Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
ArmeniaChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Dormant
In one paragraph
Armenia lets personal data leave, but only to a country on an official approved list of 53 states, or with case-by-case permission from the privacy regulator. That regulator has had no boss since February 2026 and the largest fine it can impose is about 1,300 US dollars. The real constraints are elsewhere: government data sent to a foreign cloud must keep a backup copy inside Armenia, and banking and medical secrecy sit outside the privacy law entirely.
The catch
The approved-country list is worthless in three places. Government bodies must keep an in-country backup of anything they put in a cloud abroad. Bank, notarial, lawyer and insurance secrets are carved out of the privacy law and are governed by their own secrecy statutes, which list exhaustively who may see the data and do not mention foreign cloud providers. And leaking medical secrets is a crime that can put a named individual in prison, not just a fine on the company.
Does this apply to me?
Probably not, if you have nothing in Armenia. The privacy law describes who it covers by naming Armenian public bodies, companies and individuals who process personal data. It contains no clause saying it follows Armenians' data abroad, and no rule requiring a foreign company to appoint someone inside Armenia. There is no size or revenue threshold either, so a one-person Armenian business is caught exactly like a bank.Medium confidence
Can the data leave the country?
Yes, with paperwork. Armenia runs an approved-country list: if the destination is on it, you can send data with no permission from anyone. The list is real and populated — 53 countries, including all of the European Union, the United Kingdom, Canada, Japan, South Korea, Israel, Georgia and Russia. Sending data anywhere else needs written permission from the privacy regulator first, and that regulator currently has nobody in the chair. Three sectors override this entirely: government, banking-type secrets, and health.High confidence
What do I have to do to send it abroad?
The model is an approved list, and the list is full. Fifty-three countries were approved on 8 July 2024 and that decision has never been changed. If your destination is on it you need nothing — no standard contract, no filing, no fee. If it is not on it, you must write to the regulator before you send anything, attach the contract you plan to sign, and wait up to 30 days for a yes or a no.High confidence
Who enforces this — and are they actually working?
On paper, the Personal Data Protection Agency inside the Ministry of Justice. In practice, nobody right now: its head resigned with effect from 24 February 2026 and no replacement appointment has been published. In more than eleven years the agency has published exactly one general decision — the approved-country list. Two other regulators are genuinely working: the Central Bank supervises banks, payment firms, insurers and securities, and a brand-new Information Systems Regulatory Commission was appointed in March and April 2026 to police cybersecurity and state computer systems.Medium confidence
How long must I keep it, and when must I delete it?
The floor is five years for anything that proves your tax position. The ceiling is not a number — it is a principle: you must destroy or block personal data as soon as you no longer need it for the purpose you collected it for. Two hard clocks sit inside that principle. If someone withdraws consent you have ten working days to destroy their data, then three more working days to tell them you did. If you spot unlawful processing you have three working days to fix it or destroy the data.High confidence
What happens when something goes wrong?
Count three clocks. Under the privacy law, if data leaks out of your electronic systems you must immediately publish a public announcement about it and at the same time tell the Armenian police and the privacy regulator — there is no grace period and no threshold. If you run a system in a sector the state calls vital, you have 24 hours to tell the cybersecurity regulator, 72 hours to send an update, two days to warn the people affected, and one month to file a final report. Both sets of duties can bite at once.High confidence
What's the trap?
Five things that will ruin your week. One: a data leak must be announced publicly and reported to the police, not just to the regulator. Two: encryption is legally compulsory, not a best practice, and failing to use it is its own separate fine. Three: before you process biometric or sensitive data you must notify the regulator in advance and wait to be entered in its register. Four: to process a dead person's data you need the consent of all of their legal heirs. Five: a child is anyone under 16 here, not 13 and not 18.High confidence
What's about to change?
Armenia rewired its digital rulebook in December 2025 and the deadlines land through 2026, 2027 and 2028. Rules for cyber incidents and for state computer systems are already live. Detailed technical rules are due by January 2027, internal cybersecurity policies and risk assessments by July 2027, and security certificates for critical systems by January 2028. The change most likely to catch someone out is not a new law at all: the approved-country list can be rewritten by one official's signature.High confidence
Hardest industry wall
  • Government «Ամպայինն առաջինը» քաղաքականության մշակման և ներդրման մասին ՀՀ կառավարության որոշում
AustriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
In one paragraph
Austria does not require personal data to be kept in Austria, and we found no Austrian industry that does. Data can leave once the right paperwork is in place under European rules. What Austria adds is a secrecy layer: a constitutional right to data secrecy, a staff secrecy duty, an extra fine of up to 50,000 euros (about $58,000), and a prison offence of up to one year.
The catch
"No local storage needed" is true. "Nothing extra to do" is not. Austria's real cost sits in the secrecy layer, not in a map. A standard supplier data agreement does not satisfy Austrian data secrecy on its own, a child can consent at fourteen rather than sixteen, and misusing data you learned at work is a criminal matter in Austria, not just a fine. Health data also moves only inside a closed, encrypted Austrian health network, which in practice narrows your supplier list even though no law names a country.
Does this apply to me?
Yes. A company with no office in Austria is still caught if it offers goods or services to people in Austria, or watches what they do online. There is no size or revenue floor to duck under. If you have no establishment anywhere in the European Union, you must name a representative inside the Union in writing. Austria does not add a second, Austria-only representative on top of that.High confidence
Can the data leave the country?
Yes, with paperwork. We looked for an Austrian rule forcing data to stay in Austria and found none — not in banking, payments, insurance, securities, health, telecoms, government or mapping. Austrian health data is the closest thing to a wall, but it is a technical wall, not a geographic one: findings move only inside a closed, encrypted Austrian health network between registered care providers. Checked on 18 August 2026.Medium confidence
What do I have to do to send it abroad?
The model is an approved-destination list. Sending data outside Europe is fine if the destination is on the European Commission's approved list. If it is not, you sign the European standard contract, or use approved group-wide rules, and you write down a short risk assessment first. You do not need permission from the Austrian regulator. Its own words: apart from a few special cases, international data traffic needs no approval.High confidence
Who enforces this — and are they actually working?
The Austrian Data Protection Authority, and it is genuinely working. It has had a permanent head, Matthias Schmidl, since 1 January 2024, a deputy, and five departments. It issues decisions, and on 24 June 2026 Austria's highest administrative court confirmed a 13 million euro fine (about $15 million) for building political-opinion profiles on around 2.2 million people. The court held the fine is measured against the whole group's turnover, not one product line.High confidence
How long must I keep it, and when must I delete it?
There is a ceiling and a floor, and they pull against each other. The ceiling is European: keep personal data no longer than you need it, then delete it. The floor is Austrian tax and company law, which makes you keep books, invoices and business records for years after the year they relate to. Where the two clash, the keeping duty wins for as long as it runs, and the data must then be deleted.Medium confidence
What happens when something goes wrong?
Count at least two clocks, sometimes four. For a personal data breach you tell the Austrian Data Protection Authority without delay and if possible within 72 hours, and if you are late you must explain in writing why. If you run an essential service you also report significant incidents to Austria's network security authority. Banks and insurers report separately under European financial rules, and telecom operators have their own duty.High confidence
What's the trap?
Five that cost people their weekend. A child can consent at fourteen in Austria, not sixteen. Misusing data you only learned about through your job is a crime punishable by up to a year in prison. There is a second, separate Austrian fine of up to 50,000 euros (about $58,000) for breaking data secrecy or running a camera unlawfully. Austrian public bodies cannot be fined at all, but you still can. And the law tells the regulator to warn first, which is not the same as forgiveness.High confidence
What's about to change?
Three things to watch. Austria's Constitutional Court is deciding whether the state may plant software on a phone to read messages; it heard the case on 22 June 2026 and has not ruled. Austria has still not written the new European cybersecurity rules into national law, so that expansion is still ahead of you. And from 12 January 2027, cloud providers across Europe may no longer charge you to move your data out.High confidence
Hardest industry wall
None found.