Blog

Beyond Data Residency: Understanding Data Sovereignty Risks

Posted by Peter Berekally | Aug 10, 2026 | 0 Comments

For APRA-regulated entities, questions about offshore hosting, cross-border disclosures and technology outsourcing are nothing new.

Privacy obligations, prudential standards and third-party risk frameworks have required organisations to assess these issues for years. Procurement teams review hosting arrangements. Risk teams assess service providers. Legal teams negotiate contractual protections. Boards expect assurance that sensitive information is appropriately protected.

Yet data sovereignty continues to attract attention from regulators, governments, academics and industry practitioners.

That attention is warranted because the technology environment supporting modern organisations has become significantly more complex.

As the Office of the Australian Information Commissioner (OAIC) observed in a 2025 joint statement on AI governance, modern data processing increasingly involves "stakeholders scattered all over the world and complex value chains", creating challenges for organisational control and transparency.

The observation reflects a shift in how organisations are approaching data sovereignty. While data sovereignty is often associated with questions of data location, current policy and academic discussions also focus on the control, governance and dependency relationships that surround data.

For many organisations, determining where data is stored is only part of the analysis.

Attention is now being directed towards providers, affiliates, subcontractors, support functions and legal arrangements that influence how data is accessed, managed and governed.

The Sovereignty Discussion Is Evolving

Data residency remains important, particularly where regulatory, contractual or customer requirements attach significance to location.

However, location alone rarely provides a complete picture.

Modern technology services often involve multinational ownership structures, globally distributed support functions, offshore delivery teams and multiple layers of subcontractors. We frequently note that suppliers seek rights for overseas affiliates to access information, provide support services or perform specialised functions.

These arrangements can often be managed through appropriate contractual, operational and governance controls.

The more difficult task is maintaining effective oversight as service delivery models evolve over time.

Data Sovereignty Is Increasingly a Governance Question

Many sovereignty discussions now centre on visibility.

A useful example emerged in 2026 when ABC News (Australia) reported that highly sensitive Australian court files had been accessed by personnel of an India-based company after work was subcontracted by a transcription services provider. According to the report, the arrangement had not been disclosed to the relevant courts and raised questions regarding subcontracting, offshore access and visibility over the provider's operating model.

Importantly, the discussion was not simply about where the information was located. In responding to the reporting, the provider stated that customer data was stored in Australia. The focus instead shifted to who had access to the information, how the services were being delivered and whether stakeholders had sufficient visibility over those arrangements.

That distinction goes to the heart of the modern data sovereignty discussion.

For many organisations, confirming that data is located in Australia is a familiar and well-established governance exercise. The more difficult task can be understanding who can access that data, what entities participate in service delivery, how those arrangements are governed and whether the operating model has changed since the arrangement was first approved.

The example demonstrates how governance questions can arise even where the location of data is known. For boards, general counsel, procurement leaders and risk officers, these are questions of assurance, oversight and control.

When Geography Stops Being the Only Question

Another commonly cited example concerns the interaction between data location and legal jurisdiction.

The U.S. CLOUD Act provides that certain service providers may be required to disclose data within their possession, custody or control regardless of where that data is physically stored.

Data location therefore does not always resolve questions of legal authority or control.

Once the location of information has been established, organisations may still need to consider matters such as legal jurisdiction, corporate structure, operational dependencies and decision-making authority.

Knowing where information is stored may answer one question. Understanding who may influence, access or exercise authority in relation to that information can raise several others.

The Connection to Operational Resilience

For APRA-regulated entities, these issues align closely with operational resilience and service provider risk.

APRA's CPS 230 requires regulated entities to manage operational risks, maintain critical operations through disruptions and manage risks arising from service providers. CPS 234 similarly requires entities to maintain information security capability having regard to relevant threats and vulnerabilities, including those arising through third-party arrangements.

Viewed through that lens, data sovereignty extends beyond privacy considerations. It sits at the intersection of privacy, cyber security, procurement, outsourcing, operational resilience and governance.

Organisations ought to ask themselves:

  • Do we understand the service chain supporting critical functions?
  • Do we know who can access sensitive information?
  • Do we understand subcontracting and offshore support arrangements?
  • Can we identify significant changes to a supplier's operating model?
  • Are we receiving assurance about the broader service delivery model, or only the primary supplier?

These are the types of questions sovereign data governance seeks to address.

Looking Beyond Where Data is Stored

Data residency remains important. Organisations should continue to understand where information is stored and processed.

Location, however, is only one component of data sovereignty.

A fuller assessment also considers the legal, operational, contractual and technological relationships that affect how information is accessed, governed and controlled.

That broader perspective is shaping the next phase of the data sovereignty conversation.

Why This Matters in Practice

At MM Legal+, we regularly see and help our customers through these issues as they emerge during technology procurements, cloud migrations and contract negotiations.

A supplier may seek rights for overseas affiliates to access information. A support model may involve offshore personnel. A service may depend on downstream providers that are not immediately visible to the customer.

Each of these scenarios requires organisations to look beyond data location and consider the governance implications of how services are delivered and controlled.

These discussions are now common in technology, outsourcing and SaaS negotiations.

As cloud, SaaS and AI services continue to evolve, organisations that understand and actively govern those relationships will be better placed to manage privacy, operational resilience and third-party risk.

Need assistance reviewing technology, outsourcing or SaaS arrangementsContact MM Legal+ to discuss how we can help. 

About the Author

Peter Berekally
Peter Berekally

Peter is an experienced commercial lawyer with over a decade of legal experience advising on a wide range of business, legal and regulatory matters. His legal career has been built on a foundation of deep commercial insight and stakeholder-focused problem solving. Peter regularly advises on a broad variety of commercial matters including drafting, negotiating, and advising on IT, professional services, and personnel contracts, as well as advising on regulatory compliance matters (including APRA CPS230/234 compliance, and compliance with Australian Privacy Principles).

Comments

There are no comments for this post. Be the first and Add your Comment below.

Leave a Comment

A reputation built on practical support.

MM Legal+ is trusted by organisations that need reliable, in‑house style legal support. We work alongside internal legal, risk and compliance teams to provide overflow capacity, specialist expertise and clear advice — helping teams perform at their best when it matters most.

Menu