Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
AustriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Austria does not require personal data to be kept in Austria, and we found no Austrian industry that does. Data can leave once the right paperwork is in place under European rules. What Austria adds is a secrecy layer: a constitutional right to data secrecy, a staff secrecy duty, an extra fine of up to 50,000 euros (about $58,000), and a prison offence of up to one year.
- The catch
- "No local storage needed" is true. "Nothing extra to do" is not. Austria's real cost sits in the secrecy layer, not in a map. A standard supplier data agreement does not satisfy Austrian data secrecy on its own, a child can consent at fourteen rather than sixteen, and misusing data you learned at work is a criminal matter in Austria, not just a fine. Health data also moves only inside a closed, encrypted Austrian health network, which in practice narrows your supplier list even though no law names a country.
- Does this apply to me?
- Yes. A company with no office in Austria is still caught if it offers goods or services to people in Austria, or watches what they do online. There is no size or revenue floor to duck under. If you have no establishment anywhere in the European Union, you must name a representative inside the Union in writing. Austria does not add a second, Austria-only representative on top of that.High confidence
- Can the data leave the country?
- Yes, with paperwork. We looked for an Austrian rule forcing data to stay in Austria and found none — not in banking, payments, insurance, securities, health, telecoms, government or mapping. Austrian health data is the closest thing to a wall, but it is a technical wall, not a geographic one: findings move only inside a closed, encrypted Austrian health network between registered care providers. Checked on 18 August 2026.Medium confidence
- What do I have to do to send it abroad?
- The model is an approved-destination list. Sending data outside Europe is fine if the destination is on the European Commission's approved list. If it is not, you sign the European standard contract, or use approved group-wide rules, and you write down a short risk assessment first. You do not need permission from the Austrian regulator. Its own words: apart from a few special cases, international data traffic needs no approval.High confidence
- Who enforces this — and are they actually working?
- The Austrian Data Protection Authority, and it is genuinely working. It has had a permanent head, Matthias Schmidl, since 1 January 2024, a deputy, and five departments. It issues decisions, and on 24 June 2026 Austria's highest administrative court confirmed a 13 million euro fine (about $15 million) for building political-opinion profiles on around 2.2 million people. The court held the fine is measured against the whole group's turnover, not one product line.High confidence
- How long must I keep it, and when must I delete it?
- There is a ceiling and a floor, and they pull against each other. The ceiling is European: keep personal data no longer than you need it, then delete it. The floor is Austrian tax and company law, which makes you keep books, invoices and business records for years after the year they relate to. Where the two clash, the keeping duty wins for as long as it runs, and the data must then be deleted.Medium confidence
- What happens when something goes wrong?
- Count at least two clocks, sometimes four. For a personal data breach you tell the Austrian Data Protection Authority without delay and if possible within 72 hours, and if you are late you must explain in writing why. If you run an essential service you also report significant incidents to Austria's network security authority. Banks and insurers report separately under European financial rules, and telecom operators have their own duty.High confidence
- What's the trap?
- Five that cost people their weekend. A child can consent at fourteen in Austria, not sixteen. Misusing data you only learned about through your job is a crime punishable by up to a year in prison. There is a second, separate Austrian fine of up to 50,000 euros (about $58,000) for breaking data secrecy or running a camera unlawfully. Austrian public bodies cannot be fined at all, but you still can. And the law tells the regulator to warn first, which is not the same as forgiveness.High confidence
- What's about to change?
- Three things to watch. Austria's Constitutional Court is deciding whether the state may plant software on a phone to read messages; it heard the case on 22 June 2026 and has not ruled. Austria has still not written the new European cybersecurity rules into national law, so that expansion is still ahead of you. And from 12 January 2027, cloud providers across Europe may no longer charge you to move your data out.High confidence
- Hardest industry wall
- None found.
BulgariaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Bulgaria is an ordinary European Union country for data. Personal data can leave, as long as you use one of the standard European transfer tools. There is no general rule forcing data to stay in Bulgaria. But online gambling is a hard exception: a control server must physically sit on Bulgarian soil. Bulgaria switched to the euro on 1 January 2026, so all fines are now in euro.
- The catch
- The relaxed headline stops being true in two places. First, online gambling: an operator licensed in Bulgaria must keep a control local server on Bulgarian territory and stream live game data to the tax authority's server. Second, telecoms: operators must build and pay for interception equipment wired into two Bulgarian state agencies, which cannot be run from abroad. Mapping and aerial survey work also needs clearance from five Bulgarian ministries and agencies before you may even collect the data.
- Does this apply to me?
- Yes, it can reach you with no office in Bulgaria. The European Union's privacy rulebook applies to anyone who offers goods or services to people in Europe or watches what they do online. Bulgaria's own Personal Data Protection Act sits on top of that and adds extra local duties. There is no revenue or headcount threshold, and no Bulgaria-specific representative: the European-wide requirement to name a representative in Europe is the only one, and it can be in any European country.High confidence
- Can the data leave the country?
- In general, yes. Bulgaria has no law telling ordinary businesses to keep personal data inside the country. Data moves freely to the rest of Europe, to Switzerland, and to countries Europe has approved; anywhere else needs a standard contract or a similar tool. Two industries break that pattern. Online gambling operators must keep a control server physically in Bulgaria. Telecoms operators must build interception equipment that plugs into Bulgarian state agencies, which cannot sit abroad.High confidence
- What do I have to do to send it abroad?
- Bulgaria uses Europe's system, not its own. There is no Bulgarian list of banned countries and no Bulgarian permit to apply for. If the destination is inside Europe, the wider European Economic Area or Switzerland, nothing extra is needed. Otherwise you need either an official European approval of that country, or the standard European contract, or approved group-wide rules. One Bulgarian twist: Bulgarian law explicitly puts Switzerland on the same footing as a European Union country.High confidence
- Who enforces this — and are they actually working?
- The Commission for Personal Data Protection is the main regulator. It is real, staffed and it does issue formal decisions, including ones published across Europe. But it is not a heavy hitter. In a Europe-wide check on deletion rights reported in February 2026, it contacted twenty-three organisations, opened no formal investigations, imposed no penalties, and said it did not plan to. A separate inspectorate polices the courts and prosecutors. Cybersecurity has its own separate regulators.Medium confidence
- How long must I keep it, and when must I delete it?
- Bulgaria has strong minimum-keeping rules and a few sharp delete-by rules. You must keep payroll records for fifty years, accounting books and financial statements for ten years, and other accounting papers for three years. Telecoms firms keep connection records for six months. Going the other way, job applicants' data must be deleted within six months unless they agree otherwise, and data you were given with no legal basis must be returned or destroyed within one month.High confidence
- What happens when something goes wrong?
- There are at least three clocks and they do not agree. A personal data breach must reach the privacy regulator within seventy-two hours. Under the cybersecurity law rewritten in February 2026, an early warning must reach the response team within twenty-four hours and a fuller report within seventy-two hours. Trust service providers get twenty-four hours for that fuller report. Financial firms answer to the separate European financial-resilience rules on top.High confidence
- What's the trap?
- Five things bite people in Bulgaria. You may not photocopy someone's identity card, driving licence or residence permit unless a law lets you. Children need a parent's consent up to age fourteen, not sixteen. Job applicant files must go within six months. Your accounting software must be able to output in Bulgarian. And one clause of the privacy law was struck down by the Constitutional Court in 2019 but is still printed in the statute.High confidence
- What's about to change?
- Two dated changes are already fixed. From 12 January 2027 every cloud provider must let customers move their data out for free. Bulgaria's new cybersecurity duties started on 13 February 2026 and enforcement is only now warming up. The biggest live risk is not Bulgarian at all: Europe's approval of United States data transfers is being challenged, and Europe's own privacy board asked the Commission on 31 July 2026 to re-examine it.High confidence
- Hardest industry wall
- Online gaming — Закон за хазарта