article?

The article directs readers to the OAIC (Office of the Australian Information Commissioner) site to learn more about the new privacy laws.

Who should be contacted to learn more about blueAPACHE's emPOWER Cloud or data privacy compliance requirements?

Readers are advised to contact blueAPACHE's Account Management team to better understand their data privacy compliance requirements or to learn more about emPOWER Cloud.

Who wrote the 'New privacy laws and the Cloud' article and when was it published?

The article was written by blueAPACHE and published on October 2, 2014.

Images on This Page