Why Data Sovereignty Matters for Government Surveillance Procurement in Australia

Why Data Sovereignty Matters for Government Surveillance Procurement in Australia

Jason Scarborough

Every procurement officer buying surveillance equipment for a government operation is making two decisions at once. The first is obvious: will this system do the job? The second is less visible, but increasingly the one that determines whether the procurement survives scrutiny: where does the data go, and who can access it?

Data sovereignty is no longer a compliance checkbox. It is becoming the central question in government surveillance procurement across Australia.

What data sovereignty actually means in a surveillance context

Data sovereignty refers to the principle that data is subject to the laws and governance of the country in which it is stored and processed. For surveillance systems, this has direct operational consequences.

A camera that stores footage on servers located outside Australia — or that is manufactured by a company subject to the laws of a foreign government — creates a chain of custody problem. The footage your system captures may be legally accessible to entities outside your jurisdiction. In an intelligence or law enforcement context, that is not a theoretical risk. It is a procurement failure.

The Australian government's position has hardened significantly. In 2023, the Department of Defence began removing Hikvision and Dahua cameras from Commonwealth buildings following an audit that found over 900 such devices across government agencies, including the Department of Foreign Affairs and Trade. The Attorney-General's office requested advice on a government-wide ban. The US and UK had already moved to prohibit these manufacturers entirely from federal procurement.

The issue is not whether these cameras produce good footage. Most of them do. The issue is that both Hikvision and Dahua are partly state-owned by the Chinese government, and China's 2017 National Intelligence Law requires organisations to cooperate with national intelligence efforts. That legal obligation does not stop at China's borders.

The Digital Transformation Agency's hosting certification framework

For data storage, the DTA's hosting certification framework provides clear guidance. Government data at the 'Protected' level must be hosted only by certified providers. The 'Certified Strategic' classification represents the highest standard — facilities that have passed the most rigorous audit scrutiny and comply with Australian Privacy Principles as determined by the Office of the Australian Information Commissioner.

For surveillance systems, this means the question is not just "is the camera good?" but "where is the footage stored, who built the storage infrastructure, and what laws govern that infrastructure?"

Australia's new Cloud Policy, released by the DTA in December 2025 and effective 1 July 2026, reinforces this. Australian Public Service entities must now prioritise cloud solutions that are secure, sovereign, and domestically governed.

What this means for councils and agencies buying surveillance today

If your organisation is procuring surveillance equipment in 2026, the procurement risk landscape looks like this:

Equipment manufactured by companies subject to foreign intelligence laws creates supply chain risk that is increasingly difficult to defend in a procurement review. Footage stored on offshore servers creates data residency risk that may breach your organisation's obligations under Australian Privacy Principles. Systems that cannot demonstrate end-to-end data sovereignty will face growing scrutiny from auditors, procurement panels, and the agencies responsible for whole-of-government security.

These are not hypothetical concerns. They are the documented reasons 913 cameras were ordered removed from Commonwealth buildings.

How Echidna Cams is designed for sovereign procurement

Echidna Cams is an Australian company. Our hardware is designed and assembled for the Australian market. Our data is stored on secure servers in Australia. We are not subject to the legal obligations of any foreign government.

Our end-to-end encryption and strict access controls mean that your footage remains yours — not accessible to us without your explicit authorisation, and not accessible to any third party under any foreign jurisdiction's laws.

For government bodies with specific data sovereignty or privacy requirements, we are happy to walk through our data handling architecture in detail before any procurement decision is made. That conversation is part of how we work, not an afterthought.

The question every government procurement officer should be asking their surveillance vendor is simple: under what country's laws does your data ultimately sit? If the answer is anything other than Australia, that is a procurement risk that belongs in your assessment.

Talk to our team about sovereign surveillance procurement

Contact us to discuss your operation's specific requirements. We work with councils and government agencies across Australia and understand what procurement panels need to see.

Back to blog