An Australian data region answers where some information sits. APP 8 asks a harder question: which overseas recipient can access it, and whether you released its handling from effective control. Map the access path before approving personal information in an AI workflow.
An Australian hosting region is not an APP 8 conclusion. It does not identify who can access prompts and outputs, what a provider may do with them, which subcontractors participate or whether your organisation retains effective control.
The reverse is also true, but only for data in transit. The OAIC says that routing personal information, in transit, through servers located outside Australia would usually be considered a use, and that there would not usually be a disclosure until the information is able to be accessed or modified by the overseas recipient. Overseas storage is a different question, and the OAIC's position is that in most circumstances the provision of personal information to an overseas contractor is a disclosure, and only in limited circumstances a use. The legal analysis turns on the recipient, access and control, not a flag on an architecture diagram.
Build an access-path map for each approved AI use case. This is a proposed internal control from TheAICommand, not a form prescribed by the OAIC. It should make the technical facts visible enough for privacy and legal specialists to decide whether the arrangement is a use, a disclosure, or a collection of different handling events requiring separate treatment.
What does data residency actually prove?
Start with the law that is in force. The Privacy Act 1988 current Compilation No. 104, compiled on 4 June 2026, contains APP 8 and section 16C. APP 8.1 applies before an APP entity discloses personal information about an individual to a person who is not in Australia or an external Territory and is not the entity or the individual. The APP entity must take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles, other than APP 1, in relation to the information.
That is a recipient test. OAIC APP Guidelines Chapter 8, current version 1.3 from 3 October 2025, says an overseas office of the same APP entity is not an overseas recipient for APP 8. An overseas related body corporate is a different entity, so it will be an overseas recipient and APP 8 will apply. Product names and corporate branding do not resolve the legal identity.
Residency evidence can still be useful. Record the locations of processing, primary storage, logs, backups and disaster recovery. Then identify which legal entity operates each layer, where support personnel sit and whether a subprocessor receives the information. This is the same evidence discipline that third-party AI vendor due diligence demands, applied to one use case rather than one supplier.
For an AI assistant, the relevant information is wider than the typed prompt. The OAIC's commercial AI privacy guidance, updated 17 January 2025, says privacy obligations apply to personal information entered into an AI system and to generated output that contains personal information. It tells organisations to consider who will have access to personal information input or generated when using the product, and to review whether terms or settings allow the product owner to collect the data input by customers for further training and development of AI technologies.
Your map should therefore cover prompts, attachments, retrieval results, generated output, user feedback, telemetry, safety logs, support copies and backups where they may contain personal information. A vendor statement that customer content is stored in Australia answers one field. It does not answer the rest.
Use this minimum evidence checklist before anyone assigns an APP 8 status:
- the APP entity and the exact vendor, affiliate and subprocessor legal entities;
- the personal information classes in each input, intermediate record and output;
- processing, storage, backup, support and incident-response locations;
- every actor that can view, retrieve, alter, copy, reuse or delete the information;
- the permitted purposes for service delivery, security, support, analytics and model improvement;
- contract terms, configured settings and technical controls that constrain each purpose;
- retention, deletion, retrieval and exit rights, including downstream copies; and
- the human legal or privacy decision, assumptions, evidence date and review trigger.
Residency evidence and effective-control evidence answer different questions, and only the second one moves the APP 8 analysis:
Is the AI arrangement a use or a disclosure?
The OAIC describes disclosure as making personal information accessible outside the entity and releasing its subsequent handling from the entity's effective control. A use occurs where the entity handles the information within its effective control. That distinction must be applied to the actual arrangement, not inferred from the country of the server.
Where an entity engages a contractor located overseas to perform services on its behalf, in most circumstances the provision of personal information to that contractor is a disclosure, according to OAIC Chapter 8. Limited arrangements may instead be a use where the APP entity does not release subsequent handling from effective control. The OAIC gives overseas cloud storage as an example that may qualify where a binding contract restricts handling to storage and access services, imposes the same obligations on subcontractors and gives the entity effective control.
The factors go beyond a contractual label. The OAIC points to whether the entity retains the right or power to access, change or retrieve the information, who else will be able to access it and for what purposes, what type of security measures will be used for storage and management, and whether the information can be retrieved or permanently deleted by the entity when no longer required or at the end of the contract. A clause saying the vendor acts as a processor is evidence. It is not the whole factual assessment.
Do not over-invest in the label itself. The OAIC says that where it is difficult to tell a use from a disclosure, the practical effect of distinguishing them should not be overstated, and that the best approach is to take reasonable steps to ensure the APPs are complied with. A use is not a lighter obligation: the entity may still be considered to hold the information even though it sits overseas, must comply with the APPs that apply to held information, and will be held accountable for a breach of them.

Generative AI makes that assessment harder because one product can contain several access paths. Core inference may run in an Australian region while overseas engineers receive support access. A search connector may send part of a prompt to another provider; the OAIC's AI guidance notes that some commercial generative AI products have interfaces with search engines or other features that would result in disclosure of personal information entered in prompts to a third party. Abuse monitoring may retain a copy under different terms. Feedback may be eligible for product improvement. Each path can involve a different recipient, purpose and control position. Mapping them also surfaces where several products lean on a common foundation model, and it gives you the recipient list you will need in a hurry if a vendor breach starts your notification clock.
Treat settings as evidence only after testing them. Confirm which tenancy they govern, whether they apply to attachments and connected services, and whether an administrator can enforce them. Capture dated configuration evidence. A sales answer without a contractual or technical anchor is not a stable control.
Where disclosure and APP 8.1 apply, assess reasonable steps before disclosure. The OAIC generally expects an enforceable contract and monitoring. Its sending-personal-information-overseas page, published 13 June 2019, carries an update notice for APP 8.2(aa) and APP 8.3 changes commencing 11 December 2024. Use the current Act and Chapter 8 version 1.3 for exceptions.
Do not describe reasonable steps as a liability transfer. Subject to its statutory conditions and exceptions, section 16C can treat an overseas recipient's relevant act or practice as the APP entity's own breach. The OAIC says this accountability can apply even where the entity took reasonable steps and the recipient later mishandled the information. A human privacy or legal specialist must assess APP 8.2 exceptions and section 16C for the actual disclosure. AI may organise the evidence, but it must not make that legal judgement.
How should the access-path map work?
Create one row for each movement or access event, not one row for the product. Give the row a source node, information class, recipient legal entity, country, access capability, purpose, retention rule, onward path, control evidence and proposed APP treatment. Keep USE, DISCLOSURE, NO PERSONAL INFORMATION and LEGAL REVIEW REQUIRED as candidate labels until the authorised reviewer decides.
Use this prompt to turn approved technical and contractual material into candidate rows. A privacy specialist and technical owner must verify every fact and decide the legal treatment.
Then run an adversarial pass. Look for access that the primary-region narrative obscures: global support, administrator intervention, diagnostic snapshots, content-filtering services, third-party connectors, model-improvement settings, backups and exit-period retention.
Use this prompt to challenge the map. Procurement, security, the product owner and a privacy or legal reviewer must resolve each issue against current evidence.
Fictional worked example: [BANK] proposes an AI assistant for summarising customer-call notes. Its contract specifies Australian primary storage. The access-path map finds that core content processing and storage remain in Australia, but [OVERSEAS_SUPPORT_ENTITY] may receive a diagnostic copy after an administrator opens a support case. It also finds an optional web connector that sends selected prompt text to [SEARCH_PROVIDER].
The map does not pronounce the whole product compliant. It creates separate rows for routine processing, support escalation and connector use. The privacy reviewer assesses the recipients, effective control, APP 6 authority, APP 8 treatment and reasonable steps for each path. The product owner disables the connector pending that decision and changes the support procedure so staff must remove personal information before escalation where feasible.
Attach a review trigger to the map. Reopen it when a subprocessor, region, model, support process, retention term, connector or training setting changes. The OAIC's commercial AI guidance says due diligence for AI products should not amount to a set and forget approach, and that regular reviews of the product's performance, training of staff and monitoring should be conducted throughout the entire AI product lifecycle.
Do this Monday
- Choose one live AI use case. Select a workflow that may handle customer, member, claimant or employee information and identify the accountable product owner.
- Expand the data objects. Add attachments, retrieval content, output, logs, feedback and backups to the existing flow diagram.
- Name the recipients. Replace vendor brands with legal entities, countries, access purposes and subprocessors using current contract and configuration evidence.
- Test the access paths. Verify support access, connectors, retention, deletion and model-improvement settings with procurement, security and the technical owner.
- Record the human assessment. Have privacy or legal specialists decide use versus disclosure, any applicable exception, reasonable steps and section 16C exposure.
- Set change triggers. Require reassessment before enabling a new model, region, subprocessor, connector, support route or reuse setting.
Bottom line
Data residency is evidence about location, not a complete APP 8 assessment. The decisive facts include the overseas recipient, its access and purposes, and whether your organisation retains effective control. Map each access path separately, then let authorised privacy and legal professionals decide the APP treatment and required controls. AI can expose missing facts; it cannot decide that an overseas handling arrangement complies.
This article is general information and education only. It is not legal, compliance, financial or professional advice. Obligations vary by organisation and circumstance. Verify current requirements against the primary sources cited and seek advice specific to your situation.
References
- Federal Register of Legislation, Privacy Act 1988, current Compilation No. 104 (C2026C00227), compilation date 4 June 2026. https://www.legislation.gov.au/C2004A03712/latest
- Office of the Australian Information Commissioner, Chapter 8: APP 8 Cross-border disclosure of personal information, Australian Privacy Principles Guidelines, current version 1.3 from 3 October 2025. https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-8-app-8-cross-border-disclosure-of-personal-information
- Office of the Australian Information Commissioner, Guidance on privacy and the use of commercially available AI products, published 21 October 2024 and updated 17 January 2025. https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products
- Office of the Australian Information Commissioner, Sending personal information overseas, published 13 June 2019 and currently carrying an update notice for APP 8.2(aa) and APP 8.3 changes that commenced 11 December 2024. https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/sending-personal-information-overseas
TheAICommand. Intelligence, At Your Command.


