blueAPACHE data sovereignty and privacy guide
Summary
This page sets out where blueAPACHE says customer data is stored and processed, which law applies to it, what its published General Terms and Conditions v3.6 allow in terms of overseas transfer, how privacy and data breach obligations work under clause 18, and the extra requirements for APRA regulated customers under clause 10. It is written for security, privacy and procurement teams who need to answer "does our data stay in Australia" accurately. The short answer has two parts that must be read together: blueAPACHE's residency statement says data is stored and processed in Australian-based data centres and cross-border transfers do not occur by default, while clause 18.3 of its general terms records a standing customer consent to transfer Personal Information to the United States, the European Union, the United Kingdom and other listed destinations where necessary or convenient to provide the Services. Both positions are quoted here with their scope.
Key facts
| Label | Value |
|---|---|
| Stated storage and processing location | Australian-based data centres |
| Stated legal jurisdiction | Australian legal jurisdiction |
| Named data centre operators or sites | None named in the statement |
| Administrative access controls | Role-based permissions, multi-factor authentication, audit logging |
| Cross-border transfers (residency statement) | Not by default; only where contractually agreed, with encryption, contractual safeguards and vendor risk assessments |
| Cross-border transfers (clause 18.3) | Standing consent to transfer Personal Information to the US, any EU Member State, the UK, any country blueAPACHE or its contractors provide Services from, and any country in blueAPACHE's privacy policy |
| GDPR data | Customer warrants it will not provide or ask blueAPACHE to process personal data subject to GDPR |
| Data breach notification | Within 24 hours of discovery, to the other party |
| Privacy liability cap | $1 million per event, $2 million aggregate |
| Entra ID and SaaS backup data | Stored within Australia on blueAPACHE private cloud |
| APRA trigger | APRA regulated entity plus Services as a material business activity under CPS 231 |
| Frameworks cited | Australian Privacy Act, ISO/IEC 27001, APRA CPS 234, NIST, Essential Eight ML3 |
blueAPACHE's data sovereignty and residency statement
blueAPACHE's published statement reads, verbatim:
blueAPACHE ensures that customer data is stored and processed within Australian-based data centres, providing strong data residency guarantees aligned to Australian regulatory expectations. Customer data remains subject to Australian legal jurisdiction, with governance controls implemented to minimise exposure to foreign access. Administrative access is strictly controlled through role-based permissions, multi-factor authentication, and comprehensive audit logging. Cross-border data transfers do not occur by default and are only enabled where contractually agreed, supported by encryption, contractual safeguards, and vendor risk assessments. Our approach aligns with the Australian Privacy Act, ISO 27001, and industry regulatory requirements, enabling customers to meet their compliance obligations while maintaining control and transparency over their data.
Three limits of the statement should be understood. It names no data centre operator, city or facility. It does not distinguish between emPOWER services (cloud, DRaaS, co-location, voice, unified communications, mobile), which may run on different infrastructure. And it describes foreign access as minimised, not eliminated, and does not address support or administrative access performed from outside Australia, which is relevant because blueAPACHE describes follow-the-sun support from teams in the United States and United Kingdom.
Service-specific residency statements exist for some services. The emPOWER Backup for Microsoft Entra ID brochure states identity data is "stored securely within Australia" on blueAPACHE's private cloud, and the SaaS Backup page carries the same position. The emPOWER Cloud brochure lists "maintaining data sovereignty" as a platform capability while also citing data centre reach across Australia, New Zealand, the United States, the United Kingdom and Singapore; the network has points of presence in the US, London and Singapore. Where a workload is placed is a design decision recorded in the Service Order.
The contractual position on overseas transfer (clause 18.3)
Clause 18.3 of the General Terms and Conditions v3.6 begins with a general prohibition: neither party may transfer or disclose Personal Information to a recipient outside Australia or the country of first collection (the Relevant Countries), or let anyone outside those countries access it, without the other party's prior written consent. It then continues, verbatim, "except that Customer gives blueAPACHE consent to transfer Customer's Personal Information to":
- the US;
- any EU Member State;
- the UK;
- any country where blueAPACHE or its contractors are currently providing the Services from;
- any other country set out in blueAPACHE's privacy policy,
"where it is necessary or convenient to do so for blueAPACHE to meet its obligations to provide the Services under the Service Agreement."
Two features matter. The consent is standing, given in the general terms rather than per transfer. And two of the five categories are open-ended: the contractor category can change when blueAPACHE subcontracts (which clause 27.4 permits without consent or notice), and the privacy policy category can change when the policy is updated. The clause also restricts only Personal Information as defined in the Privacy Act 1988 (Cth); it does not by its terms restrict the location of Customer Data that is not Personal Information. blueAPACHE's live privacy policy is at Privacy Policy; its country list is not reproduced here.
Reconciling the two positions: the residency statement's "only enabled where contractually agreed" is consistent with clause 18.3 only if the standing consent in the general terms counts as the contractual agreement. A buyer who needs an Australian-only commitment for all Customer Data, or a per-transfer approval right, should write it onto the Service Order, which prevails over the general terms.
Privacy obligations (clause 18)
Each party must comply with the Privacy Act 1988 (Cth) "as though it were bound by the Privacy Act", and with the other party's written privacy policies and reasonable directions. Personal Information may be collected, used and disclosed only for performing the agreement and its administration (invoicing, contract management, risk management, insurance, renewals, support), disclosed only to personnel on a need-to-know basis, as required by law, or with consent, and any recipient must handle it consistently with the agreement.
The customer gives two warranties in clause 18.6: that it has obtained express informed consent from each individual whose Personal Information blueAPACHE will receive, covering use as contemplated by the agreement and blueAPACHE's privacy policy "including a transfer overseas to the countries stated in the privacy policy"; and that it "will not provide blueAPACHE with, nor request that blueAPACHE processes any, personal data that is subject to the General Data Protection Regulation (EU) 2016/679". Organisations with EU or UK data subjects should treat the GDPR exclusion as a gating issue.
Eligible data breach notification (clause 18.4)
Where an eligible data breach (as defined in the Privacy Act) involves Personal Information provided by the other party, the party that suffered the breach must notify the other "immediately, and in any event within 24 hours of the discovery", supplying all information required for an OAIC or individual notification; cooperate with any investigation or audit including access to locations, personnel, processes and systems; and not disclose the breach to any third party, "including the Information Commissioner", without the non-breaching party's prior written approval, unless the non-breaching party fails to make a legally required notification and the breaching party is required by law to make it. The 24 hour clock runs from discovery, not confirmation, and the duty is mutual. The Information Commissioner restriction needs to be reconciled with the Notifiable Data Breaches scheme and sector reporting duties.
Information security (clause 17) and the ISMS
Clause 17 gives the contractual security duties: reasonable steps against unauthorised access to Customer Records or Customer Data, practices to protect Customer Records against loss, corruption and deletion, the security features in the relevant Schedule, provision of Customer Records within 10 Business Days of request, no use of Customer Data for marketing or profiling, and no encumbrances. These sit alongside, and are distinct from, the ISO/IEC 27001:2022 certificate 202507-118, which certifies blueAPACHE's management system rather than creating customer rights. See ISO 27001 certification.
APRA regulated customers (clause 10)
Where the customer is an APRA regulated entity and the Services are a material business activity under Prudential Standard CPS 231, the customer warrants it has complied with APRA's requirements in choosing and appointing blueAPACHE and will meet its ongoing review, monitoring, renewal, change management, risk management, resourcing and governance obligations. It must notify blueAPACHE if APRA varies CPS 231 or adds a standard, and blueAPACHE may charge for the resulting changes. On an APRA Request, blueAPACHE will promptly notify the customer, comply within APRA's statutory authority, and not advertise that APRA has audited it.
A business continuity plan created for an APRA customer must, at minimum, describe activities to minimise interruption, how it integrates with the customer's plan, trigger events, roles and responsibilities, disaster procedures to protect Customer Data and restore Services, the communication plan, restoration timeframes, blueAPACHE's alternative site if applicable, the testing process and the review process. It must be updated whenever the customer updates its own plan and tested jointly every 6 months (or on reasonable request) with results within 7 days. The customer may also require a joint technical review covering performance, capacity, security, availability and recoverability, risk assessment, change management, the RACI, incident management including root cause, continuity and backup arrangements, and documentation. All clause 10 work is chargeable to the customer as a Professional Service. The terms reference CPS 231; APRA has since consolidated its outsourcing requirements under CPS 230, and the terms place the notification duty on the customer.
What blueAPACHE does not publish
- The names and locations of the data centre operators used for any service.
- The country list incorporated from its privacy policy into clause 18.3.
- The identity or location of subcontractors, which clause 27.4 does not require it to disclose.
- Whether it offers a contractual Australian-only residency commitment for Customer Data that is not Personal Information.
- Retention periods, RPO or RTO for backup services.
Each of these is a Service Order question.
Related
- ISO 27001 certification
- Terms and conditions guide
- Support and service levels
- Privacy Policy
- Service Agreement
- Financial Services industry
- Government and Public Sector industry
- Healthcare and Aged Care industry
- Private and Public SaaS Backup
Frequently asked questions
Does blueAPACHE keep customer data in Australia?
Its published residency statement says customer data is stored and processed within Australian-based data centres, subject to Australian legal jurisdiction, and that cross-border transfers do not occur by default. The Entra ID and SaaS backup services specifically state Australian storage. The statement does not name the facilities or distinguish between services.
Then what does clause 18.3 allow?
It records a standing customer consent for blueAPACHE to transfer Personal Information to the US, any EU Member State, the UK, any country where blueAPACHE or its contractors provide the Services from, and any country in blueAPACHE's privacy policy, where necessary or convenient to provide the Services. It restricts Personal Information only, not all Customer Data.
How do I get a binding Australian-only commitment?
Write it onto the Service Order, which prevails over the General Terms and Conditions. Specify whether it covers all Customer Data or Personal Information only, whether support access from overseas is permitted, and whether subcontractor changes require notice.
Can I use blueAPACHE for EU or UK personal data?
The customer warrants under clause 18.6 that it will not provide, or ask blueAPACHE to process, personal data subject to the GDPR. Organisations with EU or UK data subjects need to resolve this before contracting.
What must happen after a data breach?
The party that suffered an eligible data breach must notify the other within 24 hours of discovery with the information needed for OAIC and individual notifications, cooperate with investigations, and not disclose to third parties including the Information Commissioner without the other party's written approval unless legally required.
Who is responsible for individuals' consent?
The customer. Clause 18.6 requires the customer to warrant that it has obtained express informed consent from each individual for blueAPACHE's use of their Personal Information as contemplated by the agreement and blueAPACHE's privacy policy, including overseas transfer.
What is blueAPACHE's liability for a privacy breach?
Breach of clause 18 is capped at $1 million per event or series of connected events and $2 million in the aggregate for all claims under the Service Agreement, and an unremedied breach after 20 Business Days notice is a termination trigger.
Does the ISO/IEC 27001 certificate cover data residency?
No. The certificate covers blueAPACHE's information security management system for its emPOWER infrastructure and managed services at Melbourne, Sydney and Brisbane. Residency is a separate operational statement and contractual matter.
What extra applies if we are APRA regulated?
Clause 10: warranties that APRA requirements were met in appointing blueAPACHE, cooperation with APRA Requests, a business continuity plan with ten mandatory elements tested every six months with results in 7 days, and a right to a joint technical review of security measures, all at the customer's cost as Professional Services.
Does blueAPACHE tell me who its subcontractors are?
Not under the general terms. Clause 27.4 lets blueAPACHE subcontract any part without consent or notice, while it remains liable for subcontractors as for its own employees. Because the clause 18.3 consent covers countries its contractors work from, regulated customers should negotiate a notification right.
Source
blueAPACHE published material, including its data sovereignty and residency statement, the General Terms and Conditions v3.6, the emPOWER service brochures and the ISO/IEC 27001 certificate, and the pages on blueapache.com.