Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
ArmeniaChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Dormant
- In one paragraph
- Armenia lets personal data leave, but only to a country on an official approved list of 53 states, or with case-by-case permission from the privacy regulator. That regulator has had no boss since February 2026 and the largest fine it can impose is about 1,300 US dollars. The real constraints are elsewhere: government data sent to a foreign cloud must keep a backup copy inside Armenia, and banking and medical secrecy sit outside the privacy law entirely.
- The catch
- The approved-country list is worthless in three places. Government bodies must keep an in-country backup of anything they put in a cloud abroad. Bank, notarial, lawyer and insurance secrets are carved out of the privacy law and are governed by their own secrecy statutes, which list exhaustively who may see the data and do not mention foreign cloud providers. And leaking medical secrets is a crime that can put a named individual in prison, not just a fine on the company.
- Does this apply to me?
- Probably not, if you have nothing in Armenia. The privacy law describes who it covers by naming Armenian public bodies, companies and individuals who process personal data. It contains no clause saying it follows Armenians' data abroad, and no rule requiring a foreign company to appoint someone inside Armenia. There is no size or revenue threshold either, so a one-person Armenian business is caught exactly like a bank.Medium confidence
- Can the data leave the country?
- Yes, with paperwork. Armenia runs an approved-country list: if the destination is on it, you can send data with no permission from anyone. The list is real and populated — 53 countries, including all of the European Union, the United Kingdom, Canada, Japan, South Korea, Israel, Georgia and Russia. Sending data anywhere else needs written permission from the privacy regulator first, and that regulator currently has nobody in the chair. Three sectors override this entirely: government, banking-type secrets, and health.High confidence
- What do I have to do to send it abroad?
- The model is an approved list, and the list is full. Fifty-three countries were approved on 8 July 2024 and that decision has never been changed. If your destination is on it you need nothing — no standard contract, no filing, no fee. If it is not on it, you must write to the regulator before you send anything, attach the contract you plan to sign, and wait up to 30 days for a yes or a no.High confidence
- Who enforces this — and are they actually working?
- On paper, the Personal Data Protection Agency inside the Ministry of Justice. In practice, nobody right now: its head resigned with effect from 24 February 2026 and no replacement appointment has been published. In more than eleven years the agency has published exactly one general decision — the approved-country list. Two other regulators are genuinely working: the Central Bank supervises banks, payment firms, insurers and securities, and a brand-new Information Systems Regulatory Commission was appointed in March and April 2026 to police cybersecurity and state computer systems.Medium confidence
- How long must I keep it, and when must I delete it?
- The floor is five years for anything that proves your tax position. The ceiling is not a number — it is a principle: you must destroy or block personal data as soon as you no longer need it for the purpose you collected it for. Two hard clocks sit inside that principle. If someone withdraws consent you have ten working days to destroy their data, then three more working days to tell them you did. If you spot unlawful processing you have three working days to fix it or destroy the data.High confidence
- What happens when something goes wrong?
- Count three clocks. Under the privacy law, if data leaks out of your electronic systems you must immediately publish a public announcement about it and at the same time tell the Armenian police and the privacy regulator — there is no grace period and no threshold. If you run a system in a sector the state calls vital, you have 24 hours to tell the cybersecurity regulator, 72 hours to send an update, two days to warn the people affected, and one month to file a final report. Both sets of duties can bite at once.High confidence
- What's the trap?
- Five things that will ruin your week. One: a data leak must be announced publicly and reported to the police, not just to the regulator. Two: encryption is legally compulsory, not a best practice, and failing to use it is its own separate fine. Three: before you process biometric or sensitive data you must notify the regulator in advance and wait to be entered in its register. Four: to process a dead person's data you need the consent of all of their legal heirs. Five: a child is anyone under 16 here, not 13 and not 18.High confidence
- What's about to change?
- Armenia rewired its digital rulebook in December 2025 and the deadlines land through 2026, 2027 and 2028. Rules for cyber incidents and for state computer systems are already live. Detailed technical rules are due by January 2027, internal cybersecurity policies and risk assessments by July 2027, and security certificates for critical systems by January 2028. The change most likely to catch someone out is not a new law at all: the approved-country list can be rewritten by one official's signature.High confidence
- Hardest industry wall
- Government — «Ամպայինն առաջինը» քաղաքականության մշակման և ներդրման մասին ՀՀ կառավարության որոշում
Saudi ArabiaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Saudi Arabia, but never for free. You need a purpose the law allows, a written safeguard such as the government's own standard contract, and a written risk assessment that asks whether the transfer could harm the Kingdom itself. Banks need the central bank's written permission before anything goes abroad. The privacy regulator is fully set up but publishes no fines.
- The catch
- The 'paperwork and you can send it' answer is true for an ordinary business. It is false for banks and finance companies, where the central bank must give written no-objection first and cloud is expected to sit inside the country. It is also unsettled for government bodies and critical national infrastructure: the old rule forcing them to host inside Saudi Arabia was deleted in 2024 and replaced by a duty to ask a government office for a decision, and that office has published no replacement rule.
- Does this apply to me?
- Yes. The law reaches a company anywhere in the world with no office in Saudi Arabia, as long as it handles the data of people living in the Kingdom. There is no size, revenue or headcount threshold to fall below. There is no general duty to appoint a local representative, but many organisations must register on the government's data platform and some must name a data protection officer.High confidence
- Can the data leave the country?
- Yes, with real paperwork. First the reason for sending it has to be on the government's short list of allowed purposes. Then you need a safeguard: the government's own standard contract, approved group-wide rules, or a certificate from a licensed body. Then you must write a risk assessment that includes whether the transfer could damage the Kingdom's vital interests. Two industries are much harder. Banks and finance companies must get the central bank's written no-objection before any data goes to an overseas supplier, and the central bank's rules say cloud services should sit inside Saudi Arabia unless it approves otherwise. For government bodies and critical national infrastructure the picture changed in 2024 and is now genuinely unclear.High confidence
- What do I have to do to send it abroad?
- The model is an approved-destination list, and the list is empty. The law says data may go to a country the regulator has judged good enough, but no such list has been published, so in practice nobody uses that route. Instead almost everyone relies on the escape hatches: sign the government's word-for-word standard contract, or get approved group-wide rules for a multinational, or send to a body holding a certificate from a licensed Saudi accreditation body. On top of that you must run a written risk assessment before the data moves.High confidence
- Who enforces this — and are they actually working?
- The Saudi Data and Artificial Intelligence Authority is the privacy regulator, and it is genuinely up and running. Its National Data Governance Platform is live and takes registrations, self-assessments, breach reports and complaints, and it has published the rulebook for the panels that hear violations and issue fines. What we could not find is a single published fine or named decision, so how hard it bites is still unknown. The financial regulator and the cybersecurity authority, by contrast, have supervised their sectors for years.Medium confidence
- How long must I keep it, and when must I delete it?
- Both directions apply, and the floor wins when they clash. The ceiling: you must destroy personal data without undue delay once the reason you collected it has gone, and also when someone asks, when they withdraw the only consent you relied on, or when you learn you processed it unlawfully. Destruction must reach backups too. The floor: your written record of processing activities must be kept for five years after the activity ends. If another law sets a keeping period, the law says keep the data until whichever is longer.High confidence
- What happens when something goes wrong?
- The main clock is 72 hours. If personal data is breached, lost or accessed unlawfully and that could harm the people involved, you must tell the privacy regulator within 72 hours of finding out, through the government's data platform — and you have to be registered on that platform before you can use the service. You must also tell the affected people without undue delay, in plain language. A second, separate clock runs for government bodies and critical national infrastructure, which owe cyber incident reports to the national cybersecurity authority under its own rules. Suppliers owe you notice without undue delay so you can meet your own deadline.High confidence
- What's the trap?
- Five things that are not in the summary. One: sending data abroad is not only about protecting the individual — you must also assess whether the transfer could harm the Kingdom's own vital interests, and there is a government guide telling you how. Two: the standard contract must be copied word for word, and changing it is itself a breach of the law, while the overseas recipient has to accept Saudi courts. Three: leaking or publishing sensitive data to hurt someone or to profit can put a person in prison for up to two years — this is a criminal charge, not a fine. Four: your supplier contract must go beyond a normal data processing agreement and say whether the supplier is subject to foreign laws and how that affects its compliance. Five: the widely quoted rule that all government and critical infrastructure data must be hosted inside Saudi Arabia was deleted in 2024, and quoting it today is wrong.High confidence
- What's about to change?
- Nothing is scheduled to commence on a fixed date in the next twelve months — the law and all its main regulations are already fully in force. The risk is the opposite kind: several switches the government already holds and can flip with no consultation. The biggest is the approved-country list, which the regulator is legally required to publish and has not; the day it appears, every transfer plan in the country needs rechecking. The second biggest is the missing localisation rule for government and critical infrastructure, which one office was handed in 2024 and has not yet written.Medium confidence
- Hardest industry wall
- None found.