Where Is Your CRM Data Actually Stored? A Guide for Australian and NZ Businesses
Ask most business owners where their customer data is physically stored and you get a shrug. It's in the cloud. Which is true, and tells you nothing — the cloud is a building in a country with laws.
For a lot of businesses this never becomes an issue. For others it becomes an issue at exactly the wrong moment: during a tender, a client security review, an insurance renewal, or a breach.
Why it matters
Your obligations don't transfer with the data
Under the Australian Privacy Act, if you disclose personal information to an overseas recipient, you generally remain accountable for how it's handled. Sending it offshore does not send the responsibility with it. New Zealand's Privacy Act 2020 takes a similar position through its cross-border disclosure rules — you need reasonable grounds to believe the receiving party has comparable safeguards.
In practice this means "our CRM vendor handles that" is not an answer. You are still the one accountable to your customers and to the regulator.
Contracts increasingly require it
Government work, health, education, financial services and a growing share of larger private contracts now ask where data is stored — and some require it to stay onshore. If you can't answer, you don't get shortlisted. This is the most common way the question turns up: not as a legal problem, but as a commercial one.
Other countries' laws reach your data
Data stored with a US-headquartered provider can be subject to US legal process regardless of which data centre it physically sits in. That may be perfectly acceptable for your business — but it should be a decision you made, not one you discovered.
Latency, in a practical sense
Less dramatic but more felt day to day: a system served from the other side of the Pacific is slower than one served from Sydney or Auckland. Across a team using it all day, that's real friction.
How to actually find out
Four steps, none of which need a lawyer:
- Read the sub-processor list. Most vendors publish one. It names every third party that touches your data and, usually, where. It's the most honest document a vendor produces.
- Check whether your plan includes region selection. Data residency is frequently an enterprise-tier feature. Being on a platform that offers Australian hosting doesn't mean your account uses it.
- Ask where backups go. This is the one people miss. Primary data in Sydney and backups replicated to Virginia is offshore storage, whatever the marketing page says.
- Ask about support access. Where is the support team, and can they see customer records? Offshore support with production access is offshore data access, regardless of where the servers are.
What good looks like
Whatever system you use, you should be able to answer these without ringing anyone:
- Which country the primary data sits in
- Which country the backups sit in
- Who can access it, and from where
- Whether access is logged, and how far back
- How long it takes to get a full export if you leave
- How long a restore takes, and when it was last tested
That last one is worth dwelling on. A backup that has never been restored is a hypothesis, not a backup. The time to discover your restore doesn't work is not the morning you need it.
Where a custom build changes the answer
With a custom system, hosting is a decision you make rather than a tier you buy. You pick the region — Sydney, Melbourne or Auckland — and the data stays there. Backups stay in the same region unless you decide otherwise.
Access is defined by roles you set. Every access is logged, so if a client or an auditor asks who viewed a record and when, that's a query and not an investigation.
And because the infrastructure accounts are in your business's name, you're not asking anyone's permission to get at your own data. Export is a database dump you can run yourself.
None of that requires an enterprise plan, because there are no plans.
A reasonable position to take
This isn't an argument that offshore hosting is unacceptable. For many businesses it's fine, and the major platforms run better security operations than most companies could manage themselves.
The argument is that it should be a decision. Know where your data lives, know who can reach it, know what happens if the vendor has an outage or you decide to leave. If the answers are acceptable, carry on. If you can't answer at all, that's the problem — not the location.
If you're going through a security review or a tender that's asking these questions, or you'd like a system where the answers are yours to set, book a discovery call.