Regional regulatory context

Vendor risk and data privacy in Australia

Australia's Privacy Act 1988 and the Australian Privacy Principles (APPs) govern the handling of personal information by APP entities. The Privacy Act is being updated through reforms currently before parliament, including mandatory data breach reporting and enhanced individual rights.

Applicable regulations

  • Privacy Act 1988
  • APPs
  • My Health Records Act
  • SOCI Act

Hosting considerations

AWS (Sydney), GCP (Sydney/Melbourne), and Azure (Australia East/Southeast) offer Australian data residency. Certain health data types under the My Health Records Act may require Australian hosting.

Common questions

Does the Australian Privacy Act apply to overseas vendors?
Yes, if the overseas vendor handles personal information of Australians under a contract with an Australian entity. The Australian entity remains accountable for ensuring its overseas vendors comply with the APPs.

Which of your vendors operate in AU?

TrustVendor tracks vendor hosting regions, subprocessor geographies, and applicable adequacy decisions.

Book a demo