ArticlesSeptember 3rd, 2026
Whose data, whose rules? Data sovereignty in Australia


How data became a service issue
Australia's Privacy Act is older than the web. It passed in 1988, when a record meant a folder in a filing cabinet and the worst thing that could happen to it was a flood. It is a fair bet nobody drafting it imagined Medicare, the tax office and your local council all running on the same kind of database, or that most of us would hand over our details every day without a second thought.
Yet here we are. Over the last decade governments moved their records into the cloud, much of it rented from a handful of overseas companies. Banks, telcos and insurers built enormous customer files. We got used to clicking 'I agree'. Then in 2022 Optus and Medibank lost the details of millions of people, and a lot of Australians realised for the first time that they had no idea who held what about them, or where.
Two other conversations had been running for much longer, if more quietly. First Nations communities have argued for years that data about them should be governed by them. A dataset can describe a whole community or a place, so the rules for using it matter well beyond any one person's privacy. And now the AI boom is putting data centres on the edge of our towns, with councils and Traditional Owners asking, reasonably, what they get out of it.
All of this gets called 'data sovereignty'. The trouble is that the phrase is doing three different jobs. Which country's laws protect the data? Who can move it, or switch off the system that holds it? And who decides how data about a community or place is used? If you design or run a service, you answer those questions whether you mean to or not. You decide what a form asks for. You choose the system that stores the answers. You decide what happens when someone wants their information back. This article takes each question in turn.
Jurisdiction: whose laws reach the data
This is the oldest meaning, and the one lawyers reach for first. Data has to follow the laws of the country where it was collected or stored, and that country's government has to be able to enforce them. It is why 'offshore hosting' has made Australian public servants twitch for twenty years. Some countries go further and simply require data about their citizens to stay on home soil. We saw that up close when we mapped critical technology across the Mekong for the Department of Home Affairs. Thailand and Vietnam both require data collected inside the country to stay inside the country.
Here, the draft Privacy Act reforms are rewriting this argument. Organisations will need to show that collecting your data is fair and reasonable. A tick-box you click on the way to something else will no longer count. Bundling a dozen permissions into one 'I agree' is banned. You get a right to have your data deleted, though only from the big platforms. Fines for serious breaches start at $50 million. And when something goes wrong, organisations will have 72 hours to report it.
There are still holes. Small businesses stay exempt. Facial recognition is untouched. And the law binds organisations, not the person filming you on the train with their new glasses. We talked about that gap with Dr Robbie Fordyce in our interview on democracy, disinformation and digital guardrails.
Control: who can switch it off or walk away
The second meaning is newer, and it comes from the people who buy technology for government. Your data can sit in a data centre in western Sydney and still be out of your hands. All it takes is for the only people who can move it, inspect it or shut it down to work for a company based somewhere else. On this reading, sovereignty comes down to one thing: whether you can leave.
Australia has largely decided to rent rather than build. Microsoft's contracts with the Commonwealth have passed $2.5 billion since July 2024. The NDIA pays about $5 million a month to keep its Salesforce system running. That is unlikely to change soon, so the government has started writing the exit clauses instead. Since 1 July, a whole-of-government cloud policy says most federal agencies must design systems so data can be moved out, and must keep a plan for leaving. Quietly, that shifts the question from 'where does our data live?' to 'who holds the keys?' Businesses are asking the same thing. And a local option has appeared. Trellis Data's Agentaus, an AI model hosted in Australia that does not reuse customer data, already has more than a thousand users, and the Department of Finance is looking at it for GovAI.
Authority: who decides how data about a people or a place is used
The third meaning is the one most often missing from procurement conversations, and it has the longest history of the three. Indigenous data sovereignty is the right of First Nations peoples to govern how data about their communities, lands and cultures is collected, owned and used. It answers what researchers call 'data nullius': generations of data gathered about Aboriginal and Torres Strait Islander people, by others and for others.
That history shows up in the Census. The Australian Bureau of Statistics estimates the 2021 Census undercounted First Nations people by 17 per cent. The 2026 Census dropped a planned question on First Nations cultural identity because the consultation was judged to be not good enough.
Authority now reaches the buildings themselves. Earlier this year, Aboriginal groups, environmental campaigners and residents stopped a huge AI data centre planned for Mandoon Bilya in Perth. The site is now set aside for wetland restoration. Researchers writing in The Conversation call data centres 'Australia's next Indigenous policy challenge', and what they are describing is a demand for real decision-making power over what gets built on Country. Meanwhile most government agencies still have no binding protections for Indigenous data. Where new systems are being built, communities want the rules set first. The newborn genetic screening program now being trialled for national rollout is the live example. Across the Tasman, University of Auckland researchers have set out how universities can turn Māori data sovereignty from a statement of intent into everyday practice.
Why the difference matters
Each argument gets settled in a different room. Jurisdiction is settled in parliament. Control is settled in a procurement office. Authority is settled, or left unsettled, out in communities. That makes it easy for an organisation to be strong on one and blind to the others. A department can keep every byte in Australia, hold a watertight exit plan, and still collect data about a community without once asking who has the right to decide how it is used.
People do not experience the three separately. They meet all of them in the same moment, when a service asks them for something. We say sovereignty is settled in law and procurement but felt in design, and we mean it literally. The consent screen. The line that explains why the data is needed. The button that gets it back. The letter that arrives after a breach. That is where the decisions become real for the person on the other side of the counter.
What it means for people who design services
None of this has to wait for the bill to pass. If we were sitting with your team this week, these are the six things we would start on. Each one takes a rule written for lawyers or procurement officers and turns it into something your team can act on: a change to a form, a flow or a process that people will notice.
- Design for the test. Collect less, and say why. When the fair and reasonable test arrives, the reason has to sit right where the data is asked for. Nobody is going to read the policy PDF.
- Make leaving easy. Moving your data out should be part of the service. Show people, and auditors, how it comes back.
- Treat consent as a relationship. Consent gets earned in the moment and checked again later. Data collectives, where people pool their data and negotiate the terms together, show what fair terms can look like.
- Bring the community in early. If a data centre needs a community benefit deal, start with residents and councils before the site plan, and well before the backlash.
- Set Indigenous data rules first. Ask who holds authority over the data. Then design the consent and the information around that answer.
- Rehearse the breach. 72 hours is a service. Try out the notice, the support line and the plain-language explanation before you need them.
Where to start
If you run a department, a utility or a platform, try asking the question in our title of each service you offer. Whose data is it, at the moment we ask for it? Whose rules apply, and could the person in front of us tell? Half an hour spent walking through the moments where your service collects data, explains itself, hands data back or says sorry will usually show which of the three arguments you have been ignoring. If you would like company on that walk, get in touch.
Further reading
- Privacy Act overhaul to tighten 72-hour breach reporting deadline, iTnews, 1 September 2026
- Privacy reform: consultation on exposure draft legislation, Attorney-General's Department. Submissions close 18 September 2026
- Australia is eyeing a world-first 'fair and reasonable' test for data collection and privacy, The Conversation
- Whole-of-government cloud computing policy now in effect, Digital Transformation Agency
- AI sovereignty is the power to leave, The Mandarin, 17 July 2026
- The fight over AI data centres is becoming Australia's next Indigenous policy challenge, The Conversation, 28 August 2026
- First Nations peoples are often undercounted in Australia's census, The Conversation
- Māori research data governance in New Zealand universities, Journal of the Royal Society of New Zealand, 2026
