Legal Reference · Updated May 2026

Australian
Healthcare &
Patient Data Laws

A structured reference to federal legislation, state and territory regimes, sector-specific rules, and current reform timelines governing health information in Australia.

Federal + 8 Jurisdictions POLA 2024 · RRO Act 2025 OAIC · ADHA · TGA Current to May 2026
Federal law
State / territory
Sector-specific
New / amended 2024–26
Enforcement risk
01

Federal Privacy Framework

The Privacy Act 1988 (Cth) is the principal federal instrument. Health information is classified as sensitive information and receives the highest level of protection under the Australian Privacy Principles.

Privacy Act 1988 (Cth) — as amended by POLA 2024
Principal federal privacy law; governs all APP entities handling personal and sensitive health information
Federal Amended Dec 2024 Penalty up to $50M
All APP entities — private sector organisations with annual turnover above AUD $3 million, plus smaller entities that are health service providers regardless of turnover. Federal and ACT government agencies. From Wave 2 reforms (timeline TBC): small businesses exemption to be narrowed.
  • APP 3: Health information can only be collected with consent or if necessary for a permitted health situation
  • APP 6: Health info used/disclosed only for primary purpose of collection or with consent — secondary use requires specific grounds
  • APP 11: Must take reasonable steps to protect health information from misuse, interference, loss, unauthorised access — clarified by POLA 2024
  • APP 12/13: Individuals have rights of access and correction; health providers have specific obligations around release of records
  • Clarified "reasonable steps" standard under APP 11 — now more prescriptive
  • New statutory tort for serious invasion of privacy — individuals can sue directly from June 2025
  • OAIC infringement notices up to AUD $66,000 per contravention for administrative breaches (e.g. non-compliant privacy policy)
  • New criminal offence for doxxing (publishing private information to harm) — up to 7 years imprisonment
  • Strengthened children's privacy provisions
⚠ Penalties: Up to AUD $50 million · or 3× benefit obtained · or 30% of adjusted domestic turnover — whichever is greatest. First civil penalty against a health entity: Australian Clinical Labs fined AUD $5.8M (October 2025) after 2022 Medlab Pathology breach.
National Health Act 1953 (Cth) — National Health (Privacy) Rules 2025
Governs MBS and PBS claims data held by Commonwealth agencies
Federal Rules commenced 1 April 2025
Requirements for Australian Government agencies regarding use, storage, disclosure, and linkage of Medicare Benefits Schedule (MBS) and Pharmaceutical Benefits Schedule (PBS) claims information — one of the richest health datasets in Australia.
  • Data storage: Agencies must implement enhanced security controls for MBS/PBS data at rest and in transit
  • Linkage restrictions: Strict rules on linking MBS/PBS data with other datasets without authorisation
  • Research access: Researchers must apply through approved pathways; ethics committee approval mandatory
  • Disclosure limits: Tightened rules on which agencies can share data and for what purposes
Relevance for medtech: Clinical trial sponsors using Medicare data for recruitment or outcome verification must comply with these Rules. Registry linkage studies using PBS data require specific authorisation and data governance documentation.
02

Digital Health Legislation

A parallel legislative stack governs the My Health Record system, healthcare identifiers, and digital health infrastructure — largely separate from the Privacy Act but interoperating with it.

My Health Records Act 2012 (Cth) — amended by RRO Act 2025
Governs Australia's national electronic health record system — approximately 24 million Australians enrolled
Federal Amended Dec 2025 ADHA Oversight
Opt-out national system — all Australians have a My Health Record unless they chose to opt out. Healthcare providers registered with My Health Record can upload and access clinical documents. The Australian Digital Health Agency (ADHA) is System Operator. The OAIC oversees privacy enforcement.
  • Permitted: Provision of healthcare to the individual; management of healthcare; indemnity insurance for healthcare providers; quality assurance and safety activities
  • Prohibited (expanded by RRO Act 2025): Underwriting insurance decisions; determining insurance policy coverage; use for employment decisions; any commercial secondary use without specific authorisation
  • RRO Act 2025 addition: Downstream use of data that was lawfully downloaded from MHR but then used for a prohibited purpose is now also prohibited — closes a previous gap
De-identified MHR data available for research and public health purposes under the ADHA's Secondary Use Framework. Governed by a My Health Record Data Governance Board. Individual opt-out from de-identified data release is available. Identified data requires individual consent.
⚠ Civil penalties up to AUD $315,000 for individuals and AUD $1.575M for bodies corporate for misuse of MHR data. All MHR data breaches must be reported to ADHA regardless of scale.
Healthcare Identifiers Act 2010 (Cth) — amended by RRO Act 2025
Governs Individual Healthcare Identifiers (IHI), HPI-I (providers), and HPI-O (organisations)
Federal Phase 2 Dec 2025
Unique numeric identifiers that enable safe linkage of health records across systems — an Individual Healthcare Identifier (IHI) is assigned to every Australian. Underpins My Health Record, electronic prescribing, secure messaging, and pathology/imaging linkage.
  • Enhanced National Healthcare Provider Directory — more comprehensive digital health gateway for provider communication
  • Research institutes can now use healthcare identifiers for HREC-approved research with patient consent
  • Data standards development mandated for safe cross-jurisdictional data exchange
  • From February 2027: Healthcare identifiers authorised for use in wearable devices and remote patient monitoring technology
Medtech/SaMD relevance: The February 2027 extension to wearables and remote monitors is significant for connected device manufacturers — products that capture biometric data may soon be able to integrate with the HI Service, creating both an opportunity and a compliance obligation.
Digital ID Act 2024 (Cth)
Establishes the Australian Government Digital ID System — affects patient identity verification in health portals
Federal 2024
Accredited Digital ID providers must comply with the NDB scheme when providing accredited services. Health platforms using Digital ID for patient authentication face privacy obligations aligned with the Privacy Act. The OAIC co-regulates Digital ID privacy alongside the Digital ID Regulator.
03

State & Territory Legislation

The Privacy Act does not apply to state and territory public sector health service providers — public hospitals, state health departments. This creates a patchwork. NSW, Victoria, and ACT have the most comprehensive parallel health privacy regimes.

New South Wales
Privacy and Personal Information Protection Act 1998 (NSW) — public sector personal info

Health Records and Information Privacy Act 2002 (NSW) — health information, public AND private sector. 15 Health Privacy Principles (HPPs) broadly equivalent to APPs but not identical. NSW IPC enforces.

Private sector health providers must comply with both the federal APPs and NSW HPPs.
Victoria
Health Records Act 2001 (Vic) — governs health information for both public and private sector health service providers. 11 Health Privacy Principles. Office of the Victorian Information Commissioner (OVIC) enforces.

Privacy and Data Protection Act 2014 (Vic) — general privacy for Victorian public sector.

Victoria: dual compliance required for private health providers.
ACT
Health Records (Privacy and Access) Act 1997 (ACT) — health records in the ACT, public and private sector.

Information Privacy Act 2014 (ACT) — general ACT public sector privacy.

ACT has the oldest dedicated health records legislation in Australia.
Queensland
Information Privacy Act 2009 (Qld) — Queensland public sector only (including public hospitals).

Information Privacy and Other Legislation Amendment Act 2023 (Qld) — introduces mandatory data breach notification for Qld public sector; breach notification requirements expected from mid-2026.

Private health providers in QLD covered only by federal Privacy Act.
Western Australia
Privacy and Responsible Information Sharing Act 2024 (WA) — commenced 2025; applies to WA public sector including public hospitals. Introduces mandatory information breach notification and an Information Commissioner for WA.

First comprehensive privacy legislation for WA. Previously had no specific privacy Act.
South Australia
No dedicated privacy legislation. SA government agencies operate under Cabinet-endorsed Information Privacy Principles. SA Privacy Committee handles complaints.

Health and Community Services Complaints Commissioner receives broader health complaints.

Private sector SA health providers covered by federal Privacy Act only.
Northern Territory
Information Act 2002 (NT) — covers NT public sector including public hospitals. NT Information Commissioner enforces.

Private health providers covered by federal Privacy Act only.
Tasmania
Personal Information Protection Act 2004 (Tas) — covers Tasmanian public sector including public hospitals. Tasmanian Ombudsman handles complaints.

Private health providers covered by federal Privacy Act only.
Key compliance rule: A private hospital or clinic operating in NSW, VIC, or ACT must comply with both the federal APPs and the relevant state health privacy principles — whichever imposes the higher standard governs. A public hospital in any state is covered by that state's legislation, not the federal Privacy Act.
04

Data Breach Notification

Healthcare is consistently the most-breached sector in Australia. In January–June 2025, health entities accounted for 18% of all Notifiable Data Breach notifications — the highest of any sector.

Notifiable Data Breaches (NDB) Scheme — Part IIIC, Privacy Act 1988
Mandatory notification to OAIC and affected individuals when a breach is likely to cause serious harm
Federal Mandatory Commenced 2018
  • Unauthorised access to, disclosure of, or loss of personal information held by an APP entity
  • A reasonable person would conclude the breach is likely to result in serious harm to one or more individuals
  • The entity has not been able to prevent likely serious harm through remedial action
  • Notify OAIC as soon as practicable after becoming aware of an eligible data breach
  • Notify affected individuals directly — or by prominent publication if direct notification impractical
  • Statement must include: entity identity, description of breach, kinds of information, recommendations for individuals
  • Assessment window: 30 days maximum to assess whether a suspected breach is eligible
All MHR data breaches must be reported to the ADHA regardless of scale or harm assessment. This is separate from and additional to the NDB scheme. ADHA contacts affected healthcare recipients where required.
⚠ Australian Clinical Labs: AUD $4.2M for APP 11 failure + AUD $800K for delayed assessment + AUD $800K for late OAIC notification = AUD $5.8M total (first-ever health sector civil penalty, October 2025)
State-Level Mandatory Breach Notification — Emerging Patchwork
QLD and WA have introduced state-level mandatory breach notification for public sector health entities
State 2024–2026
  • Queensland: IP&OLA 2023 introduces mandatory breach notification for QLD public sector — notification requirements expected from mid-2026
  • Western Australia: PRIS Act 2024 establishes mandatory information breach notification scheme for WA public sector, including public hospitals
  • NSW, VIC, ACT: No separate mandatory breach notification schemes — rely on federal NDB scheme for both public and private health entities
Compliance implication: A public health service operating in QLD or WA from 2026 must comply with both the state mandatory breach scheme AND the federal NDB scheme — with potentially different thresholds and timelines.
05

Research, Secondary Use & AI

Research and secondary use of health data is permitted under specific conditions — ethics approval, de-identification, and data governance arrangements. AI and machine learning add an emerging regulatory layer.

Research Exemptions — Privacy Act + National Health Act
Conditions under which health data can be used without individual consent for research purposes
Federal Research
  • Research relevant to public health or safety — if HREC-approved, consent impractical, and research cannot be conducted with de-identified data
  • Compilation or analysis of statistics relevant to public health or safety
  • Management, funding, monitoring, or evaluation of a health service
  • Genetic relative disclosure — to lessen serious threat to life/health/safety of a genetic relative
National Health (Privacy) Rules 2025 govern access to linked MBS/PBS data. Applications must be submitted through the Australian Institute of Health and Welfare (AIHW) or the Centre for Health Record Linkage (CHeReL) in NSW. Ethics committee approval is mandatory. Data is supplied in de-identified form.
Research institutes can now use healthcare identifiers for HREC-approved research with patient consent. This enables more precise record linkage for longitudinal health studies and device outcome registries.
AI, Algorithms & Health Data — Emerging Obligations
No dedicated AI health law yet; Privacy Act + TGA SaMD rules + OAIC priorities converge
AI / SaMD OAIC Priority 2025–26 Rapidly evolving
  • Privacy Act APPs apply to AI systems processing health data — no separate AI exemption
  • AI that constitutes a medical device (SaMD) must comply with TGA classification, clinical evaluation, and cybersecurity requirements
  • OAIC 2025–26 priorities explicitly target "artificial intelligence systems" and "excessive data collection" — health AI is in scope
  • Automated decision-making using health data must comply with APP 3 (collection), APP 6 (use/disclosure), and the purpose limitation principles
  • Must identify the legal basis for collection and use of health data for training
  • De-identification is required before training unless consent obtained or permitted health situation applies
  • Re-identification risk must be assessed — OAIC has emphasised that "de-identified" data that can be re-identified remains personal information
  • If training data sourced from MHR or MBS/PBS, specific authorisation frameworks apply
Watch: Australia's proposed AI governance framework (voluntary in 2025; mandatory AI guardrails under consultation) will interact with health AI. The TGA's position on AI/ML SaMD is aligned with FDA GMLP principles. No direct equivalent to the EU AI Act has been enacted, but obligations under the Privacy Act effectively fill some of the same space.
Australian Institute of Health and Welfare Act 1987 (Cth)
Governs AIHW's role as Australia's national health data custodian and linkage authority
Federal Data Custodian
  • Collects, links, and analyses health and welfare data from states, territories, and Commonwealth
  • Operates the National Death Index, National Cancer Statistics Clearing House, and multiple disease registries
  • Provides data linkage services for approved research — linking MBS, PBS, hospital, cancer, death data
  • Applications require ethics approval; strict conditions govern data access, storage, and publication
Medtech relevance: Post-market surveillance studies and real-world evidence generation for Australian medical devices frequently depend on AIHW data linkage. Early engagement with AIHW during trial design avoids months of delay at the data access stage.
06

Reform Timeline 2024–2027

Australian health data law is in its most active reform period in decades. The following timeline shows enacted and pending changes relevant to healthcare and medtech.

November 2024
Privacy and Other Legislation Amendment Act 2024 (POLA) passed by Parliament. Statutory tort for serious privacy invasion; clarified APP 11; criminal doxxing offence; OAIC infringement notices. Commenced December 2024.
December 2024
Western Australia Privacy and Responsible Information Sharing Act 2024 (PRIS) commenced — first privacy legislation for WA public sector, including public hospitals.
1 April 2025
National Health (Privacy) Rules 2025 commenced — enhanced protection for MBS/PBS claims data; new storage, linkage, and disclosure requirements for Commonwealth agencies.
June 2025
Statutory tort for serious invasion of privacy became actionable — individuals can now sue directly in Australian courts without needing to go through OAIC. First significant cases expected in 2026.
October 2025
First civil penalty in health sector: Australian Clinical Labs ordered to pay AUD $5.8M — establishes that health entities face real financial consequences for APP 11 failures and delayed breach notification.
December 2025
Regulatory Reform Omnibus Act 2025 (RRO Act) — Phase 2 healthcare identifier reforms commenced; MHR prohibited purposes expanded; National Healthcare Provider Directory enhanced; research use of identifiers with consent enabled.
Mid-2026 (expected)
Queensland mandatory data breach notification for public sector (including public hospitals) expected to take effect — one year after QLD Information Privacy Act reforms commenced.
February 2027
Healthcare identifiers extended to wearable devices and remote monitors — manufacturers of connected health technology will face new obligations when integrating with the HI Service.
TBC — Wave 2 Privacy Reform
Second tranche of Privacy Act reforms: Narrowing of small business exemption (currently AUD $3M turnover threshold); right to erasure; right to object to automated decision-making; enhanced children's privacy protections. Bill expected in 2026.
07

Data Domicile, Residency & Sovereignty

Where health data physically lives — and who has legal access to it — is one of the most operationally consequential compliance questions for cloud-hosted medtech, SaMD, and hospital systems. Three distinct concepts apply simultaneously.

Three Concepts — Residency vs Sovereignty vs Localisation
Frequently conflated, but legally distinct — each creates different obligations
Foundational
The physical geographic location where data is stored. A residency requirement says where data must sit — but does not prevent foreign legal access to it. A US hyperscaler's Sydney data centre satisfies data residency but not data sovereignty.
Data remains subject exclusively to Australian law, accessible only to Australian entities, stored and operated by providers not subject to foreign surveillance legislation. Requires both local storage and that the cloud provider's parent company is not compellable under foreign law (e.g. US CLOUD Act, US FISA Section 702).
A legal requirement that data must remain within a country's or territory's borders — the strongest form of restriction. Australia's My Health Record regime is effectively a localisation mandate. Some state health records laws impose intra-state localisation unless specific conditions are met.
The critical distinction for cloud procurement: A hyperscaler running servers in Sydney still holds data subject to US CLOUD Act compulsion — meaning US law enforcement can access that data without notifying the Australian patient or provider. Only a provider whose parent entity is not subject to foreign surveillance law achieves true sovereignty.
My Health Records Act 2012 — Absolute AU Localisation Requirement
MHR data and all backups must never leave Australia — no exceptions, no consent mechanism
Federal Absolute Prohibition MHR System
My Health Record data — including all associated data and backups — must never be processed, held, taken, or handled outside of Australia. This applies to the System Operator (ADHA), registered healthcare providers uploading or accessing records, repository operators, portal operators, and contracted service providers.
  • Any software or platform that integrates with the MHR system must host all MHR-derived data in Australian infrastructure
  • Backup and disaster recovery infrastructure must also be onshore — offshore DR is non-compliant
  • Offshore support or maintenance personnel who can access MHR data constitute a potential breach
  • Cloud service providers must be able to demonstrate ADHA-compliant AU-only data handling, including subcontractors
⚠ Offshore storage or processing of MHR data is a criminal offence under the MHR Act — not merely a civil penalty matter. All MHR-related data breaches (including offshore access incidents) must be reported to ADHA.
APP 8 — Cross-Border Disclosure of Health Information
Liability follows the data offshore — the Australian entity remains accountable even after transfer
Federal Strengthened by POLA 2024 Accountability follows data
Before disclosing personal health information to an overseas recipient, an APP entity must take reasonable steps to ensure the recipient will handle it in accordance with the APPs. If the overseas recipient mishandles the data, the Australian entity is treated as having breached the APPs itself — not the foreign provider. Liability does not transfer to the overseas party.
  • Sending health data to an overseas cloud provider for processing (not just storage) is a disclosure
  • Offshore support personnel being given access to health data — even temporarily — is a disclosure
  • API calls that route health data through overseas servers may be a disclosure depending on what the recipient does with the data
  • Exception: Routing data in transit through overseas servers without effective access by the overseas party is a "use" not a "disclosure" — APP 8 does not apply, but APP 11 security obligations still do
  • Exception: Offshore cloud storage where the provider is contractually limited to storage only and the AU entity retains effective control is generally not a disclosure — but must be documented
  • Contractual protections: Data processing agreements requiring APP-equivalent standards from overseas vendors
  • Due diligence: Assess the recipient's legal jurisdiction and whether foreign surveillance laws (US CLOUD Act, UK IPA, etc.) create compelled disclosure risk
  • Informed consent: Alternatively, obtain explicit patient consent to offshore disclosure after informing them the APPs may not apply — rarely practical for health data at scale
  • Post-POLA 2024: Contractual clauses alone are no longer sufficient — actual oversight and audit of overseas handling is now expected
State-Level Intra-Territory Residency — NSW, VIC, ACT
Health records laws in NSW and VIC restrict disclosure outside the state — creating a sub-national localisation layer
NSW · VIC · ACT Often Overlooked
The Health Records and Information Privacy Act 2002 (NSW) and the Health Records Act 2001 (Vic) restrict disclosure of health records outside the relevant state or territory — not just outside Australia. This means data held in a NSW public hospital system cannot be moved to a Victorian data centre, or to an interstate cloud region, without meeting specific criteria.
  • The individual consents to the transfer
  • A substantially similar protective regime will apply to the records in the receiving jurisdiction
  • The transfer is necessary for the performance of a contract between the individual and the organisation
  • The organisation has taken reasonable steps to protect the information consistent with state health privacy principles
Multi-state deployments: A cloud platform deployed across NSW and VIC public hospitals must analyse both state regimes. A Sydney AWS region hosting Victorian public hospital data may face both VIC HPP compliance requirements and NSW HRIPA disclosure restrictions. This is one of the most commonly overlooked compliance issues in national health platform deployments.
Protective Security Policy Framework (PSPF 2025) & IRAP
Mandatory for Commonwealth health entities; effectively mandatory for vendors supplying government health systems
Government PSPF 2025 — July 2025 Flows to suppliers
The PSPF 2025 (published July 2025) is mandatory for non-corporate Commonwealth entities — including DoHDA, Services Australia (Medicare/PBS), the ADHA, and AIHW. It governs classification of health data (OFFICIAL · OFFICIAL: Sensitive · PROTECTED), storage location, access controls, and cloud hosting standards. PSPF 2025 adds new requirements for AI systems, Zero Trust architecture, and connected peripheral technologies.
Cloud and SaaS providers supplying Commonwealth health agencies must undergo IRAP assessment by an ASD-endorsed assessor against the Australian Government Information Security Manual (ISM). IRAP certification at OFFICIAL: Sensitive level is effectively a procurement prerequisite for any platform handling Commonwealth health data, including MBS/PBS data, Medicare records, and ADHA systems.
Data centres used for classified or sensitive Commonwealth data must be HCF-certified — constructed to PSPF zone specifications. The HCF is currently undergoing reform (paused new registrations from November 2025). Cloud providers must use only HCF-certified facilities or compliant enclaves for Protected-level Commonwealth data.
Private sector flow-down: PSPF obligations flow through contracts to private sector suppliers. A medtech company supplying a connected device platform to a Commonwealth-funded hospital must implement PSPF-aligned security controls — including AU data residency, IRAP-assessed cloud hosting, and ISM-compliant access management — as contract conditions, even though the company itself is not a government entity.
Cloud Provider Selection — Compliance Decision Framework
How to assess whether a cloud or SaaS provider is compliant for Australian health data
Practical Guide
  • Yes → Must use AU-only infrastructure; provider must be registered with ADHA; no offshore access permitted for any personnel. Only AU-sovereign providers qualify.
  • No → Proceed to Tier 2
  • Yes → IRAP assessment required; PSPF compliance required; HCF-certified data centres; AU data residency expected at OFFICIAL: Sensitive and above. Major hyperscalers (AWS, Azure, Google) have achieved IRAP at these levels but remain subject to US CLOUD Act.
  • No → Proceed to Tier 3
  • Yes → State health records law restricts interstate and international disclosure; document compliance basis; confirm the receiving region/provider meets substantially similar protections.
  • No → Proceed to Tier 4
  • Overseas storage/processing triggers APP 8 — requires contractual protections and due diligence
  • Assess whether provider's parent company is subject to foreign compelled disclosure (US CLOUD Act, UK IPA)
  • Document the APP 8 compliance basis; maintain records for OAIC audit purposes
  • Privacy Impact Assessment recommended before deploying any offshore or hyperscaler solution for health data
⚠ Post-POLA 2024: The OAIC has explicitly flagged AI systems and cloud providers as regulatory priority areas for 2025–26. Inadequate APP 8 due diligence on overseas cloud vendors handling health data is a live enforcement risk — not a theoretical one.
Australian Sovereign Cloud vs Hyperscaler — Key Distinctions
Not all "Australian data centres" are created equal under law
Procurement CLOUD Act Exposure
  • Physical servers in Australia — satisfies data residency requirements
  • IRAP-assessed at OFFICIAL: Sensitive for government use — suitable for most Commonwealth health workloads below PROTECTED
  • Subject to US CLOUD Act — US law enforcement can compel disclosure regardless of where data sits; provider cannot always notify the Australian customer
  • Azure and AWS have "sovereign cloud" offerings (e.g. Azure Government, AWS GovCloud) with additional controls, but these are primarily designed for US government use
  • Macquarie Government, Vault Cloud, Sliced Tech, AUCloud — AU-owned, AU-operated, not subject to foreign surveillance law
  • IRAP-assessed at PROTECTED level in some cases — required for PROTECTED-level Commonwealth health data
  • No CLOUD Act or equivalent foreign compelled-disclosure risk
  • Typically higher cost and less feature-rich than hyperscalers — tradeoff is legal protection
  • MHR data → AU sovereign cloud only; no hyperscaler regardless of region
  • PROTECTED Commonwealth health data → AU sovereign cloud required; hyperscaler not sufficient
  • OFFICIAL: Sensitive Commonwealth data → IRAP-assessed hyperscaler AU region acceptable for most purposes
  • General private health data → hyperscaler AU region acceptable with APP 8 contractual protections and documented due diligence on CLOUD Act exposure
Practitioner's Note

The most common compliance failures in Australian healthcare data are: using health data for a secondary purpose without consent or a permitted health situation; delayed or absent NDB notifications (now attracting civil penalties — see Australian Clinical Labs); inadequate data security under APP 11, particularly in cloud-hosted systems; and cloud procurement that satisfies data residency but not data sovereignty — choosing a US hyperscaler's Sydney region for MHR-adjacent workloads is the most common example. For medtech and SaMD companies, the convergence of Privacy Act obligations, TGA cybersecurity requirements, PSPF flow-down in government contracts, and OAIC scrutiny of AI systems means that privacy, sovereignty, and regulatory compliance cannot be treated as separate workstreams. A Privacy Impact Assessment — including a cloud provider sovereignty assessment — should be initiated at the same time as TGA classification is determined, not after product launch.