Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
ArgentinaChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Active
- In one paragraph
- Argentina lets personal data leave the country, but only on paper terms it sets. You either send it to a country the regulator has approved, or you sign the regulator's own model contract with the receiver. No industry has to keep data inside Argentina. Fines are tiny in dollars, but the regulator can order a database shut down, and some misuse is a crime.
- The catch
- There is no data-residency wall in Argentina, but four sector rules still catch people out. Banks and payment firms must run their technology and security management from inside Argentina, must tell the banking supervisor before they outsource, and must report a cyber incident within one hour. Government bodies must have a working backup data centre by late 2026. And nobody may publish a map showing Argentine territory without the national mapping agency's prior approval.
- Does this apply to me?
- The main privacy law is Ley 25.326, passed in 2000. It covers personal data held in any file or database in Argentina, public or private. There is no size threshold, no revenue threshold, and no duty to appoint a local representative. The law does not clearly say it reaches a foreign company with no presence in Argentina, and in practice the regulator has acted against local subsidiaries of global firms rather than against foreign entities directly.High confidence
- Can the data leave the country?
- Yes, with paperwork. The rule is that personal data may not go to a country that does not protect it well enough. The regulator publishes a list of countries it accepts, and for everywhere else you sign its model contract with the receiver. We looked for industries that must keep data inside Argentina - banking, payments, insurance, securities, health, telecoms, government cloud and mapping - and found none as of 18 August 2026.High confidence
- What do I have to do to send it abroad?
- The model is an approved-destinations list, and it is populated today with about a dozen places, including the whole European Union. If your destination is not on it, use the regulator's published model contract - two versions, one for handing data to another company that decides how to use it and one for a supplier processing it for you. Using the published wording needs no permission. If you change the wording, you must file the contract with the regulator within 30 days of signing.High confidence
- Who enforces this — and are they actually working?
- The Agency for Access to Public Information, known by its Spanish initials AAIP, enforces both privacy and freedom of information. It is real and working: it has a named head, it publishes a register of final penalties that was updated on 3 July 2026, it opened a public investigation into debt-collection calls in April 2026, and it chaired an international data-protection committee in July 2026. Its 244 final penalties are mostly small, and more than half are for calling people on the do-not-call list.High confidence
- How long must I keep it, and when must I delete it?
- Argentina has strong floors and one hard ceiling. Anti-money-laundering rules make banks, insurers, crypto firms, accountants and estate agents keep transaction records and customer files for at least ten years. Clinical records must be kept ten years from the last entry. Banks must keep audit and accounting support data six years and produce it immediately on demand. The ceiling: credit-reporting data may only show the last five years, dropping to two years once the debt is paid.High confidence
- What happens when something goes wrong?
- There is no general duty to report a data breach in Argentina, checked on 18 August 2026 - the privacy law has no deadline and the regulator's security rules are recommendations, not commands. Finance is the exception and the clock is brutal: banks and registered payment firms must tell the banking supervisor within one hour of an incident happening or being spotted, keep sending updates, and file a closing report within five days.High confidence
- What's the trap?
- Five things bite people. Answer times are very short: ten days for an access request and five working days to correct or delete. The maximum fine is one hundred thousand pesos, about seventy US dollars, so the real risk is a shutdown order or a criminal case, not the fine. Databases still have to be registered. Publishing a map of Argentina needs government approval first. And a bank cannot run its technology and security management from abroad.High confidence
- What's about to change?
- Nothing is scheduled to replace the privacy law. A reform bill went to Congress in 2023 and never became law; the regulator is still campaigning for a new one. The dated thing to watch is government cybersecurity: public bodies have about 180 days from 13 May 2026 to have contingency plans and a working alternative data centre, which lands around November 2026, and a new national cybersecurity centre started issuing rules in 2026.Medium confidence
- Hardest industry wall
- None found.
ThailandChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Thailand does not make you keep personal data inside the country, but data cannot leave until you have picked and documented a legal route. The regulator never published a list of approved destination countries, so consent and written safeguards do all the work. A foreign company selling into Thailand needs a named representative living there. Getting it wrong can mean fines, double damages, and in the worst cases jail.
- The catch
- The permissive headline is about residency only. The burden is high and the pain is elsewhere: a person in Thailand who answers for you personally, parental consent for anyone under twenty in many cases, 90-day traffic logs that catch any business offering guest wi-fi, compensation owed even when you were not careless, and a technology-crime regime that forces banks and telecoms companies to hand customer data into a government-run exchange. Payments, government workloads and digital platforms each add their own regulator gate on top.
- Does this apply to me?
- Yes. The privacy law reaches a company with no office in Thailand if it offers goods or services to people who are in Thailand, or if it tracks what those people do. Payment is irrelevant — a free service counts. There is no revenue or headcount floor to fall below. A foreign company caught this way must appoint, in writing, a representative who is physically in Thailand and who can be held answerable with no cap on liability.High confidence
- Can the data leave the country?
- Yes, in most cases. Thailand does not make companies keep a copy of personal data inside the country. But data cannot simply leave: you must first have a legal route, and the regulator has never published a list of approved destination countries, so the 'this country is safe enough' route is unusable in practice. Everyone falls back on informed consent, contract necessity, approved group-wide rules, or their own written safeguards. Several industries add a second gate on top, described below.High confidence
- What do I have to do to send it abroad?
- There is no permission slip to apply for and no banned-country list. You pick a route and document it before the data moves. The routes are: the destination is judged to have good enough protection; one of six statutory exceptions such as informed consent; group-wide rules certified by the regulator; or your own written safeguards that a person in Thailand could actually enforce. The 'good enough country' route is dead on arrival because the regulator has published no approved list, so in practice the safeguards route and consent do all the work.Medium confidence
- Who enforces this — and are they actually working?
- The Office of the Personal Data Protection Committee, usually shortened to PDPC, sits under the Ministry of Digital Economy and Society. It is real and staffed: it has a serving Secretary-General, it runs walk-in complaint centres in five provinces and opened another in Ubon Ratchathani on 17 August 2026, and it is executing Cabinet-level instructions on data breaches. Complaints are decided by an Expert Committee that can order you to stop, order you to fix things, and impose fines itself. Other regulators run their own lanes: the cyber-security agency for critical infrastructure, the central bank for payments, and the electronic transactions agency for digital platforms.Medium confidence
- How long must I keep it, and when must I delete it?
- Thailand pushes in both directions at once. The floor: anyone who provides a computer or internet service to other people must keep traffic logs for at least 90 days, and an official can order that stretched to as much as two years. The ceiling: the privacy law makes you build a system that actually deletes personal data once your stated retention period runs out or the data is no longer needed. When the two collide, the keep-it duty wins, because the delete duty has a written carve-out for complying with law and for defending legal claims.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. First: tell the privacy regulator about a personal data breach without delay and within 72 hours of becoming aware, unless the breach carries no risk to people; if the risk to people is high you must also tell the affected individuals, with advice on what to do, without delay. Second: if you run critical information infrastructure, a significant cyber threat must be reported to the national cyber-security agency and to your own sector regulator, and silence without good reason is itself an offence. Third: if you are a bank or a telecoms operator and you suspect technology crime, you must push customer account and transaction data into a shared government-run system immediately.High confidence
- What's the trap?
- Five things that are not in the brochure. Children: Thailand needs a parent's consent for a child aged ten or under, and for older teenagers too unless the act is one the law lets a minor do alone — and a person is a minor in Thailand until twenty. Jail is on the table for misusing sensitive data. You owe compensation even if you were not careless, and a court can add up to double on top. A foreign company must put a named human in Thailand with unlimited authority. And the 90-day log rule catches ordinary businesses that just offer guest wi-fi.High confidence
- What's about to change?
- Nothing in the next twelve months looks like a new statute. What is moving is enforcement reach. The privacy regulator is opening walk-in centres in eight provinces during 2026 to cover all five regions, which means more complaints will actually get filed. The Cabinet decided on 11 August 2026 to require multi-factor login protection across government to stop leaked passwords turning into data breaches, and the ministry is pushing the same expectation across all twenty ministries. The bigger risk is not new law but switches the government already holds and can flip without warning.Medium confidence
- Hardest industry wall
- None found.