Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
AustriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
In one paragraph
Austria does not require personal data to be kept in Austria, and we found no Austrian industry that does. Data can leave once the right paperwork is in place under European rules. What Austria adds is a secrecy layer: a constitutional right to data secrecy, a staff secrecy duty, an extra fine of up to 50,000 euros (about $58,000), and a prison offence of up to one year.
The catch
"No local storage needed" is true. "Nothing extra to do" is not. Austria's real cost sits in the secrecy layer, not in a map. A standard supplier data agreement does not satisfy Austrian data secrecy on its own, a child can consent at fourteen rather than sixteen, and misusing data you learned at work is a criminal matter in Austria, not just a fine. Health data also moves only inside a closed, encrypted Austrian health network, which in practice narrows your supplier list even though no law names a country.
Does this apply to me?
Yes. A company with no office in Austria is still caught if it offers goods or services to people in Austria, or watches what they do online. There is no size or revenue floor to duck under. If you have no establishment anywhere in the European Union, you must name a representative inside the Union in writing. Austria does not add a second, Austria-only representative on top of that.High confidence
Can the data leave the country?
Yes, with paperwork. We looked for an Austrian rule forcing data to stay in Austria and found none — not in banking, payments, insurance, securities, health, telecoms, government or mapping. Austrian health data is the closest thing to a wall, but it is a technical wall, not a geographic one: findings move only inside a closed, encrypted Austrian health network between registered care providers. Checked on 18 August 2026.Medium confidence
What do I have to do to send it abroad?
The model is an approved-destination list. Sending data outside Europe is fine if the destination is on the European Commission's approved list. If it is not, you sign the European standard contract, or use approved group-wide rules, and you write down a short risk assessment first. You do not need permission from the Austrian regulator. Its own words: apart from a few special cases, international data traffic needs no approval.High confidence
Who enforces this — and are they actually working?
The Austrian Data Protection Authority, and it is genuinely working. It has had a permanent head, Matthias Schmidl, since 1 January 2024, a deputy, and five departments. It issues decisions, and on 24 June 2026 Austria's highest administrative court confirmed a 13 million euro fine (about $15 million) for building political-opinion profiles on around 2.2 million people. The court held the fine is measured against the whole group's turnover, not one product line.High confidence
How long must I keep it, and when must I delete it?
There is a ceiling and a floor, and they pull against each other. The ceiling is European: keep personal data no longer than you need it, then delete it. The floor is Austrian tax and company law, which makes you keep books, invoices and business records for years after the year they relate to. Where the two clash, the keeping duty wins for as long as it runs, and the data must then be deleted.Medium confidence
What happens when something goes wrong?
Count at least two clocks, sometimes four. For a personal data breach you tell the Austrian Data Protection Authority without delay and if possible within 72 hours, and if you are late you must explain in writing why. If you run an essential service you also report significant incidents to Austria's network security authority. Banks and insurers report separately under European financial rules, and telecom operators have their own duty.High confidence
What's the trap?
Five that cost people their weekend. A child can consent at fourteen in Austria, not sixteen. Misusing data you only learned about through your job is a crime punishable by up to a year in prison. There is a second, separate Austrian fine of up to 50,000 euros (about $58,000) for breaking data secrecy or running a camera unlawfully. Austrian public bodies cannot be fined at all, but you still can. And the law tells the regulator to warn first, which is not the same as forgiveness.High confidence
What's about to change?
Three things to watch. Austria's Constitutional Court is deciding whether the state may plant software on a phone to read messages; it heard the case on 22 June 2026 and has not ruled. Austria has still not written the new European cybersecurity rules into national law, so that expansion is still ahead of you. And from 12 January 2027, cloud providers across Europe may no longer charge you to move your data out.High confidence
Hardest industry wall
None found.
GermanyChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
In one paragraph
Contrary to widespread belief, neither Europe nor Germany requires personal data to be stored in Europe. What the law requires is a valid legal instrument before data leaves — an official decision that the destination is safe enough, or a standard contract, plus a documented risk assessment. Germany then adds its own layer on top, and one genuine hard wall: health and social data may only be processed in the cloud within Europe, by a provider holding a specific German security certificate.
The catch
'Germany doesn't require local storage' is true right up until you sell to a hospital, a health insurer, a doctor, a lawyer or a tax adviser. In health and social care it is simply false, and for the professional-secrecy trades a standard data processing agreement is not enough and getting it wrong is a criminal matter.
Does this apply to me?
Yes, it reaches you with no office in Germany. Europe's privacy law applies to any organisation anywhere that offers goods or services to people in Europe or monitors their behaviour. If you have no European establishment you must also appoint a representative inside Europe.High confidence
Can the data leave the country?
Yes — with paperwork. This is the single most misunderstood point in the field. European law does not say where data must sit; it says what you must have in place before it leaves Europe. Storage location is a risk factor in that assessment, never a prohibition. For non-personal data, Europe goes further and actually forbids member states from imposing storage-location rules.High confidence
What do I have to do to send it abroad?
One of three routes. Best case, the destination is on Europe's official 'adequate' list and you need nothing extra — currently 17 entries including the UK, Japan, South Korea, Switzerland, Canada for commercial bodies, Brazil since January 2026, and the United States but only for companies self-certified under the EU-US Data Privacy Framework. Otherwise you sign Europe's standard contract clauses, or get group-wide internal rules approved. In either of those two cases you must also document an assessment of whether the destination country's surveillance laws undermine the protection.High confidence
Who enforces this — and are they actually working?
Eighteen separate authorities, and for a private company it is almost never the federal one. Each of the 16 states has its own regulator, and you answer to the one where your German office is. The federal regulator handles government bodies plus telecoms and postal operators. Bavaria splits it further, with different bodies for private and public sector. If you operate across Europe, a separate rule lets you deal mainly with the regulator where your main European establishment sits.High confidence
How long must I keep it, and when must I delete it?
Business records have a floor: accounting vouchers must be kept 8 years (cut from 10 with effect from 2025, and from 2026 for banks and insurers), the annual accounts and trading books still 10 years, and business correspondence 6 years. Privacy law pushes the other way — don't keep personal data longer than you need it. Where the two collide, German law has an elegant answer: you restrict processing of the data instead of deleting it.High confidence
What happens when something goes wrong?
72 hours to tell your state regulator about a personal data breach, and without undue delay to tell affected people where the risk to them is high. Separately, since December 2025 Germany's cybersecurity law adds its own clocks for around 29,500 in-scope companies: a first warning within 24 hours, an update at 72 hours, and a full report within a month. Financial firms follow a separate European regime instead.High confidence
What's the trap?
Four. (1) Health and social data really does have to stay in Europe, with a specific German security certificate — the general 'no localisation' answer is wrong here. (2) For doctors, lawyers, tax advisers and notaries, a standard data processing agreement is NOT enough: you need explicit secrecy undertakings flowed down to every subcontractor, and breach is a criminal offence, not a fine. (3) Germany still requires a data protection officer at just 20 employees involved in data processing — far stricter than European law, and still in force despite a government promise to scrap it by the end of 2026. (4) The German rule people cite for employee data was effectively struck down by Europe's top court in 2023 but never removed from the statute book, so citing it as your legal basis is a mistake.High confidence
What's about to change?
Two hard dates and one live risk. From 12 January 2027 every cloud provider must drop switching and data egress fees to zero — renegotiate contracts now. By 31 December 2026 Germany's banking IT rulebook is fully withdrawn in favour of the European financial regime. The live risk is the US arrangement: Europe's data protection board formally asked the Commission on 31 July 2026 to review whether it is still valid, and a separate court appeal is pending. If it falls, thousands of transfers move to standard contracts overnight.High confidence
Hardest industry wall
  • Health and social care § 393 SGB V — Cloud-Einsatz im Gesundheitswesen
  • Telecoms §§ 175–181 TKG — Vorratsdatenspeicherung