EXPLORE KNOWLEDGE BASE
-
CERI Knowledge Base
-
About the CERI knowledge base
-
Introduction to Australia’s electricity markets
-
Australian consumer insights
-
CER technical and interoperability standards
-
Connecting a customer to an electricity network
-
Connecting a generator to a distribution network
-
Utility interconnection (CSIP-AUS)
-
Dynamic network export and generation control schemes
-
Network load control schemes
-
Network tariffs and network support services
-
Participating in the National Electricity Market
-
Participating in a frequency control market
-
Participating in the RERT
-
Participating in the Wholesale Electricity Market (Western Australia)
-
Participating in the I-NTEM (NT)
-
Cyber security and data privacy arrangements
-
Consumer protection frameworks
-
Data sovereignty and data residency requirements
Last Updated on 4 August 2026
SUGGEST AN EDIT
LIKE THIS PAGE?
The applicable requirements depend on the type of data, the organisations involved and any licence, cybersecurity, procurement or contractual obligations imposed by network businesses and other energy-sector participants.
Under the Privacy Act, the concepts of data residency and data sovereignty are distinct:
- Data residency refers to the physical location where data is stored (e.g., in Australia or overseas).
- Data sovereignty concerns the legal jurisdiction governing access, use, and protection of that data. For example, even if data is stored in Australia, foreign laws may apply if the entity controlling the data is subject to those laws.
Key points
- Data residency concerns where data is physically stored.
- Data sovereignty concerns which legal jurisdiction governs the data.
- DNSPs generally apply stricter requirements than retailers because they operate critical network infrastructure.
- Common controls restrict offshore storage, offshore system access and the use of cloud services without residency assurances.
- Additional requirements may be imposed through licences, procurement processes and contracts.
Obligations for DNSPs and retailers
While national frameworks such as the SOCI Act and the Privacy Act establish baseline requirements for data sovereignty and residency across Australia’s energy sector, state and territory arrangements can introduce additional layers of compliance. Both DNSPs and retailers operate under state-based licences, but the nature of these obligations differs:
- DNSPs: operate critical network infrastructure and therefore face stricter expectations relating to OT/ICT control, data residency, and supply-chain assurance.
- Retailers: have obligations related to consumer protection and privacy but generally do not face the same prescriptive OT-related data-sovereignty requirements. Many will require contractual mandates such as onshore data and hosting; however, this is on a case-by-case basis.
In all jurisdictions, DNSPs apply strong data-governance and sovereignty expectations through a combination of:
- licence obligations
- SOCI Act responsibilities,
- internal cybersecurity policies,
- procurement rules, security assessments,
- contractual clauses and supplier-assurance processes.
These controls commonly restrict:
- offshore storage of operational or security-sensitive data,
- offshore access to operational systems,
- use of cloud services without residency assurances,
- use of vendors who cannot demonstrate robust security governance.
The OAIC website provides a useful overview of state and territory privacy legislation and individual licencing requirements for DNSPs can create further obligations. DNSP cyber and data-handling policies may impose additional requirements on third-party providers interfacing with operational or market-connected systems.
Local requirements for NSW DNSPs
NSW is a commonly cited example where additional data sovereignty and residency requirements can be imposed on third parties at the state level. Licence conditions imposed under the NSW Electricity Supply Act 1995 require local DNSPs to adopt industry best practices, ensure that infrastructure can be accessed, operated and controlled only from within Australia, and that it cannot be connected to or operated by any person outside Australia. Clause 10 requires that information relating to OT and associated ICT infrastructure is held solely within Australia.
DNSPs are responsible for ensuring that relevant infrastructure and service providers comply with these requirements and with broader Australian data sovereignty obligations. This is typically managed through contractual clauses, due diligence processes and regular compliance checks. In some cases, DNSPs specify in their network connection requirements that any device or system connecting to the network must meet their own data residency, sovereignty and privacy standards. Entities commonly affected include community-scale battery operators and CER aggregation platform providers that interface with DNSP operational or network-support systems.
While NSW provides the most explicit legislated example of these obligations, most DNSPs across Australia apply operationally similar expectations driven by national security considerations, SOCI obligations and internal cybersecurity policies. CER providers should therefore expect consistent questions and controls relating to local data storage, restricted offshore access, and secure management of operationally sensitive information when integrating with DNSPs in any jurisdiction.
Related articles