| Data sovereignty is the question of whose law can compel your business data to be produced. The answer follows the country your provider is incorporated in, so a New Zealand data centre owned by an overseas company does not settle it, and data residency is the separate and narrower question of where the files physically sit. |
A Christchurch firm won a place on a corporate supplier panel in March and lost it in June.
The customer sent a two-page schedule with the renewal paperwork. It asked which countries the firm stored data in, which companies could reach that data, and what would happen if one of them were served with a legal order.
The firm answered from memory, because that was quicker than finding out. Three of the answers were wrong.
The one that cost the panel place was a document system everybody had assumed was in Auckland. It had been storing files in Oregon since the week it was bought.
Nobody had lied. Nobody had checked either, because until that schedule arrived there had been no reason to.
None of that was new. It had been costing the firm money for two years, and the schedule was the first time anyone had to put a figure on it.
The figures below are illustrative. Take a 28-person professional services business in Christchurch running Microsoft 365, a practice management system, an accounting package, a document store and an outsourced payroll service.
Its operations manager spends around five hours a month on questions about where information is held and who can reach it, spread across tenders and insurance renewals. At $70 an hour across the year, that is $4,200.
The same firm pays $420 a month for a second document system it bought two years ago, because nobody could confirm what the first one did with New Zealand files. That is $5,040 a year, and $9,240 once the two are added together.
The panel schedule cost more and cost it once. A lawyer and a consultant spent a fortnight answering it properly, and the invoice came to $6,800.
Neither number is a judgement about where servers ought to live. That is an architecture question, and our guide to hybrid cloud covers it. The wider set of privacy duties, all thirteen principles of them, belongs to our guide to Privacy Act compliance.
An owner can answer two questions without any help. Which countries hold your information, and who can be ordered to hand it over.
Why Does Data Sovereignty Matter for a New Zealand Business?
It matters because the law reaching your data is not always New Zealand law, and your customers, your insurer and your regulator have all started asking which one does.
For most owners the subject arrives as paperwork. A procurement schedule wants a list of countries. An insurance renewal asks whether customer information is held offshore, and a customer asks for their file back and wants to know who else has held a copy.
None of those is a technical question. Each one is answered from a contract, a company register and a settings page.
What is the difference between data sovereignty and data residency?
Data residency describes the physical location of stored information, usually a named region such as Australia East or New Zealand North. Data sovereignty describes the legal authority over that same information, and it follows the ownership of the company holding it. A file can sit on a disk in Auckland and still be reachable by a foreign court, if the company operating that disk is owned overseas and can be ordered to produce what it controls.
The United States has a law on this point, the Clarifying Lawful Overseas Use of Data Act, which the industry shortens to the CLOUD Act. It governs when American authorities can require an American provider to hand over data held abroad, and several other countries have their own versions.
If your provider answers to a foreign government, so does your data.
Vendors volunteer the residency answer without being asked, because it is easy and it sounds reassuring. Ask the ownership question separately, since a procurement team will be checking that one.

Is this the same as Māori data sovereignty?
No. Māori data sovereignty, or mana raraunga, concerns the rights and interests Māori hold in the collection, ownership and use of Māori data, wherever that data happens to be stored.
Te Mana Raraunga and Te Kāhui Raraunga are the networks that set those rights out, and the government treats them as a consideration alongside jurisdictional risk and not as the same question.
This post covers the commercial question only. Whose law can compel a business file, and what an owner does about it.
Who asks a New Zealand business this question?
Corporate customers, government agencies buying services, insurers at renewal, and individual customers using their privacy rights.
The wording changes with the sender and the request underneath stays the same. Name the countries and the companies, then say what happens when one of them receives an order.
A procurement team scores the answer and files it. A customer with a group policy compares it against a rule written in another country, and a weak answer can lose a renewal without anyone telling you why.
Write the answer down once and keep it with the contracts. The person asked next time may not be the person who worked it out.
What Does the Privacy Act 2020 Say About Sending Data Overseas?
It says the responsibility stays with you. Section 4 of the Privacy Act 2020, which replaced the Privacy Act 1993, applies the Act to a New Zealand business in respect of the personal information it collects or holds, and states plainly that the location of that information makes no difference.
The Act uses the word agency for a business. A business based offshore is an overseas agency, and it is caught as well if it carries on business in New Zealand, whether or not it has an office here. That is why a software vendor in Sydney with New Zealand customers can be complained about to the New Zealand Privacy Commissioner.
So the obligation does not move when the data does. A customer whose information is mishandled on a server in Singapore still complains here, to the Privacy Commissioner, under this Act.
The Act does have a rule aimed squarely at cross-border disclosure. It is information privacy principle 12, written throughout the industry as IPP 12, and it is narrower than most people assume.
Does IPP 12 apply to a cloud provider?
Usually not. Information privacy principle 12 governs disclosure of personal information to a foreign person or entity, and it asks you to believe on reasonable grounds that the recipient will protect the information with safeguards comparable to the New Zealand Act.
Putting files into a cloud service is usually not that kind of disclosure. Section 11 of the same Act treats information one agency holds for another, for safe custody or processing, as held by the second one, and it says outright that it makes no difference whether the holder is outside New Zealand.
Handing your files to an offshore data centre does not hand the privacy obligation to the provider. It stays with your business, and a residency sales pitch tends to imply the reverse.
When customer information leaks out of a system you rent, the letter comes to your door and not the vendor’s.
When does a cloud service become a disclosure under IPP 12?
When the provider uses the information for its own purposes. Section 11 then treats the information as held by both of you, and the transfer becomes a disclosure that IPP 12 governs.
Three arrangements cross that line. A marketing platform that profiles your customers for its own model, an offshore bookkeeping service working your ledger, or an overseas parent company reporting on your client list.
IPP 12 offers several ways through. The recipient can be subject to comparable privacy laws, or based in a prescribed country named in regulations, or a member of a prescribed binding scheme, or bound by an agreement that sets out the safeguards.
The Privacy Commissioner publishes model contract clauses for the last of those and they cost nothing to use. Attach them to the supplier agreement before signing, because the same clause asked for a year later turns into a negotiation.
Which of Your Business Systems Store Data Outside New Zealand?
More of them than an owner expects. A business of twenty to thirty people commonly runs between ten and twenty systems holding customer or staff information, and in our experience most of those store it in Australia, Singapore or the United States.
The list has to be written down system by system, and nobody can do it from memory. The firm on the supplier panel tried.
The exercise takes an afternoon. For every system, write down three things: the country it stores data in, the company that sells the service, and the country that company is incorporated in.
Start the list with these:
- Email and files, usually Microsoft 365 or Google Workspace
- The accounting package, and anything plugged into it
- Payroll, which holds bank account numbers and IRD numbers
- The customer, practice or job management system
- Backup, which often lands in a different country from the thing it backs up
- The phone system, and any call recordings it keeps
- The website, its host and every form on it
- Anything a staff member signed up for on a company card
That last line finds more than the rest of the list combined. Subscriptions bought outside the IT budget bring their own storage location and their own terms, and our guide to software as a service sets out the trade-offs that come with them.
Keep the finished list somewhere a non-technical manager can open it. A register only the IT person understands gets rebuilt from scratch the next time a schedule arrives, and that rebuilding is most of the $4,200 above.

How do you find out where a system stores your data?
Read the vendor documentation first, then ask the vendor in writing for anything the documentation does not answer.
Large providers publish this properly. Microsoft’s data location documentation names New Zealand among the local region geographies where Microsoft 365 customer data can be stored, and lists a set of extra commitments it calls Advanced Data Residency for tenants in those geographies.
Smaller vendors often cannot answer quickly. Give them ten working days and a written question, and treat a vague answer the same way as no answer.
What about backups, logs and support access?
All three routinely end up in a country nobody chose.
A backup of a New Zealand file server can land in Sydney. Application logs carrying customer names can be held in the United States for two weeks before they roll off. A support engineer in another time zone can hold standing access to your tenant.
Put the same questions to the backup as to the system it protects. What Microsoft keeps for you and what it does not is a related question, and our guide to backing up Microsoft 365 sets out where that line falls.
| System | Where it commonly stores data | Who can be required to produce it |
|---|---|---|
| Microsoft 365 email and files | New Zealand or Australia, depending on the tenant geography | Microsoft, a company incorporated in the United States |
| Accounting software | Australia, for most products sold into New Zealand | The vendor, and any offshore parent above it |
| Payroll | New Zealand, for locally built products | The payroll provider and any bureau it subcontracts |
| Cloud backup | Frequently a different country from the system it protects | The backup vendor and its storage subprocessor |
| Website and its forms | Wherever the host runs, often Australia or the United States | The host, and whoever holds the hosting account |
| Phone system call recordings | With the platform, and frequently offshore | The platform operator |
Does Storing Data in New Zealand Make It Sovereign?
No. A New Zealand address settles where the files are and nothing about who can be ordered to produce them, because the company operating the local equipment may still answer to a foreign court.
Microsoft lists New Zealand among its local region geographies, and Microsoft is a United States company. Building capacity in New Zealand does not change where a provider is incorporated.
The government says the same thing in its own advice. The Cloud Jurisdictional Risk guidance published by the Government Chief Digital Officer warns that jurisdictional risks are still present in onshore data centres where the products and services are owned by offshore vendors.
A New Zealand owned provider has no offshore parent for a foreign court to order. New Zealand law is then the only law that reaches the file.
Very few businesses move everything. Put the handful of systems holding the sensitive material onto New Zealand infrastructure, leave the rest where it runs well, and write down the reason for the line you drew.
What is a New Zealand data centre worth?
Data residency New Zealand buys lower latency and an end to one argument that keeps coming back. Plenty of corporate customers keep a written policy on offshore data storage and have no appetite to debate it, and being able to point at a local region ends the debate without changing how anyone works.
Providers running data centres here can also hold Public Cloud Data Centre Certification from the Government Chief Digital Officer. Ask about it if you sell to agencies, because their own rules turn on it.
Price the move before making it. Migrating a file store to satisfy one clause in one contract can cost more than the contract earns.
What Should You Ask a Cloud Provider About Data Sovereignty?
Ask five questions in writing and keep the answers filed with the contract:
- In which country is our data stored, and does that cover backups and logs?
- Which company sells this service, and where is that company incorporated?
- Which other companies process our data, and in which countries do they operate?
- When a foreign authority demands a customer file, who reviews the demand, do you disclose only what the warrant requires, and will you tell us?
- On the day we leave, what do we get back, in what format, and do you delete what remains?
None of those questions is invented. They follow the tests the Government Chief Digital Officer sets for agencies buying cloud services, so a supplier that sells into government will already have the answers written down.
The fourth question is the one vendors answer badly. A provider with a written process describes it in a paragraph. A provider without one says it has never come up.
Microsoft publishes a position on it, promising no back doors and no direct or unfettered government access to customer data. A small vendor may have no position at all. Find that out before your customer list goes into their system.
What should end up in the contract?
A named country for storage, a duty to notify you if an authority asks for your data, and an exit clause with a format and a deadline in it.
Add them before signing. Every one of them becomes a renegotiation once the contract is live.
When Does Business Data Have to Stay in New Zealand?
Rarely because a statute says so, and often because a contract does. A customer normally raises it long before a regulator would. No general New Zealand law requires ordinary business data to be stored onshore.
The Privacy Act sets conditions on disclosure and says nothing about geography.
The pressure comes from somewhere else:
- Government agencies applying their own procurement and hosting rules to suppliers
- Health sector agreements covering patient information
- Financial services licence conditions covering outsourced systems
- Corporate customers applying a group policy written in another country
Once any of those is signed, it works on your business exactly as a law would. The obligation also flows downhill, so a subcontractor to a government supplier can inherit a hosting rule it never negotiated.
Read the schedule before the tender goes in. Answering one of these from nothing, under deadline, is what produced the $6,800 invoice above.
How Much Does Data Sovereignty Cost to Get Right?
For the illustrative 28-person firm above, about $4,800 a year, set against the $9,240 a year it currently spends on not knowing. The net is around $4,440 a year of recurring saving, and no lost panel place has been counted in that.
The recurring side buys a maintained register of every system and its owner, plus the contract clauses that go with it. A short review each quarter keeps the register true as software changes underneath it.
The one-off side is a separate number and should stay separate. Building the first register, chasing the answers out of every vendor and retiring the duplicate document system runs around $3,900 for a firm this size, against the $6,800 that panel schedule cost when the firm had nothing written down.
Both figures move with the number of systems, and barely at all with the number of staff. A ten-person business with fifteen subscriptions has more work in front of it than a fifty-person business with six.
What does this look like for a five-person business?
Smaller, and worth half a day of somebody’s time.
A five-person business still runs eight or nine services holding customer information, and it still gets asked by its largest customer. The register is a spreadsheet and the contracts are the vendors’ standard terms. A firm that size should still be able to answer its customer inside a day.
Where Should a Business Start With Data Sovereignty?
Start with the list, because nothing else can be decided until you know what you have. Every New Zealand business can then work through six steps in order:
- List every system holding customer or staff information, including the ones bought on a card.
- For each one, record the country it stores data in and the country its owner is incorporated in.
- Mark the systems holding information you would not want produced under a foreign order.
- Put the five questions above to the vendors behind the marked systems, in writing.
- Move what belongs onshore, and write down the reason the rest stays where it is.
- Date the register, and review it whenever a system is added or replaced.
None of that needs new software. Most of it is asking suppliers for answers they should already have written down.
The firm at the top of this post held all of it the whole time. The answers were spread across five contracts nobody had read since the day they were signed.
Can You Say Where Your Customer Data Sits Today?
Exodesk has supported South Island businesses since 1989 and works with clients across Canterbury, Otago and Southland from offices in Christchurch and Dunedin. Our cloud team builds the register with you and names the owner behind every system you run, then moves what should be held in New Zealand.
Contact us today to discuss how we can help your business or connect with us on LinkedIn to stay updated with more insights.
Frequently Asked Questions
What is data sovereignty?
Data sovereignty describes which country’s courts and authorities hold legal power over information a business keeps. It turns on the corporate ownership of the service holding the file, so an overseas-owned provider can be ordered to produce records it keeps on a disk in Auckland. New Zealand businesses meet the term most often in customer contracts and insurance questionnaires. The residency question, meaning where the file physically lives, is a different and much easier one to answer.
Does the Privacy Act 2020 apply if my business data is stored overseas?
Yes. The Act attaches to the business itself, so a New Zealand company remains answerable for personal information no matter which country holds it. Storing a customer list offshore changes nothing about your obligations to the people on that list.
What is information privacy principle 12?
Information privacy principle 12, usually shortened to IPP 12, is the rule in the Privacy Act 2020 covering disclosure of personal information to a person or entity outside New Zealand. It permits the disclosure where the recipient is subject to comparable privacy laws, is based in a prescribed country, or belongs to a prescribed binding scheme. An agreement setting out comparable safeguards also satisfies it. Otherwise the individual has to authorise the disclosure, after being told their information may not be protected to the same standard.
Do I need a contract with my cloud provider to comply with IPP 12?
In most cases no, because storing files with a provider for safe custody or processing is not treated as a disclosure at all. The Privacy Act treats that information as still held by your own business. A contract becomes necessary when the provider uses your customers’ information for its own purposes. The Privacy Commissioner publishes free model clauses written for exactly that situation.
Is Microsoft 365 customer data stored in New Zealand?
It can be. New Zealand appears on Microsoft’s published list of local region geographies, and tenants in those geographies can take up an extra set of commitments the company calls Advanced Data Residency. Your own tenant may still be in Australia, depending on how it was created, so check the setting before telling a customer anything.
Does using a New Zealand data centre put your data beyond foreign law?
No. A data centre in New Zealand fixes the physical location and leaves the legal question open, because a foreign-owned operator can still be ordered by its own courts to produce what it controls. Removing that exposure means using a provider with no offshore parent.
How long does it take to work out where a business’s data is held?
For a business under thirty people, half a day to build the first list and two to three weeks to get written answers back from every vendor. The large providers answer immediately because the information is already published. Smaller suppliers are the ones that take the time.
Does the New Zealand government have rules about storing data offshore?
Yes, for public sector agencies. Under the Cloud First policy an agency may only put data classified RESTRICTED or below into a public cloud service, and over time must host RESTRICTED information in a New Zealand data centre where a suitable onshore service exists. Private businesses are not bound by that policy directly. It reaches them through supplier contracts, and that is how the question turns up in an ordinary government tender.
Does New Zealand law require business data to be kept onshore?
No general law requires it. The requirements that do exist come from contracts and sector rules, including government procurement terms, health sector agreements and financial services licence conditions. Once signed, those bind a business as firmly as legislation would.
What does it cost a small business to sort this out?
For a firm of around thirty people, budget roughly $3,900 once to build the register and chase the vendor answers, and about $4,800 a year to keep it current. A five-person business can do the same work in a couple of hours with a spreadsheet.
What should I ask a software vendor about where our data is held?
Ask which country stores the data including backups and logs, which company sells the service and where it is incorporated, which subprocessors touch the data, what the vendor does if a foreign authority demands a customer file, and what you get back on the day you leave. Get every answer in writing and file it with the contract.
Does Exodesk work with Christchurch and Dunedin businesses on where their data is held?
Yes. Exodesk works with businesses across Canterbury, Otago and Southland from offices in Christchurch and Dunedin, and has supported South Island clients since 1989. That work covers building the system register and moving the workloads that belong in New Zealand.
NEXT STEP
Could you name a country for every system you run?
Most businesses can name three or four and guess at the rest, and the guesses are the ones that turn up wrong in a procurement schedule. An IT assessment lists every system holding customer or staff information, records the country it stores data in and the company that owns it, and flags what should be sitting in New Zealand.
Or read more about our cloud solutions.
