Your data is in Australia: that doesn't mean it is under your control
By Paul Hadjy, VP of APAC and Cyber Security Services, Bitdefender
Thursday, 20 August, 2026
We spend most of our security conversations on attackers breaking in. But consider the case where nobody breaks in at all, where a foreign government lawfully orders a company to hand over your data, and you never find out it happened.
Let me take you through today’s landscape, the questions to ask and why it matters.
What is digital sovereignty?
Digital sovereignty is your ability to truly control your data, your security operations and your technology decisions.
Most assume the critical part of that is where the data is stored. It’s the easiest question to answer and it rests on a simple, indisputable fact, which is why it’s asked first and is often treated as the whole answer. However, it’s not the whole answer and in fact four harder questions sit behind it.
- Who owns the software running on those servers?
- Who operates that software day to day?
- Which people can reach your data as part of their work?
- Which government can legally force the company that holds your data to hand it over?
These four decide whether you are genuinely in control; the location of the disk does not.
What is sovereignty washing?
Data residency is a geographic fact: it describes where information is physically held. Data sovereignty is a jurisdictional one: it describes who holds the legal authority to govern that information, and it does not follow the map. Sovereignty washing is the gap between the two: a provider presenting residency as though it’s the whole answer, when in reality, three key factors routinely sit inside that gap.
The first is who touches the data in the ordinary course of work: local storage says nothing about where support and operations teams sit. Picture a Sydney-hosted database displaying errors at 11 pm on a Tuesday night, so the engineer who logs in to fix it is in California, or Bangalore or Dublin, because that is where the support desk happens to be at that hour. The moment your records are rendered on that engineer's screen or cached on that terminal, they are being accessed in a foreign jurisdiction and are exposed to that jurisdiction's surveillance and interception laws. The disk never moved, but it didn’t need to.
The second factor is ownership. Sovereignty follows the corporate chain of command, not the coordinates of the server rack. A data centre in Brisbane can be wholly Australian-owned on Monday but after being bought by a foreign private equity firm or multinational company, sit within the subpoena and intelligence powers of another country by Tuesday. While nothing physical changes, and even your contract may not either, your exposure surely does.
The third factor is the law binding the provider’s parent company. The US CLOUD Act lets American law enforcement demand data held by any US-incorporated technology company, wherever in the world that data sits. Australian business data, stored in Australia, on a platform owned by a US company, is still reachable by a US warrant served on the parent. Since January 2024, this arrangement goes both ways, with a bilateral agreement letting authorities in each country serve orders directly on providers in the other, in serious criminal investigations.
Consider a Melbourne accounting firm whose clients’ files sit in an Australian data centre, on software owned by a US company. If a US court orders that company to hand over the files and it complies, copying them from the servers in Australia, the Melbourne-based firm may never be told, because the order was never addressed to it directly.
None of this requires anyone to behave badly. It is simply the systems put in place working as designed, in someone else’s jurisdiction.
The questions worth asking
No jam manufacturer accepts “the warehouse is in Australia” as an answer about where its fruit came from. It asks who grew it, who processed it, who handled it on the way, and under whose safety rules. These are the same questions that should be asked of a digital supply chain.
Four questions separate a sovereignty claim from a sovereignty capability, and I strongly recommend putting all four to anyone handling information that matters.
- Who owns the technology? Not who resells it or whose logo is on the contract, but who holds the intellectual property and sets the roadmap. A straight answer is a company name, whereas an evasive one describes a partnership.
- Who operates it? That is, who operates it day-to-day, in production, with credentials. If the answer involves teams in several countries, that is not disqualifying, but you should know which countries and under whose supervision.
- Who can access the data? This includes support staff, subcontractors and the provider’s own administrators. The honest answer is rarely nobody, but it should be a short, specific list, with the controls that bound it.
- Under which jurisdictions does the provider operate? This is the one most often deflected, because the answer often includes a country the customer had not thought about. Remember, a company incorporated in one place, owned in another and operating from a third is subject to all three.
What the Australian Government requires of itself
When the federal government buys hosting for sensitive government data, it does not simply ask where the servers are. Under the Hosting Certification Framework, the highest tier of certification is open only to providers that allow the government to set conditions on their ownership and control, so a change of hands cannot quietly become a change of jurisdiction.
Every certified provider currently holds that tier, several of which are among the largest technology companies in the world.
The test is not about nationality or postcode, but rather ownership, control, supply chain and transparency, assessed on evidence rather than assertion.
Where this is heading
Private organisations are not bound by the Hosting Certification Framework, but the certified list is public and the thinking behind it is entirely borrowable.
|
Take the four questions into your next contract renewal and ask them about the systems holding the information you would least like to explain the loss of: your cloud and hosting arrangements, your managed IT provider and the platforms running payroll, client records, patient records and finance. Data sovereignty is moving from a compliance question to a procurement one, and from there to a board one. The organisations that handle it well will not be the ones with the best answer about where their servers are; they will be the ones who know who can reach their data, under whose law — and can prove it. If the answer stops at a map, keep asking. |
![]() |
Neoclouds force a rethink of data storage infrastructure
Neocloud providers such as Firmus, OneQode, Sharon AI, CoreWeave, Crusoe, and Nebius are building...
AI's hidden cost: who really owns your enterprise knowledge?
Ultimately, sovereignty should not be viewed as a constraint on innovation, but that which makes...
ASIO’s cyber warning is a test of Australia’s AI resilience
The answer is not to slow innovation or avoid AI, but to embed security, governance and...

