This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
In short: Ask any AI vendor exactly where data is stored, where it's processed (these can differ), whether it's used for model training, and what happens to it if you cancel. Vague or evasive answers to any of these are themselves useful information.
Why this is a narrower question than general vendor due diligence
This guide focuses specifically on data location and sovereignty questions, not the full vendor evaluation. If you want the broader checklist covering security certifications, breach notification clauses, and contract terms as well, see our AI vendor due diligence checklist. This one is deliberately narrow: ten questions specifically about where your data physically goes.
Take a practice manager at a physiotherapy clinic, evaluating a new AI scribe tool for consultation notes. Instead of signing up on the strength of a landing page and finding out later where patient data actually lives, she emails the sales contact the ten questions above before entering any payment details. Two vendors quote Australian data residency in their marketing but cannot confirm it in writing when asked directly. A third answers all ten within a day, with a link to its data processing agreement. That is the vendor she signs with, and it took fifteen minutes of questions to get there instead of a client complaint six months later.
The ten questions
Storage and Processing Location
- Where is the data stored at rest? (Get a specific country or region, not "the cloud")
- Where is the data processed when the AI tool generates a response? (This can be a different location from storage)
- Does the vendor offer any regional choice, or is location fixed?
- If regional choice exists, does it apply to all data, or only some categories?
Training and Retention
- Is your business data used to train the vendor's models, and can you opt out?
- How long is data retained after you stop actively using it?
- What happens to your data if you cancel your subscription entirely?
Sub-Processors and Onward Transfer
- Does the vendor use any third-party sub-processors, and where are they located?
- Can the vendor's stated data location change without notifying you?
- Is there a written commitment (not just marketing language) covering data location that you can point to later?
Why vague answers matter
A vendor that can answer these questions specifically and in writing is telling you something useful about how seriously they treat data handling generally, and our Claude AI review for Australian business is one example of what that looks like in practice. A vendor that responds with general reassurance rather than specifics ('we take security seriously,' 'your data is safe with us') without answering the actual location questions is also telling you something, just not what they intend. Treat evasiveness on location questions as a data point in itself, not a formality to skip past.
Where this fits with your Privacy Act obligations
Australian Privacy Principle 8 (APP 8) covers cross-border disclosure of personal information, which is directly relevant if any of these ten answers reveal your data leaves Australia. Getting clear answers before you buy, rather than discovering the location after a breach or a customer complaint, is the practical difference between a five-minute question and an unplanned compliance review. See our guide to where AI tools store data for the answers already confirmed for major named tools.
What a good answer actually looks like, versus a vague one
Take the storage location question as an example. A good answer names a specific country or region and points you to a written data processing agreement or trust centre page confirming it, for example "data is stored in Sydney and Melbourne availability zones, confirmed in section 4 of our DPA." A vague answer says something like "we use leading cloud infrastructure providers with world-class security," which sounds reassuring but names no actual location and commits to nothing you could point back to later. The same test applies to the training-data question: a good answer states plainly whether your specific plan tier opts you out of training by default or requires an explicit toggle, and tells you where to find that setting. A vague answer talks generally about "responsible AI practices" without confirming whether your business's actual data is or isn't used to train the underlying model.
What to do once you have the answers
Write the answers down, even informally, alongside which tool they relate to and the date you got them. This becomes part of your AI register if you're building one, and it's the reference point if a vendor's practices later change or if a customer or regulator ever asks how your business assessed a tool before adopting it. If any answer reveals your data leaves Australia, that's not automatically a reason to avoid the tool, most useful AI tools involve some overseas processing, but it does mean checking that arrangement against your Privacy Act obligations specifically (APP 8) rather than assuming it's fine because the vendor seems reputable. If a vendor's answers reveal your data is used for model training by default with no opt-out, weigh that specifically against what kind of data you'd actually be putting into the tool, general admin drafting carries different stakes to anything containing customer or patient information.
Methodology (Real-World, Verified)
This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.
Read our full methodology and independence and disclosure policy.
Related reading: our can staff upload customer data to AI tools, our AI and the Privacy Act guide, and our AI data residency in Australia.
Try our free AI Compliance Checker to check whether your AI tools meet your compliance obligations.
Related reading: our AI vendor contracts and Privacy Act.
Related reading: our AI governance by region.
Try our free AI Privacy Risk Scorer to score your current AI tool setup against Privacy Act requirements.
What if a vendor won't answer these questions before I sign up?
Treat that as a real answer. A vendor unwilling to commit to specifics about data location before you've paid is unlikely to become more transparent afterward.
Do I need a lawyer to ask these questions?
No, these are practical questions any business owner or manager can ask directly, usually via the vendor's sales or support contact, before signing up. A lawyer becomes useful once you're negotiating contract terms, which is a separate step covered in our AI contract clauses guide.
Is it reasonable to ask these questions for a free or low-cost AI tool?
Yes, arguably more so, since free tools sometimes monetise through broader data use than paid enterprise tiers. Price point isn't a reliable signal of data handling practices on its own.
Should I ask these questions again if I've already been using an AI tool for a while?
Yes, periodically. Vendors change data handling practices, sub-processors, and default settings over time without necessarily making this obvious to existing customers, so a tool that answered well at signup can quietly drift. Revisiting these questions every six to twelve months, or after any major product update, is a reasonable habit.
Do these questions apply the same way to a free browser-based AI tool as a paid enterprise one?
The questions are identical, but expect the answers to differ meaningfully. Enterprise and business-tier plans more often include contractual data protections and training opt-outs that free consumer tiers don't, so don't assume a free tool's answers will match its paid sibling product.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
<a href="/calculators/ai-privacy-risk-scorer/">AI Privacy Risk Scorer</a> to score your current AI tool setup against Privacy Act requirements
Score Your Setup