Who Really Controls Your Firm's Client Data? Cross-border data sovereignty risk for law firms.

Data Sovereignty for Law Firms: A Legaltech Stack Guide

A practical, Australia-focused walkthrough for principals, covering practice management, AI notetakers and call recording, e-discovery and every other vendor that touches client data.

For most of the last decade, ‘the cloud’ was treated as a single decision a law firm made once: pick a practice management system, pick a document management system, migrate and move on. That framing no longer holds. A modern practice now runs on a stack of a dozen or more connected systems, each provided by a different vendor, each making its own choices about where client data physically sits, who can access it and under whose law it is governed. Sovereign data (the question of which country’s laws actually control your firm’s information, regardless of where you or your client are located) has quietly become one of the more consequential due diligence questions in legal technology procurement.

This matters more in 2026 than it did even two years ago. Australia’s privacy reform program is moving in tranches, generative AI tools are now embedded in research, drafting, document review and, increasingly, client meetings themselves, and the federal government’s whole-of-government cloud policy is pushing sovereign and local hosting up the agenda for every regulated sector, including legal services. This article works through what ‘sovereign data’ actually means, why it sits differently for law firms than for other businesses and where the exposure lives across the full legaltech stack: practice management, document management, e-discovery, AI research and drafting tools, AI notetakers and call recording, communications, billing and the infrastructure underneath all of it.

What ‘Sovereign Data’ Actually Means
Data sovereignty is often shorthand for ‘the data is stored in Australia,’ but that definition is incomplete and sometimes misleading. Three separate questions are usually bundled together under the term:

Data residency: the physical location of the servers storing the data. This is the easiest question to answer, and the one most vendors lead with in their marketing.

Data sovereignty: which country’s laws govern access to the data, regardless of where it is stored. A firm’s information can be physically hosted in a Sydney data centre and still be subject to a foreign government’s compulsion powers if the vendor operating that data centre is a subsidiary of a company headquartered elsewhere; the US CLOUD Act is the most commonly cited example, giving US authorities a legal basis to compel disclosure from US-headquartered providers even where the underlying data centre is offshore.

Data control: who can actually see or extract the data in practice: the vendor’s support staff, its offshore engineering team, its AI training pipeline or subcontractors several layers removed from the contract the firm actually signed.

A vendor can satisfy the first question and fail the other two. For a law firm, all three matter, because they sit on top of duties that other businesses don’t carry in the same form.

Why This Bites Differently for Law Firms
Every organisation that handles personal information has to consider the Privacy Act. Law firms carry an additional layer: the duty of confidentiality under the Australian Solicitors’ Conduct Rules, and, in litigation contexts, the practical reality that privileged material moving through a compromised or poorly governed system is a discoverability and waiver risk, not just a privacy incident.

The regulatory backdrop is also moving. The first tranche of Australia’s privacy reform passed in late 2024, introducing a new statutory tort for serious invasions of privacy (actionable without proof of damage), imprisonment and materially higher civil penalties for privacy interferences that don’t meet the old ‘serious or repeated’ threshold. A second tranche, the Privacy Amendment (Personal Data Protection) Bill 2026, is now out for consultation, with submissions open through 18 September 2026. Its centrepiece is a proposed ‘fair and reasonable’ test: an organisation’s handling of personal information must be objectively justifiable, not merely technically consented to. For firms handling sensitive client, employee and matter data, that shifts the compliance bar from ‘did we get a tick in a box’ to ‘would this data handling arrangement survive scrutiny.’

Separately, Australian Privacy Principle 8 already requires reasonable steps before disclosing personal information to an overseas recipient, and firms remain accountable for what happens to that data offshore: a vendor’s compliance certifications don’t transfer that accountability away from the firm that engaged them.

Working Through the Stack, Layer by Layer
‘The legaltech stack’ is now genuinely a stack, a set of interconnected systems rather than a single platform, and sovereign data risk doesn’t sit evenly across it. Here is where to look and what to ask.

Practice and matter management. This is the system of record for client details, matter notes, trust accounting and conflict checks, arguably the most sensitive single dataset in the firm. The question to put to any vendor, Australian-founded or otherwise, is not ‘is my data in Australia’ but ‘under what legal process, and from what jurisdiction, could a third party compel access to it and would I be notified?’ Ask for this in writing, not as a sales conversation.

Document and matter management (DMS). Correspondence, precedents, drafts and privileged material typically live here, often synchronised across desktop, mobile and email plug-ins. Because DMS platforms are frequently multi-tenant cloud services from global vendors, this is a common point where residency and sovereignty diverge: data can be pinned to an Australian or APAC region while remaining subject to the vendor’s home jurisdiction’s compulsion laws. Region-pinning is a useful control but not a complete answer on its own.

Communications and collaboration. Email, e-signature and client portals move privileged and confidential material outside the firm’s systems for every transaction. The relevant question here is less about server location and more about retention: how long is data cached or logged by the intermediary platform, and do the platform’s standard terms grant it any rights to use the content (including for product improvement or AI training) that a firm would not want applied to privileged material.

E-discovery and litigation support. These platforms concentrate enormous volumes of third-party and opposing-party data, often under court-imposed handling obligations, protective orders or confidentiality regimes that make jurisdictional questions a live legal issue rather than a background IT concern. Where a matter involves government, regulatory or national-security-adjacent parties, sovereignty questions can become case-critical rather than merely a procurement preference: this is one area where an unambiguous, verifiable local hosting and support arrangement is often worth paying a premium for.

AI and generative AI tools. This is the fastest-moving and least settled layer of the stack. Legal AI research, drafting and document-review tools typically process content through large language models operated by, or licensed from, a small number of global providers, and the default commercial terms for many consumer-grade AI products permit use of submitted content for model training unless a firm has specifically contracted out of it. Before any AI tool touches client material, a firm should have confirmed in writing: where inference actually happens (not just where the vendor’s headquarters is), whether prompts and outputs are retained and for how long, whether the vendor commercially guarantees no training on submitted data and how the vendor’s answer changes for a matter involving privileged or classified material.

AI meeting assistants, note-taking and call recording. This deserves separate treatment from research and drafting AI because it captures something different: live, often unscripted privileged conversation (client interviews, settlement discussions, board and committee calls) as it happens, rather than documents already reduced to writing. Tools such as Otter.ai, Fireflies and Fathom, and the AI companions now built into Zoom, Teams and Google Meet, typically stream audio to the vendor’s cloud in real time, generate a permanent, time-stamped transcript that did not previously exist and, under many providers’ standard commercial terms, retain the right to use that content to improve or train their models unless a firm has specifically negotiated otherwise. A verbatim transcript of a privileged conversation is also a new discoverable artefact in its own right, and 2026 has already produced a wave of US class-action litigation against major AI notetaker vendors over exactly this kind of unauthorised retention and use, a live signal worth watching even though the litigation itself is offshore.

There is also a consent layer here that sits on top of, and is separate from, the sovereignty question: recording a private conversation in Australia is governed by state, not federal, surveillance devices legislation, and the rules genuinely differ by state. Victoria, Queensland and the Northern Territory generally permit a participant to record their own conversation; New South Wales, Tasmania and the ACT technically prohibit it but carve out an exception for recordings not made for the purpose of communicating or publishing them to others; Western Australia and South Australia take the narrowest approach, requiring consent or a specific lawful-interest justification before a participant may record at all. A firm operating across state lines cannot rely on a single national assumption; regardless of which state applies, obtaining clear client consent before enabling any AI notetaker is both the safer legal position and the more defensible one against a confidentiality complaint.

Worth adopting as firm policy:

  • Disclose and get consent before any AI notetaker joins a client call, regardless of state
  • Default notetakers off for anything privileged and switch them on deliberately rather than by habit
  • Prefer vendors that contractually guarantee no training on submitted audio or transcripts and that support on-device or firm-tenant processing
  • Route the resulting transcript into the firm’s own DMS as the governed record, rather than leaving it sitting indefinitely in the notetaker vendor’s own retention store

Billing, trust accounting and payments. Often overlooked because it feels like ‘just finance,’ this layer holds bank details, trust ledger data and client financial information, all subject to its own regulatory regime under the state-based legal profession trust account rules. The same residency-versus-sovereignty distinction applies, with the added complication that trust accounting software is sometimes bundled with or bolted onto a practice management platform from a different vendor entirely, which is worth mapping explicitly rather than assuming.

Underlying cloud infrastructure. Most of the systems above are themselves built on one of a small number of hyperscale cloud providers. A vendor’s marketing claim of ‘Australian data sovereignty’ is only as strong as the contractual and technical arrangement it has with its own infrastructure provider: ask what tier of assurance that arrangement actually carries, rather than accepting the claim at the sales-deck level.

Identity, access and backup. The control plane spans every layer above: single sign-on, multi-factor authentication, and backup/disaster recovery. A firm can get every other layer of the stack right on sovereignty and still have its entire data footprint exposed through a poorly governed identity provider or an offshore backup copy nobody accounted for in the vendor review.

A Practical Due Diligence Approach
Given the number of vendors now in a typical firm’s stack, a one-off ‘cloud policy’ document is no longer sufficient. A more workable approach is a standing vendor register that records, for every system touching client data: the physical hosting region, the vendor’s ultimate parent jurisdiction, whether the vendor uses subprocessors and where they sit, the AI training and retention position in writing and the vendor’s stated process for responding to a foreign government data request. This is the kind of document to review at contract renewal, not just at initial onboarding: vendor ownership, subprocessor arrangements and AI features all change over the life of a contract far more often than firms tend to revisit them.

AI meeting assistants and call-recording tools deserve specific attention in this register. Unlike a practice management or DMS migration, these tools are often adopted informally by individual practitioners rather than procured centrally, which means many firms already use several such tools across different practice groups without any of them having undergone a vendor review. Bringing these into the same register, with the same consent and no-training questions applied, closes one of the more common gaps in an otherwise thorough sovereignty review.

It is also worth treating this as a partner-level governance question rather than delegating it entirely to IT. The confidentiality obligation rests with the practitioner, not the vendor, and the forthcoming ‘fair and reasonable’ standard under the tranche two reforms raises the practical bar for demonstrating, not just asserting, that a firm’s data-handling arrangements are defensible.

Where This Is Heading
The direction of travel across government and, gradually, across the profession, is towards more explicit sovereignty requirements rather than fewer. The federal government’s own whole-of-government cloud settings increasingly favour sovereign and locally accountable providers for sensitive workloads. That pressure is starting to flow through to sectors, like legal services, that handle comparably sensitive information without yet facing comparable mandates. Firms that get ahead of this by knowing their own stack, asking vendors precise rather than general questions and documenting the answers will find the next round of reform far less disruptive than firms that have never mapped where their data lives.

This article is provided for general information purposes only and does not constitute legal advice. Data sovereignty obligations depend on a firm’s specific vendor arrangements, practice areas and client base, and firms should seek advice tailored to their own circumstances, including from their professional indemnity insurer and the relevant state or territory law society, before changing vendor arrangements based on this content.

by Shaun Locke

Shaun Locke is a legal technology leader, entrepreneur, and connector. As the owner of Legal Practice Intelligence, Asia Law Portal and the custodian of a network of over 80,000 legal professionals. For over 25 years, Shaun has worked with law firms and accounting practices, harnessing technology to work smarter, safeguard information, and deliver better outcomes for clients.

His expertise spans practice management systems, CRM, information management and security, transaction management, knowledge and expertise management, eDiscovery, finance automation, and AI-driven solutions. Shaun has a proven track record of introducing innovative solutions that transform how legal and accounting practices operate into the future.

Back to blog