
Confirm whether contract data is processed “end-to-end” in Australia.
Run practical due diligence on data location, retention, logging, access controls, subprocessors, and whether customer content is used to train models (opt-in/opt-out/default).
Assess cross-border disclosure risk under Australian Privacy Principle 8 (APP 8)
Understand the role of contractual safeguards (security, audit, retention, breach notification).
Understand accountability exposure under section 16C where an overseas recipient mishandles
personal information, and what to do about it.
By Michael Pattison, Lawyer & Founder, ContractProbe
When contract data goes to an AI review tool, "data sovereignty" covers more than where the vendor is headquartered. It covers where the contract is uploaded, where the model actually runs, where prompts and outputs are stored, where logs and backups sit, and where support staff can access your data. For Australian legal, procurement, and commercial teams, three questions decide most of the risk: is data processed exclusively in Australia, where is the supplier (and its subprocessors) actually located, and has the tool been built to recognise Australia-specific statutes..
"Processing" should be read broadly. It includes where the contract is uploaded, where model inference happens, where prompts and outputs are stored (even temporarily), where logs are retained, where backups are held, and where supplier support personnel can access systems. Publicly reported Australian data incidents show that oversight and incident response get harder when key systems, subprocessors, or operational teams sit offshore — so understanding the full data flow, not just the marketing claim of "Australian company," is what actually matters for risk assessment.
Where contracts containing personal information are disclosed to a supplier outside Australia, Australian Privacy Principle 8 (APP 8) generally requires the disclosing organisation to take reasonable steps to ensure the overseas recipient handles that information consistently with the Australian Privacy Principles, unless an exception applies. In practice, APP 8 due diligence covers both the privacy laws that govern the place where the data is processed and the supplier's actual data handling practices — any gaps typically need to be closed through contractual provisions covering security, audit rights, retention, and breach notification.
Section 16C of the Privacy Act adds a further layer: it can make an Australian organisation accountable for misuse or mishandling of personal information by an overseas recipient it disclosed data to. Managing this exposure means doing due diligence on the recipient's practices up front and making sure the contract clearly allocates responsibility and provides enforceable protections.
Even when data is processed in Australia on paper, supplier location and corporate structure can materially affect how well-protected that data actually is. Where a supplier's operations or key subprocessors sit mainly offshore, incident response, time-zone coverage, and crisis prioritisation tend to slow down.
Prompt notification matters because Part IIIC of the Privacy Act requires an Australian company that experiences an eligible data breach to notify affected individuals and the Office of the Australian Information Commissioner (OAIC). If a supplier is holding your contract data, you need to be informed of incidents quickly enough to meet that obligation yourself.
There's also a compelled-disclosure risk to weigh: laws of a foreign country can require an overseas company (directly, or through subsidiaries holding data in Australia) to disclose that information on request from a foreign government. The US CLOUD Act and its enabling legislation in Australia is the most commonly cited example.
Many generative AI tools are trained predominantly on data from outside Australia, which means they may not be well suited to the Australian legal context. Australian organisations operate under statutes that in some cases are unique to Australia, or that treat familiar issues differently — a model that hasn't been trained to recognise these differences is more likely to produce incomplete or incorrect output.
A concrete example: Australian Privacy Principle 11.1 requires an organisation to take reasonable steps to protect personal information from misuse, interference, and loss. When information is disclosed to a third party, that duty can extend to taking steps at the time of disclosure to ensure the third party will treat the information appropriately afterwards. A contract review tool checking a disclosure clause should be able to identify this and recommend measures — stronger security obligations, audit/assurance rights, breach notification, and appropriate indemnities. A tool that isn't attuned to Australian requirements can easily miss this extension of responsibility.
In practice, contracts drafted by overseas suppliers often lack robust language protecting disclosed personal information. A typical gap-filling clause looks like this:
Upon the occurrence of a Security Incident, the Supplier must: (a) promptly notify the Customer of the incident and provide full details on an ongoing basis as they become known; (b) promptly take all actions necessary to minimise the incident's adverse consequences on the Customer; (c) promptly take all actions necessary to prevent reoccurrence of that Security Incident or similar incidents; and (d) provide the Customer with ongoing details of the steps taken under (b) and (c). "Security Incident" means any actual or suspected incident resulting in, or that may result in, misuse, interference, loss, unauthorised access, unauthorised modification, or unauthorised disclosure of data provided by the Customer or generated in the course of providing services, including any incident constituting an eligible data breach under Part IIIC of the Privacy Act 1988 (Cth).
A minimum due diligence pack should cover four areas: data location, processing and retention (including where inference occurs and whether retention can be disabled); access controls and operational security (roles, onshore-only support options, encryption, and certifications such as AS/NZS ISO/IEC 27001, 27002, and 27701); model training and leakage controls (whether customer content trains or fine-tunes models, and what prevents cross-customer leakage); and incident response and breach notification (SLAs, evidence, and support for your own Part IIIC obligations).
Comparing suppliers side by side works best with a weighted scoring matrix — criteria like exclusive Australian processing, no foreign disclosure obligations, an express commitment not to train models on customer data, and independent security assurance should each carry meaningful weight rather than being treated as a single pass/fail checkbox.

Michael Pattison is a Lawyer and the Founder of ContractProbe, an Australian AI-powered contract review platform built for legal and commercial teams.
This article is general information only and does not constitute legal advice. Organisations should obtain advice for their specific circumstances.
Sample supplier due diligence questionnaire.
Example scoring matrix to compare suppliers.
List of contract clauses to request.
Information on why it matters to have AI contract review tools that are trained on the Australian legal context.
Tired of vendor assurances that don’t answer the hard questions? Download the white paper and use the due diligence pack and scoring matrix to compare suppliers before you send them your data.

Download the questionnaire, scoring matrix and clause schedule.