When your eye clinic switches to cloud software, your scans, your history and your contact details move somewhere new, and it is fair to ask exactly where that is and who can see them. The reassuring answer, in Australia, is that your records stay protected by the same privacy law wherever they are kept, and a clinic that has chosen carefully can keep them in the country. Here is what actually happens to your information, in plain terms, and the rights you hold over it the whole way.
"The cloud" sounds like it means your data floats off to somewhere far away and out of reach. It does not have to. The cloud is just computers in a data centre that someone else runs, and the only questions that really matter for your privacy are simple ones: where those computers are, who is allowed to look at what they hold, and what happens if something goes wrong. Australian law has an answer for each, so it is worth taking them one at a time.
Your records are protected by law, no matter how small the clinic
Start with the law, because it sits underneath everything else. The main federal law protecting your information is the Privacy Act 1988, which sets out 13 Australian Privacy Principles, the rules an organisation has to follow whenever it handles personal information.1 Many small businesses are exempt from that Act, but health care is the important exception: regardless of turnover, the Privacy Act covers any business that provides a health service, so your eye clinic is bound by it no matter how small it is.2
Your scans and your history are not treated as ordinary contact details, either. Health information is classed as "sensitive information" under the Act, which means stricter requirements apply when an organisation handles it.3 And if a clinic gets it wrong, you are not left to sort it out alone. The independent regulator is the Office of the Australian Information Commissioner, the OAIC, and you can make a complaint to it about the way your personal information has been handled.4
Moving to the cloud is not the same as moving overseas
The worry underneath "moving to the cloud" is usually that the data leaves the country. It need not, and the choice is the clinic's to make. The regulator is explicit that privacy law does not stop an organisation using a cloud provider, and equally does not push the data offshore: "Generally, no. The Privacy Act does not prevent an organisation or agency from engaging a cloud service provider to store or process personal information overseas."5 In other words, where your data physically lives depends on the provider and the region a clinic chooses, not on the word "cloud". Software can run entirely on servers inside Australia, and that is a deliberate decision a clinic can make and ask about. Trenthos builds Trenthos Vision this way, keeping clinical data in an Australian region, ap-southeast-2.
If a clinic does send your information to a recipient overseas, the responsibility does not travel with it. Before disclosing personal information to an overseas recipient, an organisation has to take reasonable steps to make sure that recipient handles it in line with the Australian principles.6 More than that, it stays on the hook afterwards: the organisation that sent the data is accountable for an act of the overseas recipient that would breach the principles, as though it had done so itself.6 Sending data offshore, in other words, does not send the responsibility for it offshore too.
You can see your records, correct them, and control who sees them
Your information is not something that simply happens to you behind a screen; you have rights over it that the move to cloud software does not change. If you ask an organisation that holds personal information about you, including your eye clinic, it must give you access to that information.7 And if what it holds is wrong or out of date, you can ask it to fix it, and it has to take reasonable steps to correct it.8 Those rights follow your record into whatever system the clinic runs.
There is a second layer of control that many people forget they have, in the national record. My Health Record is opt-out, which means you have one unless you have cancelled it, and you can cancel it at any time.9 While you have it, it is yours to manage: you can set access controls that decide which healthcare providers can see your record and which documents they are shown.10 None of that depends on which software your clinic happens to use.
If something goes wrong, you have to be told
No system is perfectly safe, so the honest question is not whether a breach can ever happen but what the law makes a clinic do when one does. The answer is the Notifiable Data Breaches scheme: when a data breach is likely to result in serious harm, the organisation must notify both you and the OAIC.11 The threshold matters here, because it is not every stray email that triggers it, but a breach serious enough to put you at real risk. When that line is crossed, you are entitled to know, so that you can change a password, watch an account, or take whatever step protects you.
This is not a hypothetical for health care. Health is consistently one of the most breached sectors in the country: in the second half of 2024 the health sector reported more data breaches than any other, making up 20% of all those notified.12 That figure is the strongest argument for choosing a clinic and a system that treat security as the main event rather than an afterthought, because the records being protected are exactly the kind that attackers go looking for.
"De-identified" is a careful process, not a magic word
Sometimes your information is used beyond your own care, to improve software or for research, and when it is, it should be de-identified first. It is worth being precise about what that word does and does not promise, because it is often used too loosely. De-identification is a process of removing and altering the details that identify you, not a single step like deleting your name.13
It is also not a permanent stamp. Whether information counts as de-identified depends on the context, including where and how it is released, so the same data can be de-identified in one setting and not in another.13 The regulator is candid that this is a risk-management exercise, not an exact science: done well it reduces the chance of someone being re-identified to a very low level, rather than guaranteeing it can never happen.13 That is why careful organisations treat de-identification as an ongoing discipline, and why this site says "de-identified" rather than "anonymous". We have written separately about the privacy engineering that makes this work properly.
When your clinic switches software, your record moves with you
A change of software does not loosen any of this; if anything, it is the moment the protections are tested. While a clinic holds your information it must take reasonable steps to protect it from loss, misuse and unauthorised access, whatever system it runs on.14 And when information is genuinely no longer needed, the clinic has to take reasonable steps to destroy or de-identify it, unless a law requires the record to be kept.14
For health records, the law usually does require it. In the ACT, New South Wales and Victoria, an adult's records must be kept for seven years from the last visit, and a child's until they turn 25.15 Because the record has to be kept, a clinic changing systems cannot simply discard it; it has to carry your history across to the new software intact. A good migration moves the whole record, your scans, your letters and your history, not a thinned-out copy of it. That continuity is the quiet difference between software that respects your record and software that loses pieces of it in the move.
What this means for you
You do not need to understand any of the machinery to be safe; keeping it working is the system's job, not yours. But a handful of plain questions will tell you most of what you want to know about a clinic's software, and you are entitled to ask them. Is my data kept in Australia? Who can see it? Will you tell me if something goes wrong? Can I get a copy of my records? A clinic that can answer those calmly and specifically has thought about your privacy; one that cannot has some thinking left to do.
The reassuring part is that the protections do not depend on you chasing them. They are written into the law that covers every Australian clinic, and the better software is simply the kind designed around them rather than in spite of them. Trenthos builds Trenthos Vision to keep clinical data in Australia, protect it as the law requires, and give your record somewhere it can move without being lost, because where your eye scans go, and who can reach them, should never be a mystery to the person they belong to.
References
- Office of the Australian Information Commissioner. The Privacy Act. OAIC. oaic.gov.au
- Office of the Australian Information Commissioner. Small business. OAIC. oaic.gov.au
- Office of the Australian Information Commissioner (2025). Guide to health privacy: Introduction and key concepts. OAIC. oaic.gov.au
- Office of the Australian Information Commissioner. What we do. OAIC. oaic.gov.au
- Office of the Australian Information Commissioner (2019). Sending personal information overseas. OAIC. oaic.gov.au
- Office of the Australian Information Commissioner (2025). Australian Privacy Principles guidelines - Chapter 8: APP 8, cross-border disclosure of personal information. OAIC. oaic.gov.au
- Office of the Australian Information Commissioner (2019). Australian Privacy Principles guidelines - Chapter 12: APP 12, access to personal information. OAIC. oaic.gov.au
- Office of the Australian Information Commissioner (2019). Australian Privacy Principles guidelines - Chapter 13: APP 13, correction of personal information. OAIC. oaic.gov.au
- Office of the Australian Information Commissioner. About My Health Record. OAIC. oaic.gov.au
- Office of the Australian Information Commissioner. Manage your My Health Record. OAIC. oaic.gov.au
- Office of the Australian Information Commissioner. About the Notifiable Data Breaches scheme. OAIC. oaic.gov.au
- Office of the Australian Information Commissioner (2025). Latest Notifiable Data Breaches statistics for July to December 2024. OAIC. oaic.gov.au
- Office of the Australian Information Commissioner (2018). De-identification and the Privacy Act. OAIC. oaic.gov.au
- Office of the Australian Information Commissioner (2025). Australian Privacy Principles guidelines - Chapter 11: APP 11, security of personal information. OAIC. oaic.gov.au
- Royal Australian College of General Practitioners. Medical records. RACGP. racgp.org.au
Trenthos Research
Get new writing in your inbox
An occasional email when we publish - no more than that. Pick the topics you care about, or leave them unticked to get everything.
About this piece. General commentary on healthcare and technology, not clinical or legal advice. It reflects our approach and intent - not completed results, named partners, commercial terms, or any identifiable patient. For how we handle data, the Privacy Policy is the source of truth; see also the Disclaimer.