Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
United Arab EmiratesChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Waking up
In one paragraph
The national privacy law has been in force since January 2022, but the rules that make it work were never written, so almost none of it can be enforced. Meanwhile the industries that matter have hard walls: health records, payment data, insurance data and identity-check reports must stay inside the country. Two financial districts run their own separate privacy systems, and those regulators do issue penalties.
The catch
The relaxed national picture is false the moment you touch health, payments, insurance, credit and identity checks, or government data. The national law expressly does not cover health data, banking data, government data, or companies inside the financial free zones. For most regulated businesses the national law is not the rule that binds them.
Does this apply to me?
Yes. The national privacy law reaches a company with no office in the country, as long as it handles the personal data of people inside the country. There is no revenue or headcount threshold to hide under. But the law carves out huge areas: government bodies, government data, health data, banking and credit data, and companies inside the financial free zones that have their own privacy laws.High confidence
Can the data leave the country?
It depends entirely on your industry. Under the national law data can leave once you have the right paperwork, and in practice nobody is checking. But four industries have real walls. Health records may not be stored or sent abroad at all. Payment data must be stored inside the country. Insurance data must be stored inside the country. And since April 2026 the national identity-check report may not be taken out of the country at all.High confidence
What do I have to do to send it abroad?
On paper the model is an approved-destinations list. The regulator is supposed to name countries whose protection is good enough, and no list has ever been published. So in practice everyone uses the fallback route: a contract with the recipient promising equivalent protection, or the person's explicit consent, or a narrow necessity exception. No government permission is needed and no filing is made, because the rules that would create those steps were never written.High confidence
Who enforces this — and are they actually working?
On paper the UAE Data Office. In practice it has never enforced anything: it has no public website, it has published no approved-destinations list, and the government decision that would set the fines has not been made. The regulators that really bite are elsewhere — the central bank fined a foreign bank branch about 5.4 million dollars in June 2026, and the data protection commissioner in the Abu Dhabi financial district has issued published penalty notices.Medium confidence
How long must I keep it, and when must I delete it?
The floors are long and they are set by industry, not by the privacy law. Health records must be kept for at least 25 years after the last treatment. Payment data must be kept for 5 years with a separate backup. Identity-check reports must be kept for at least 5 years. There is no working national deletion deadline, because the detailed rules that would set one were never issued.High confidence
What happens when something goes wrong?
There is no national deadline in hours today. The privacy law says you must tell the regulator as soon as you discover a breach, and leaves the actual timing and the wording of the notice to detailed rules that were never issued. So the clocks that really run are the ones set by your own regulator: the central bank for financial firms, and the separate data protection offices in the two financial districts. The national cyber incident reporting service is aimed at government bodies, not at private companies.Medium confidence
What's the trap?
Five things that cost people their weekend. One: the national privacy law does not cover health data, banking data, government data, or companies in the financial free zones, so most regulated firms are not governed by it at all. Two: health data may not leave the country, ever, and the fine is up to about 190 thousand dollars. Three: since April 2026 the national identity-check report may not be sent abroad. Four: a child is anyone under 18, but the parental consent line is drawn at 13. Five: there are two extra legal systems inside the country, and their regulators actually issue penalties.High confidence
What's about to change?
The single biggest thing is a rule that could appear on any Tuesday. When the government finally publishes the detailed rules under the privacy law, every company gets six months to comply and the law switches from decorative to real. Nothing signals when that will happen. In the meantime the new child safety law needs its penalty schedule, and the national identity-check platform is being rolled out across banks.Medium confidence
Hardest industry wall
  • Health and social care Federal Law No. (2) of 2019 Concerning the Use of the Information and Communications Technology in Health Fields
  • Payments Retail Payment Services and Card Schemes Regulation
  • Insurance Insurance Authority Board of Directors' Resolution No. (18) of 2020 Concerning the Electronic Insurance Regulations
  • Banking Cabinet Resolution No. (55) of 2026 Promulgating the Executive Regulations of Federal Decree-Law No. (30) of 2024 Regarding the "Know Your Customer" Digital Platform
South KoreaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
In one paragraph
South Korea's privacy law bans sending personal data abroad unless you have one of five grounds. The usual one is a separate consent, ticked apart from every other consent. Since September 2025 the 30 European countries need no extra paperwork. But banking, health records, government cloud and detailed maps have hard walls no consent can unlock, and the regulator fines foreign companies often.
The catch
The 'get consent and send it' headline stops being true the moment you touch six areas: bank and payment systems, financial customers' national ID numbers, hospital records, government cloud, detailed mapping data, and personal location services. In those areas the data or the machine holding it must physically sit in South Korea, and in the government cloud case so must the people who run it.
Does this apply to me?
Yes. The regulator fines companies with no Korean office. In July 2026 it fined TikTok's Singapore company and two Apple companies based in Ireland and Singapore for collecting Korean users' data and sending it abroad without a proper legal basis. If your worldwide revenue was 1 trillion won (about $720 million) or more last year, or you held data on an average of 1 million or more people in Korea per day over the last three months of last year, you must appoint a representative in Korea. Since April 2026, if you already own or control a Korean company, that Korean company has to be the representative.High confidence
Can the data leave the country?
In general yes, but only if you have one of five grounds, and the usual one is a separate consent that the person ticks apart from every other consent. Since September 2025 you can also send data to the 27 European Union countries plus Norway, Iceland and Liechtenstein with no extra step at all, because the regulator has formally accepted their protection as equal to Korea's. That is the only such list, and no other country is on it. Six industries override all of this and are covered below.High confidence
What do I have to do to send it abroad?
Korea does not police the destination. It polices your paperwork. There is no banned-country list and no approval application to file: you pick one of the five grounds, and for most companies that means asking each person for a separate transfer consent that lists what goes, where, to whom, for how long and how to refuse. The one destination list that exists is a positive one, and it holds exactly 30 countries: the European Union plus Norway, Iceland and Liechtenstein. Send data anywhere else and you also have to keep security measures, a complaints route and a dispute process in place, and write the transfer into your contract with the recipient.High confidence
Who enforces this — and are they actually working?
The Personal Information Protection Commission, chaired by Song Kyoung-hee, and it is one of the busiest privacy regulators in the world right now. In July 2026 alone it fined the telecoms company KT about 54 billion won (roughly $39 million) over a data breach, fined TikTok about 10.3 billion won (roughly $7.4 million) and Apple about 252 million won (roughly $180,000). It referred KT to prosecutors for obstructing the investigation and asked police to investigate LG U+ for destroying a server before the inquiry started. Finance is separately policed by the Financial Services Commission and the Financial Supervisory Service; health by the health ministry; maps by an inter-agency committee that includes the intelligence service.High confidence
How long must I keep it, and when must I delete it?
Two forces pull in opposite directions. The ceiling: you must destroy personal data without delay once you no longer need it, and destroy it so it cannot be recovered. The floor: other laws make you keep things. An online seller must keep advertising records for 6 months, complaint and dispute records for 3 years, and contract, cancellation, payment and delivery records for 5 years. Almost everyone must keep system access logs for at least 1 year, and 2 years if the system holds data on 50,000 or more people, holds national ID numbers or sensitive data, or belongs to a licensed telecoms carrier. When the two clash, the keeping rule wins, but you must store that data separately from everything else.High confidence
What happens when something goes wrong?
Count two clocks, and in telecoms and finance a third. Under the privacy law you have 72 hours to tell the affected people, and a separate 72 hours to report to the Commission or to the Korea Internet and Security Agency. The reporting clock starts if 1,000 or more people are affected, or if any sensitive data or national ID numbers leaked, or if the cause was someone breaking in from outside. Separately, an internet service provider must report a cyber incident to the science ministry or the same agency immediately. A hospital must also tell the health ministry about a medical-records incident.High confidence
What's the trap?
Five things that will cost you a weekend. One: the children's age line is 14, not 13 or 16, and processing an under-14's data without a parent's consent is a crime punishable by up to five years in prison, not just a fine. Two: hiding or destroying material during a regulator's inspection is itself a crime, and the regulator used it in July 2026. Three: stripping names out of a dataset does not free it. Four: a bank's Korean customers' national ID numbers may not leave the country at all, and any offshore processing of customers' financial transaction data needs a report to the supervisor 30 business days before work starts. Five: if you want to run a personal location service you must be a corporation and be registered, so you cannot serve Korea from abroad with no entity.High confidence
What's about to change?
The privacy regulator started rewriting the rulebook for artificial intelligence. It set up a reform task force on 30 July 2026, ran a public suggestion window from 6 to 31 August 2026, and plans to publish the direction of reform before the end of 2026. Consent-based rules and the block on sending pseudonymised data abroad for research are both explicitly on the table. Separately, Apple's request to export detailed Korean map data has been pending since its deadline was extended in December 2025, and Google's equivalent request was granted in February 2026 on strict conditions, so the mapping picture can move again at any time.High confidence
Hardest industry wall
  • Banking 전자금융감독규정 (Regulation on Supervision of Electronic Financial Transactions)
  • Finance 금융회사의 정보처리 업무 위탁에 관한 규정 (Regulation on Outsourcing of Data Processing Business by Financial Companies)
  • Health and social care 전자의무기록의 관리·보존에 필요한 시설과 장비에 관한 기준 (Standards for the Facilities and Equipment Required to Manage and Preserve Electronic Medical Records)
  • Government 클라우드컴퓨팅서비스 보안인증에 관한 고시 (Notice on Security Certification of Cloud Computing Services)
  • Mapping and location 공간정보의 구축 및 관리 등에 관한 법률 (Act on the Establishment and Management of Spatial Data)