Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
AustriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Austria does not require personal data to be kept in Austria, and we found no Austrian industry that does. Data can leave once the right paperwork is in place under European rules. What Austria adds is a secrecy layer: a constitutional right to data secrecy, a staff secrecy duty, an extra fine of up to 50,000 euros (about $58,000), and a prison offence of up to one year.
- The catch
- "No local storage needed" is true. "Nothing extra to do" is not. Austria's real cost sits in the secrecy layer, not in a map. A standard supplier data agreement does not satisfy Austrian data secrecy on its own, a child can consent at fourteen rather than sixteen, and misusing data you learned at work is a criminal matter in Austria, not just a fine. Health data also moves only inside a closed, encrypted Austrian health network, which in practice narrows your supplier list even though no law names a country.
- Does this apply to me?
- Yes. A company with no office in Austria is still caught if it offers goods or services to people in Austria, or watches what they do online. There is no size or revenue floor to duck under. If you have no establishment anywhere in the European Union, you must name a representative inside the Union in writing. Austria does not add a second, Austria-only representative on top of that.High confidence
- Can the data leave the country?
- Yes, with paperwork. We looked for an Austrian rule forcing data to stay in Austria and found none — not in banking, payments, insurance, securities, health, telecoms, government or mapping. Austrian health data is the closest thing to a wall, but it is a technical wall, not a geographic one: findings move only inside a closed, encrypted Austrian health network between registered care providers. Checked on 18 August 2026.Medium confidence
- What do I have to do to send it abroad?
- The model is an approved-destination list. Sending data outside Europe is fine if the destination is on the European Commission's approved list. If it is not, you sign the European standard contract, or use approved group-wide rules, and you write down a short risk assessment first. You do not need permission from the Austrian regulator. Its own words: apart from a few special cases, international data traffic needs no approval.High confidence
- Who enforces this — and are they actually working?
- The Austrian Data Protection Authority, and it is genuinely working. It has had a permanent head, Matthias Schmidl, since 1 January 2024, a deputy, and five departments. It issues decisions, and on 24 June 2026 Austria's highest administrative court confirmed a 13 million euro fine (about $15 million) for building political-opinion profiles on around 2.2 million people. The court held the fine is measured against the whole group's turnover, not one product line.High confidence
- How long must I keep it, and when must I delete it?
- There is a ceiling and a floor, and they pull against each other. The ceiling is European: keep personal data no longer than you need it, then delete it. The floor is Austrian tax and company law, which makes you keep books, invoices and business records for years after the year they relate to. Where the two clash, the keeping duty wins for as long as it runs, and the data must then be deleted.Medium confidence
- What happens when something goes wrong?
- Count at least two clocks, sometimes four. For a personal data breach you tell the Austrian Data Protection Authority without delay and if possible within 72 hours, and if you are late you must explain in writing why. If you run an essential service you also report significant incidents to Austria's network security authority. Banks and insurers report separately under European financial rules, and telecom operators have their own duty.High confidence
- What's the trap?
- Five that cost people their weekend. A child can consent at fourteen in Austria, not sixteen. Misusing data you only learned about through your job is a crime punishable by up to a year in prison. There is a second, separate Austrian fine of up to 50,000 euros (about $58,000) for breaking data secrecy or running a camera unlawfully. Austrian public bodies cannot be fined at all, but you still can. And the law tells the regulator to warn first, which is not the same as forgiveness.High confidence
- What's about to change?
- Three things to watch. Austria's Constitutional Court is deciding whether the state may plant software on a phone to read messages; it heard the case on 22 June 2026 and has not ruled. Austria has still not written the new European cybersecurity rules into national law, so that expansion is still ahead of you. And from 12 January 2027, cloud providers across Europe may no longer charge you to move your data out.High confidence
- Hardest industry wall
- None found.
GreeceChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- For most businesses Greece is a normal European country: personal data can leave, as long as you use one of the standard European transfer tools. But Greece has two hard walls that Europe does not. Phone and internet connection records must physically sit on machines inside Greece. Online gambling operators must keep their records on a server inside Greece too. The privacy regulator is fully staffed and fining companies today.
- The catch
- The relaxed European headline stops being true the moment you touch three things. Telecoms connection records must be stored on physical media inside Greek territory for twelve months. Online gambling records must sit on a server or safe inside Greece for ten years. And Greek public bodies must run their central systems on the Greek state's own clouds, not on a commercial cloud of their choosing. Outside those three, plus the health and public sectors, Greece imposes no storage-location rule of its own.
- Does this apply to me?
- Yes, it reaches a foreign company with no office in Greece. The European privacy rules apply to anyone anywhere who offers goods or services to people in Greece, or who watches what they do online. The Greek national law adds that it also covers anyone processing data on Greek soil. There is no size or revenue threshold that lets you off. If you have no establishment anywhere in Europe, you must appoint a written representative inside the European Union.High confidence
- Can the data leave the country?
- In general, yes. Greece adds no storage-location rule of its own to the European baseline, so ordinary business data can be sent abroad once you have the right European transfer paperwork. Three industries break that rule completely. Telecoms companies must keep their connection records on machines physically inside Greece. Online gambling operators must keep their records on a server inside Greece. And Greek government bodies must run their main systems on state-operated clouds. Health, banking and insurance have extra hoops but no location rule.High confidence
- What do I have to do to send it abroad?
- You need one of the standard European transfer tools before data leaves Europe. The simplest is sending it to a country the European Commission has already approved. If the destination is not approved, you sign the European Commission's standard contract with the recipient, or use approved group-wide internal rules, and you write down why you think the data will still be safe there. Greece adds no extra permission, filing or fee of its own.High confidence
- Who enforces this — and are they actually working?
- Six bodies, and all six are genuinely working. The Hellenic Data Protection Authority is the main privacy regulator and is issuing numbered decisions and fines every month — its most recent published decisions run to July 2026 and include fines on a bank and an electricity supplier. A separate constitutional authority polices the secrecy of communications. There is also a national cybersecurity authority, a telecoms regulator, the central bank for finance and insurance, and a gambling regulator. This is not a paper regime.High confidence
- How long must I keep it, and when must I delete it?
- Both directions apply, and they collide. Business books must be kept five years. Medical files must be kept ten years in a private practice and twenty years everywhere else. Online gambling records must be kept ten years. Telecoms connection records must be kept exactly twelve months and then automatically deleted. In the other direction, the European rule says you must not keep personal data longer than you need it. When a specific keeping rule and the general deleting rule clash, the specific keeping rule wins.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. If personal data is lost or exposed, you have 72 hours to tell the privacy regulator. If you run important infrastructure, you have only 24 hours to send a first warning to the national cybersecurity authority, then 72 hours for a fuller report and one month for the final one. If you are a phone or internet provider, you have 24 hours to report a personal data breach and a separate duty to tell the communications secrecy authority. Missing the 24-hour clocks is the most common failure.High confidence
- What's the trap?
- Five things that will cost you a weekend. First, a child in Greece can consent to an online service at fifteen, not sixteen — so an age gate built to the European default is set wrong. Second, misusing personal data is a crime here, with prison time, not just a fine. Third, several articles of the Greek privacy law are printed in the statute but the regulator has formally said they must not be applied, because they clash with European law. Fourth, telecoms connection records must physically stay in Greece. Fifth, government bodies cannot simply pick a commercial cloud.High confidence
- What's about to change?
- Three dated changes. Electronic invoicing between businesses became compulsory for large Greek companies on 2 March 2026 and becomes compulsory for everyone else on 1 October 2026. Greece's new artificial intelligence law took effect on 22 July 2026 and forces public bodies to register every artificial intelligence system before switching it on. And from 12 January 2027 European law bans cloud providers from charging you to move your data out.High confidence
- Hardest industry wall
- Telecoms — Νόμος 3917/2011 — Διατήρηση δεδομένων που παράγονται ή υποβάλλονται σε επεξεργασία σε συνάρτηση με την παροχή υπηρεσιών ηλεκτρονικών επικοινωνιών
- Online gaming — Νόμος 4002/2011 — Ρύθμιση της αγοράς παιγνίων, άρθρο 47, και Κανονισμοί Παιγνίων (ΥΑ 79305/2020 και 79835/2020)
- Government — Νόμος 4727/2020 — Ψηφιακή Διακυβέρνηση, άρθρο 87 (Κυβερνητικά νέφη)