Australia and New Zealand Server Hosting Guide: VPS, Cloud, Dedicated and Colocation

Harbour Dolphin plans routes between cloud, data-centre and network nodes arranged like Australia and New Zealand.

The best server is not the one with the largest specification sheet. It is the one whose location, network, operating model and failure plan fit the workload. A Sydney VPS may be ideal for a small Australian website, while a New Zealand organisation with data-location requirements may prefer an Auckland or Wellington service. A busy game community may care more about single-thread CPU performance, packet loss and attack mitigation than about virtual CPU count. A regulated application may need contractual support, evidence and tested recovery that a low-cost unmanaged server does not include.

Ozlin Info currently operates workloads on OVHcloud infrastructure in Sydney and uses Proxmox at a high level as part of its virtualisation experience. That operational background informs this guide, but no production IP address, host name, panel address, network topology or security control is disclosed here.

This is an independent market guide, not a paid ranking. Ozlin has no disclosed affiliate relationship with the providers named below. Product availability, tax treatment and routing can change, so obtain a written quote and run workload-specific tests before committing.

Article map for Australia and New Zealand Server Hosting Guide: VPS, Cloud, Dedicated…, covering Choose the service model before the brand, A dated price snapshot, not a permanent price list, Australian and trans-Tasman…
Article map: Choose the service model before the brand; A dated price snapshot, not a permanent price list; Australian and trans-Tasman providers worth shortlisting; Public cloud and New Zealand data-location options.

Choose the service model before the brand

A VPS divides a physical host into isolated virtual servers. It is inexpensive, quick to rebuild and usually gives root or administrator access. The trade-off is that storage, CPU scheduling and the host failure domain remain partly shared. Ask whether CPU is dedicated or burstable, what storage redundancy exists, and whether snapshots are backups or only convenient restore points.

Public cloud infrastructure exposes compute, storage, networking and managed services through APIs. AWS, Microsoft Azure, Google Cloud and Oracle Cloud Infrastructure all operate Australian regions; AWS also opened its New Zealand region in 2025. Public cloud is useful for automation, managed databases, short-lived capacity and architectures that truly use multiple failure zones. It is not automatically cheaper. Instance runtime, disks, snapshots, public IPv4, support and outbound data should all enter the model.

A dedicated server gives one customer the physical machine. It can deliver predictable CPU, memory, local NVMe and a large transfer allowance at an attractive monthly price. The customer still needs a plan for disk failure, hardware replacement, remote access, spare capacity and restore time. A single dedicated server is not a high-availability architecture merely because the components are powerful.

Colocation places customer-owned hardware in a provider's facility. It offers the most hardware control and can make sense for specialised storage, GPU or long-lived workloads. It also shifts procurement, firmware, spares, freight, remote hands, power density and hardware disposal back to the customer. A low rack price can become expensive after power, cross-connects, transit, addresses and support are added.

A dated price snapshot, not a permanent price list

The following examples were observed on official provider pages on 29 August 2026. Australian prices are shown in AUD. Voyager publishes New Zealand dollars; the indicative AUD figures use the Reserve Bank of Australia's 28 August 2026 reference rate of A$1 = NZ$1.2084. The RBA cautions that its rates are not for commercial settlement. GST, card conversion and supplier tax treatment still need to be checked on the actual quote.

Provider and example Advertised price GST and term Network/transfer shown Important omissions or caveats
OVHcloud Advance-1 2026, selected AU configuration A$185.99/month plus A$185.99 setup Ex GST; configuration and commitment affect price Public bandwidth selectable within the product range; private network capability varies Region, hardware, IPv4, support and setup must be confirmed in cart
Kimsufi KS-B in Sydney A$16.79/month plus A$16.79 setup Ex GST; setup advertised as waived on 12+ month commitment 500 Mbps; APAC page states 25 TB/month Entry hardware and support scope are limited; verify stock and recovery expectations
Streamline Sydney i7-7700K example A$180/month Tax treatment and contract should be confirmed at checkout 15 TB on a 10 Gbps port advertised Older CPU; compare storage, DDoS, IPv4 and support on the final order
Streamline Sydney Xeon E-2286G example A$320/month Confirm tax and term 30 TB on a 10 Gbps port advertised Provider network and latency statements require route testing from real users
Voyager NZ VPS entry plan NZ$10.08, about A$8.34/month Ex NZ GST Provider advertises unlimited bandwidth Fair-use and cross-border tax conditions need review; entry plan is 1 vCPU/1 GB/15 GB
Voyager NZ dedicated entry plan NZ$225, about A$186.20/month Ex NZ GST Provider advertises unmetered service subject to its terms Auckland location; confirm remote hands, replacement and address allocation
Voyager device colocation NZ$190, about A$157.23/month Ex NZ GST Shared 1 Gbps PIR and a /29 advertised Power and form-factor limits matter; rack, cross-connect and support needs may change TCO
Servers Australia, Micron21, Twisted Servers, Intergrid, Datacom Quote required Obtain an itemised GST quote Varies by facility and service Include power, rack units, transit, cross-connects, remote hands and support

The table is deliberately not a benchmark. The OVH and Streamline examples are not identical machines, and a 10 Gbps port with a transfer quota is not the same commercial product as a lower-rate unmetered port. For public cloud, use each provider's current calculator with the same workload hours, disk type, snapshots, address count, support tier and outbound traffic instead of comparing a headline VM rate.

Decision path for Australia and New Zealand Server Hosting Guide: VPS, Cloud, Dedicated…, covering A dated price snapshot, not a permanent price list, Australian and trans-Tasman providers worth shortlisting, Public clo…
Decision path: A dated price snapshot, not a permanent price list; Australian and trans-Tasman providers worth shortlisting; Public cloud and New Zealand data-location options; Decision matrix.

Australian and trans-Tasman providers worth shortlisting

OVHcloud operates a broad bare-metal range in Sydney. Its Australian pages describe anti-DDoS protection as included with dedicated servers, and its game range adds game-oriented filtering. That is valuable for internet-facing services, but it should be described as built-in and comparatively strong—not infinite or guaranteed to stop every attack. Product and regional conditions, false positives, application-layer attacks, mitigation behaviour and traffic allowances remain relevant. Ozlin's operational lesson is equally important: provider mitigation does not replace server hardening. Patch the operating system and management plane, restrict administrative access, use least privilege and backups, and never install cracked or “nulled” software whose integrity cannot be verified. Such packages can carry credential stealers, web shells or other backdoors and turn a server into part of someone else's botnet.

Kimsufi and So You Start are OVHcloud's lower-cost lines. Kimsufi can be attractive for labs, replicas, personal services and workloads that tolerate entry-level hardware and a narrower service envelope. The Australian page currently shows Sydney stock and a 25 TB monthly APAC transfer condition. So You Start can bridge the gap toward more capable dedicated hardware, but availability and current pricing are often configuration-dependent. Neither label should be treated as a promise of the same SLA, replacement process, network options or support as a higher-tier product. Model the cost of downtime and an independent backup before celebrating the monthly saving.

Streamline Servers and GSL Networks advertise dedicated systems across Sydney, Melbourne, Brisbane, Adelaide, Perth and Auckland. Streamline attributes its offering to low-latency routing, DDoS protection and GSL's international network; these are provider claims and should be verified with route measurements from the actual ISPs and cities that matter. Its dated prices can be higher than a budget bare-metal plan, but a fair TCO comparison must hold CPU generation, RAM, storage, traffic, port speed, mitigation, support and contract term constant. For latency-sensitive games or trans-Tasman audiences, a week of representative ping, jitter, loss and route testing is more persuasive than a network map.

Servers Australia offers colocation and connectivity around major Australian locations and into New Zealand. Its public colocation material is best used to start a requirements conversation; pricing is quote-based. Ask for the exact facility, usable power, A/B feeds, rack depth, cross-connect and transit pricing, remote-hands minimums, delivery procedure and termination costs.

Micron21 is a Melbourne operator offering data-centre, cloud, connectivity and DDoS-related services. Certifications, facility tier language and protection capabilities on its site are provider statements: request the scope, current certificate, SLA and service design that apply to the proposed product rather than transferring a company-wide claim to one rack or VM.

Twisted Servers is a useful Perth option. Its data-centre page identifies Equinix PE2 and a Western Australian presence, which may reduce latency for WA users and make local hands easier than an east-coast deployment. Perth does not automatically improve international paths to every destination; measure the relevant Australian and overseas routes.

Intergrid advertises instant cloud, bare metal and colocation across Sydney, Brisbane, Melbourne, Perth, Adelaide and Auckland. It also states Tier 3 facilities, DDoS protection, an international network and a 100% network-uptime SLA. Those are attributed provider claims, and its own page contains inconsistent “six” and “seven” city wording, so this guide lists only the six named locations and recommends confirming the applicable SLA and exclusions in writing.

Voyager adds a practical New Zealand VPS, virtual data centre, dedicated and colocation shortlist. Its public entry prices are unusually clear, and it advertises New Zealand hosting, 99.98% environmental uptime and unlimited or unmetered connectivity on relevant products. Check fair-use terms, support hours, architecture and tax treatment. A single Auckland VPS and a redundant virtual data centre solve different availability problems even when both are called cloud.

Public cloud and New Zealand data-location options

AWS, Azure, Google Cloud and OCI are strongest candidates when the workload benefits from managed services, policy APIs, temporary scaling or multiple availability zones. Their bills require disciplined tagging, budgets, egress modelling and architecture. Read the provider's shared-responsibility documentation and Ozlin's AWS and Azure cloud-security checklist before assuming a managed control covers the application or data.

For New Zealand placement, AWS Asia Pacific (New Zealand) launched with three Availability Zones. Catalyst Cloud documents regions in Porirua and Hamilton, creating a locally operated alternative with OpenStack-based services. Datacom lists facilities in Auckland, Hamilton, Wellington and Christchurch and is relevant for data-centre, private-cloud and colocation conversations. Microsoft, Google and Oracle location portfolios change over time, so use their official region lists and verify that the exact service—not merely the company—exists in the intended region.

Platform Relevant documented footprint on 29 August 2026 Commercial comparison
AWS Sydney, Melbourne and New Zealand regions; AWS documents three Availability Zones in each Broad managed-service/API range; model compute, disks, snapshots, IPv4, support and egress in the official calculator
Microsoft Azure Australia East, Australia Southeast and New Zealand North, with service and zone availability varying by region Strong Microsoft identity/data ecosystem; verify the precise service, reservation and outbound-data line
Google Cloud Sydney (australia-southeast1) and Melbourne (australia-southeast2) Strong data, Kubernetes and managed-service options; use the product-by-region list and calculator rather than assuming parity
Oracle Cloud Infrastructure Australia East (Sydney) and Australia Southeast (Melbourne) Relevant for Oracle workloads and general IaaS; both documented regions currently list one availability domain, so design failure domains explicitly
Catalyst Cloud Porirua and Hamilton regions in New Zealand NZ-operated OpenStack option; compare service catalogue, support, network and workload portability
Datacom Facilities listed in Auckland, Hamilton, Wellington and Christchurch Relevant to colocation/private-cloud and managed requirements; obtain an itemised quote and facility-specific scope

This is a capability comparison, not a price ranking. Public-cloud prices change by service, purchase option and traffic direction too often for one small VM to represent the bill. Re-run the official calculators with the same 730 monthly hours, storage performance, snapshots, IP count, support plan and measured egress.

Data location is not a complete privacy conclusion. Replication, backups, support access, logs, subprocessors and customer configuration can move or expose data beyond the compute region. Record the real data flows and obtain advice for contractual or regulatory decisions.

Decision matrix

Priority VPS Public cloud Dedicated Colocation
Lowest entry cost Usually strong Strong for tiny or temporary use; egress may dominate later Budget ranges can be strong Usually weak after hardware and setup
Rapid scaling and APIs Moderate Strong Limited to provisioned machine Slowest unless spare hardware exists
Predictable raw compute cost Moderate Requires careful modelling Often strong Strong only at stable, sustained utilisation
Hardware control Low Low High within supplier options Highest
Managed services Limited Strong Customer or third party Customer or third party
Latency-sensitive games Test noisy-neighbour and CPU Can work, but cost/CPU class matters Often strong with the right network Strong for mature operators
DDoS exposure Product-specific Product and service-specific Product-specific; OVH/Streamline advertise mitigation Transit and mitigation contract-specific
Operational burden Moderate Can be high despite managed components High Highest
Data-location evidence Ask for host/backup locations Region and service documentation usually available Facility known; backups still matter Facility and hardware known; support paths still matter
Control and evidence map for Australia and New Zealand Server Hosting Guide: VPS, Cloud, Dedicated…, covering Public cloud and New Zealand data-location options, Decision matrix, Build a comparable TCO and related revie…
Control and evidence map: Public cloud and New Zealand data-location options; Decision matrix; Build a comparable TCO; A defensible selection process.

Build a comparable TCO

Use the same workload assumptions for every candidate:

monthly TCO = compute or rack + storage + backups + outbound traffic + public IPs + support + licences + remote hands + power + expected failure/downtime allowance

For a dedicated server, annualise setup and expected replacement downtime. For colocation, include hardware purchase, freight, rails, PDUs, spares and disposal. For public cloud, model normal and incident months, because log retention, snapshots and egress can jump during recovery. For a New Zealand quote converted to AUD, retain both the supplier currency and an exchange-rate buffer.

Then run evidence-producing tests: latency from real user ISPs; packet loss and jitter during peak periods; storage latency under the real queue depth; sustained CPU behaviour; restore time; mitigation escalation; and support response through the channel you would use during an incident.

A defensible selection process

  1. Classify the workload, data, recovery target, expected traffic and attack exposure.
  2. Shortlist locations based on users and dependencies, not company headquarters.
  3. Obtain itemised quotes covering tax, term, setup, addresses, transfer, port rate, support and exit.
  4. Compare 12- and 36-month TCO under normal, growth and incident scenarios.
  5. Pilot using production-like traffic without importing sensitive data unnecessarily.
  6. Harden the operating system, hypervisor or control panel before exposure; remove defaults, restrict administration, monitor changes and test backups.
  7. Record why the choice was made and set a review date.

Ozlin can help translate these requirements into a provider-neutral architecture and migration plan through its infrastructure and technology services. The commercial decision should remain traceable to measurements and contract terms rather than a logo or a single monthly price.

Practical checklist for Australia and New Zealand Server Hosting Guide: VPS, Cloud, Dedicated…, covering Decision matrix, Build a comparable TCO, A defensible selection process and related review points.
Practical checklist: Decision matrix; Build a comparable TCO; A defensible selection process; Sources and review record.

September 2026 update: latency, traffic billing and cross-border checks

This expanded section adds a workload-first comparison of Australian and New Zealand hosting with US and European options. It explains latency, monthly transfer, fixed or unmetered service, 95th-percentile billing and the contract and privacy questions that should be checked before purchase.

Start with the workload, not the continent

Distance creates a physical lower bound, but geography alone does not determine user experience. The actual route, peering, transit provider, congestion, packet loss, jitter, server processing time and the location of databases and third-party APIs all matter. Local hosting can still perform badly if a route is indirect or the service is overloaded. An overseas service can feel acceptable when requests are cacheable, asynchronous or rarely interactive.

Microsoft’s dated Azure measurements provide a useful scale, not a promise for the public internet. Its internal region-to-region P50 table showed Australia East to New Zealand North at about 28 ms, West US at about 140 ms, Central US at about 176 ms and East US at about 202 ms when accessed on 2 September 2026. Those figures are Azure network examples; they are not an Ozlin benchmark or an end-user ISP measurement. Test the actual application from the cities and access networks that matter. See Azure network round-trip latency statistics.

Workload or personaUsually favours local AU/NZOverseas can make sense whenMeasure before committing
Authoritative multiplayer game, voice or remote desktopInteraction is delay-sensitive and users are concentrated locallyThe audience is mostly overseas, or a regional edge/relay architecture is provenRTT, jitter, loss, tick/encode delay and peak-hour routes
Chatty database, API or internal business appUsers, app and database can be kept near each otherProcessing is batch-based or dependencies already live overseasEnd-to-end transaction time, not ping alone
Public website or download originAdmins and local origin traffic benefit; local support may helpA CDN serves most static objects and origin traffic is modestCache-hit ratio, dynamic TTFB, origin egress and cache-miss latency
Backup, archive or asynchronous jobLocal restore speed and jurisdiction may matterRestore time tolerates distance and the overseas price includes sufficient egressFull restore time, retrieval/egress fee and exit test
Personal lab or low-stakes serviceSimpler support and lower delay are usefulBudget dominates and downtime or delay is tolerableTotal monthly bill, backup independence and cancellation terms
SME or regulated workloadContract, support, data flows and recovery can be easier to inspectOverseas controls and terms satisfy the documented risk assessmentData map, subprocessors, incident process, SLA and exit plan
A matrix places interactive workloads toward the low-latency end and asynchronous workloads toward the price-flexible end, with measurement checkpoints alongside.

Explanatory model: workload interaction and risk should lead the location choice; the body table contains the equivalent information.

A CDN is helpful but not magical. It can cache static pages, images, packages and downloads near users. It cannot remove the latency of uncached origin requests, dynamic APIs, a remote database, an authoritative game server, most game UDP traffic or a support workflow that must reach the origin. It also does not remove cross-border privacy and contract questions.

Why local capacity can cost more

It is safer to treat the price gap as a multi-factor market outcome, not a universal rule. Large US and European markets may offer greater provider density and scale. AU/NZ services can face different facility, power, staffing, hardware-logistics, domestic-backhaul and international-connectivity economics. Provider support, DDoS mitigation, route quality, product tier and included transfer can outweigh geography.

Peering and transit illustrate part of the network cost. The ACCC’s interconnection overview distinguishes direct interconnection, often settlement-free peering, from paid transit that reaches networks indirectly. IX Australia and NZIX describe local exchange services designed to reduce longer transit paths and improve connectivity. These sources support the mechanism, not a claim that every local provider has the same cost or route quality.

Submarine systems are another dependency, but cable distance is not a retail price formula. The ACMA overview of cables landing in Australia explains the regulatory and infrastructure context. The final route still depends on carriers, interconnection and failures. Ask for measurements and contractual inclusions rather than inferring quality from a map.

Current product pages also show why words are dangerous. The Azure page titled “Bandwidth pricing” principally describes data transfer and egress charging. OVHcloud’s Sydney data-centre page describes product-specific outbound quotas, monthly resets and conditions after the quota. These are dated examples accessed on 2 September 2026, not evergreen price comparisons. Read the exact order form and service terms.

“Bandwidth” may mean speed, traffic or a billing method

Technically, bandwidth is a rate or capacity, normally expressed in bits per second. Commercial pages sometimes use the same word for monthly data transfer. Never accept a quote with only “1 Gbps bandwidth” or “25 TB bandwidth.” Require these four columns:

Quote fieldUnitWhat it answersExample question
Port speedMbps or GbpsMaximum physical or configured rateIs 1 Gbps dedicated, shaped, shared or only a burst ceiling?
Committed or guaranteed rateMbps or GbpsCapacity included or contractually committedIs 100 Mbps a CIR, a minimum bill, or a best-effort target?
Monthly transfer allowanceGB or decimal TB per monthVolume included during the billing periodIs 25 TB counted on egress only, ingress plus egress, or the larger direction?
Overage formula$/GB, $/Mbps at p95, fixed upgrade or shapingWhat happens above the allowance or commitIs traffic charged, capped, throttled or upgraded automatically?

Also define ingress (traffic entering the service) and egress (traffic leaving it). Providers may count only egress, both directions, the sum, or the larger direction. “Unmetered” normally means no volume counter, not infinite performance: port rate, fair-use policy, acceptable-use policy, congestion and mitigation conditions can still apply.

Four quote cards separate port speed, committed rate, monthly transfer and overage, with ingress and egress directions explicitly labelled.

Explanatory model: normalise every quote into four fields. The table above supplies the same comparison in text.

Convert Mbps to monthly transfer

Using decimal units:

TB = Mbps × seconds ÷ 8,000,000

For a 30-day month:

TB = Mbps × 0.324

The reverse estimate is:

average Mbps = TB × 3.08641975

Therefore, a sustained 100 Mbps for 30 days is exactly 32,400,000,000,000 bytes: 32.4 decimal TB, or approximately 29.47 binary TiB. A sustained 1 Gbps is 324 TB. A 25 TB allowance on a 1 Gbps port can be consumed in about 55.6 hours at the theoretical line rate. Real payload results differ because of protocol overhead, shaping, sampling and traffic variation.

A 31-day month changes the factor to 0.3348. Decimal TB is 10^12 bytes; TiB is 2^40 bytes. A contract that says “TB” should state which convention applies.

Monthly transfer, fixed/unmetered or 95th percentile?

Monthly transfer or per-GB egress is usually easiest to understand. It often suits personal users, small sites, low total volume and buyers without traffic history. Its weakness is burst anxiety: a release, restore, attack or cache purge may consume a large allowance quickly.

Fixed-rate or unmetered capacity suits sustained throughput and budget certainty when the guaranteed rate is sufficient. Confirm whether the port is dedicated, shared or best-effort and whether an AUP, fair-use rule or international-traffic class changes the result.

95th-percentile billing prices a measured traffic rate while forgiving the highest fraction of samples. Equinix’s published example samples every five minutes. A 30-day month contains 8,640 samples; discarding the highest 5% removes 432 samples, and the next selected value is the p95 result. See Equinix Internet Access pricing and billing.

Two idealised patterns show why equal monthly volume can produce a different p95 bill:

PatternFive-minute samplesAverage / 30-day volumeIdealised p95
A: flat8,640 at 100 Mbps100 Mbps / 32.4 TB100 Mbps
B: short bursts8,208 at 60 Mbps; 432 at 860 Mbps100 Mbps / 32.4 TB60 Mbps

Pattern B has 95% at 60 Mbps and 5% at 860 Mbps. It has the same average and volume because 0.95 × 60 + 0.05 × 860 = 100. Under the stated selection convention, its top 432 samples are discarded. This is a teaching model, not a vendor invoice. Cloudflare’s WAN measurement documentation also uses five-minute samples and discards the top 5%, but its treatment of directions and aggregation demonstrates why the algorithm must be contractual.

Two traffic traces contain the same monthly volume: a flat 100 Mbps line bills at p95 100, while short 860 Mbps bursts above a 60 Mbps baseline yield an idealised p95 of 60.

Explanatory model: equal volume does not mean equal p95. The numbers and assumptions are reproduced in the adjacent table.

Ask how inbound and outbound samples are combined: maximum direction, sum, or separate billable values. Ask about sampling interval, missing samples, rounding, committed minimum, overage rate, burst cap and whether DDoS or mitigation traffic is excluded. A sustained busy period can make p95 expensive; short peaks can make it attractive. No model is universally cheapest.

For an enterprise or colocation buyer with monitoring, price each candidate against at least 12 months of five-minute traffic, including the busiest incident month. For a new personal or SME service with no history, start with a capped or quota product, collect measurements, then compare alternatives.

Australia: privacy and contract checks

Server location is not a compliance switch. First determine whether the Privacy Act and Australian Privacy Principles apply. The OAIC says many small businesses with annual turnover of A$3 million or less are generally not covered, but important exceptions apply; do not assume exemption from turnover alone. See the OAIC small-business guidance.

For an APP entity disclosing personal information to an overseas recipient, APP 8 guidance describes reasonable steps and potential accountability under section 16C, subject to exceptions. The OAIC also distinguishes disclosure from limited situations where an overseas cloud contractor remains under the entity’s effective control. Facility country, provider domicile, administrator access, subprocessors, logs, backups and deletion rights all matter.

Covered entities must also assess incidents under the Notifiable Data Breaches scheme, including whether an eligible breach is likely to result in serious harm. An overseas provider does not take that assessment away.

Consumer-law protections can overlap with business purchasing. The ACCC consumer-guarantees guidance notes that a business may be a consumer for some purchases, including goods or services under A$100,000 (including GST), subject to the statutory tests and exceptions. The ACCC contracts guidance explains that unfair-contract-term protections can cover a standard-form small-business contract made or renewed from 9 November 2023 where at least one party has fewer than 100 employees or turnover below A$10 million. Exact application needs advice.

New Zealand: overseas disclosure and trading terms

Information Privacy Principle 12 limits disclosure outside New Zealand unless a specified basis exists, including comparable safeguards in relevant cases. The Privacy Commissioner also explains an important distinction in guidance on sending information overseas: using an overseas cloud provider as an agent for storage or processing can be treated differently from disclosure to a foreign third party. Map the actual roles, access and purposes rather than relying on the rack location.

Where a privacy breach is likely to cause serious harm, the New Zealand Privacy Commissioner’s NotifyUs guidance covers notification to the Commissioner and affected people. Hosting offshore does not transfer the New Zealand agency’s responsibility.

The Consumer Guarantees Act guidance explains consumer guarantees for personal or household goods and services. Businesses can contract out only when both parties are in trade, the agreement is in writing, and contracting out is fair and reasonable. The Commerce Commission’s business-rights guidance describes unfair-term protections for standard-form small trade contracts with a trading relationship up to NZ$250,000 in a 12-month period. These rules are not resolved by choosing Auckland, Sydney, Virginia or Frankfurt.

There is no single rule requiring every Australian or New Zealand workload to stay onshore. Government, health, financial, contractual or sector-specific requirements may impose stricter controls. Data residency, sovereignty, governing law, support access and replicated copies are different questions. Equally, putting a server in the US or EU does not by itself establish whether the GDPR applies; that depends on the relevant legal scope and processing, not merely the server’s postcode.

The Australian Cyber Security Centre’s cloud shared-responsibility guidance is a useful operational reminder: the customer retains responsibilities for data, access, configuration, backups and incident response even when infrastructure is outsourced.

Put “local” and the contract under a microscope

A six-layer checklist separates facility, supplier jurisdiction, data controller, administrator access, replicas and subprocessors, then routes the buyer to contract and exit checks.

Explanatory model: “local” has several layers. It does not prove legal compliance or depict an Ozlin/customer architecture.

Before accepting a quote, record:

  • facility city and country, provider contracting entity and governing law;
  • user, origin, database, identity service and third-party dependency locations;
  • support/admin access countries, subprocessors, replicas, logs and backups;
  • port rate, committed/guaranteed rate, included transfer, counted direction and overage;
  • p95 interval, direction rule, commit, burst cap, rounding and DDoS treatment;
  • local versus international traffic classes, peering claims and route-test period;
  • currency, GST/tax treatment, setup, renewal, minimum term and termination fees;
  • uptime and support SLA, exclusions, service credits and remote-hands charges;
  • security responsibilities, incident notice, backup ownership and restore testing;
  • data return, deletion evidence, export format, IP-address portability and exit assistance.

A practical decision path

  1. Classify the interaction. If milliseconds and jitter change the product, shortlist local regions first. If work is static or asynchronous, include overseas options.
  2. Map every dependency and copy. “Sydney compute” is not a local system if its database, support access and backups sit elsewhere.
  3. Normalise the quote. Force the four traffic columns and itemise addresses, support, storage, backup and exit costs.
  4. Measure. Test representative ISPs and cities at peak times; measure transactions, jitter/loss and restore time, not a provider’s nearest ping target.
  5. Model normal and incident months. Compare transfer, fixed/unmetered and p95 using real five-minute data where available.
  6. Review legal and contract fit. Separate privacy applicability, cross-border processing, consumer/small-business protections and sector requirements.
  7. Pilot and preserve an exit. Use production-like traffic without unnecessary personal data, then document backups, rollback and portability.

The short answer is: choose local AU/NZ hosting when interaction, recovery, support or documented data controls justify it; choose US/EU hosting when latency is tolerable and the full contract and data flow make the lower price worthwhile. For traffic, start with monthly transfer when simplicity matters, fixed/unmetered when sustained throughput and budget certainty dominate, and 95th percentile when you have measured low baselines with short peaks and can manage variable billing.

Sources and review record

Sources were accessed on 29 August 2026. Prices and regional availability are scheduled for review by 29 November 2026.

AI assisted with source discovery, drafting and copyediting; Ozlin Info remains responsible for publication.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *


This site uses Akismet to reduce spam. Learn how your comment data is processed.