Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
AustraliaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
In one paragraph
Australia has no general rule that data must stay in the country. You may send personal information anywhere, and no destination is banned. The catch is that you stay legally responsible for whatever your overseas supplier does with it. Small businesses under A$3 million turnover are exempt from the main privacy law. Specific industries are far stricter, and one of them carries a prison sentence.
The catch
The relaxed headline stops the moment you touch six areas. National electronic health records may not leave Australia at all, and taking them offshore is a crime punishable by five years in prison. Banks and insurers must tell the banking regulator before any offshore arrangement. Open banking data, critical infrastructure data, Australian Government hosting and Queensland state government data each have their own rules. Check your sector before you believe the headline.
Does this apply to me?
Yes, it reaches you even with no office in Australia. The national privacy law applies to any organisation that carries on business in Australia, whether or not the data is collected or stored here. But Australia has something most countries do not: a real size threshold you can fall below. A business with annual turnover of A$3 million (about US$2 million) or less is generally exempt. That exemption has big holes: it does not apply if you provide a health service, if you buy or sell personal information, or if you supply services under a federal government contract. No local representative and no registration are required.High confidence
Can the data leave the country?
In general, yes. Australia has no national law saying personal data must be kept in the country, and no country is blacklisted. You can pick any cloud region you like. What you cannot do is hand off the risk: if your overseas supplier does something with the data that would break Australian rules, the law treats that as your own breach. The hard walls are industry by industry, and the health one is absolute.High confidence
What do I have to do to send it abroad?
Before data leaves, you must take reasonable steps to make sure the overseas recipient will handle it the Australian way. In practice that means a contract with the right promises in it. There is no government form to file, no approval to wait for, and no list of approved countries to check. A power to approve countries was switched on in December 2024, but as of today the government has not named a single one. The alternative routes are narrow: you can rely on the recipient already being covered by a substantially similar law, or on the person's informed consent after you warn them you will no longer be responsible.High confidence
Who enforces this — and are they actually working?
The Office of the Australian Information Commissioner. It is staffed, it has a sitting Privacy Commissioner, and it is issuing decisions. In October 2025 the Federal Court ordered a pathology company to pay A$5.8 million (about US$3.8 million), the first court penalty in the law's history. The regulator sued Optus in August 2025, settled with Meta for A$50 million in December 2024, and in June 2026 alone published formal findings against Optus, American Express and two health providers. Banking, cyber security, online safety and open banking each have their own separate regulator, and all of them are working.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling and they pull in opposite directions. The clearest floor is telecoms: phone and internet providers must keep call and connection records for two years, and must encrypt them. The general ceiling has no number attached — you must destroy or de-identify personal information once you genuinely no longer need it. Two ceilings are sharp. A social media platform must destroy age-check information as soon as it has finished using it. A digital identity provider must destroy a face or fingerprint scan immediately after the identity check is complete.High confidence
What happens when something goes wrong?
Count four clocks, because they run at different speeds. If you pay a ransom and your Australian turnover is above A$3 million (about US$2 million), you have 72 hours to report the payment to the government. If you run critical infrastructure, you have 12 hours for an attack that seriously hits availability, and 72 hours for a lesser one. If you are a bank, insurer or superannuation fund, you have 72 hours for a security incident and only 24 hours if a critical service goes down beyond tolerance. For an ordinary personal data breach you get up to 30 days to assess whether it is serious, then you must tell the regulator and the affected people as soon as you practically can. There is no fixed hour count for that last one, which is the part people get wrong.High confidence
What's the trap?
Five things that will cost you a weekend. First, moving national electronic health record data offshore is a crime, not a fine: up to five years in prison. Second, you never stop owning your supplier's mistakes — a major bank had to get a special ruling from the Privacy Commissioner just to keep processing international money transfers. Third, since December 2025 social media platforms must keep under-16s off the service and then destroy the age-check data they collected. Fourth, Queensland's rule for state government data is stricter than the national one and is hidden in section 33 of the Act, not in the numbered principles — the principle numbered 8 says there is no equivalent. Fifth, the value of a penalty unit rose to A$364 (about US$240) on 1 July 2026, so every fine figure you looked up before then is now understated.High confidence
What's about to change?
One date dominates: 10 December 2026. On that day privacy policies must start explaining computer-made decisions that significantly affect people, and the new Children's Online Privacy Code must be finalised and registered. The draft of that code was out for public comment from 31 March to 5 June 2026. Further out, the tougher critical infrastructure duties made in June 2026 start biting from mid-2027 and mid-2028 as their grace periods run out. Watch three switches the government already holds and can flip with no consultation.High confidence
Hardest industry wall
  • Health and social care My Health Records Act 2012, section 77
ChinaChecked 18 August 2026
Yes, with paperworkWork: Very highEnforcement: Active
In one paragraph
Data can leave China, but only through one of three official gates: a government security review, a government-written contract you file with the regulator, or a certificate from an approved body. Which gate you need depends on how many people's data you move, not on where you send it. Small exporters are exempt. Several industries are walled off entirely.
The catch
The 'paperwork, then it can go' answer is only true for ordinary companies. Payment firms, credit bureaus, hospitals, genetic labs, online map services, telecom and industrial operators, and anything the government labels critical national infrastructure must keep the data in China. In those areas a copy staying behind is not optional.
Does this apply to me?
Yes. China's privacy law reaches a company with no office and no staff in China if it offers goods or services to people in China, or analyses their behaviour. There is no revenue or headcount threshold that lets you out. If you are caught this way, you must set up a dedicated office in China or name a representative there, and give the regulator their details.High confidence
Can the data leave the country?
In general yes, once you clear the right gate — but the gate is set by volume, not by destination. China has no list of banned or approved countries. Below 100,000 people a year you can usually send data abroad with no filing at all. Above that you need a contract filed with the regulator or a certificate; above a million people, or if you hold data the state calls 'important', you need a full government security review. Then come the industry walls, which override all of this.High confidence
What do I have to do to send it abroad?
Three routes, and you do not get to pick freely — your volume picks for you. Route one is a government security review, run by the national internet regulator through your provincial office; an approval lasts three years and only covers the exact purpose, scope and method you declared. Route two is China's own standard contract, which you sign with the overseas recipient and file with the provincial regulator along with a risk assessment. Route three is a certificate from an accredited body, which since 1 March 2026 has a national standard behind it. You also need each person's separate, specific consent before their data goes abroad.High confidence
Who enforces this — and are they actually working?
The Cyberspace Administration of China leads, and it is fully staffed and busy. It runs a nationwide enforcement campaign every year, tests apps itself and publishes the names of the ones that fail, and puts out batches of worked enforcement cases. Police, the industry ministry and the market regulator enforce alongside it, and finance, health, mapping and securities regulators run their own rules. Fines are usually modest and paired with an order to fix things; the eye-watering penalties in the statute are rarely used.High confidence
How long must I keep it, and when must I delete it?
Both directions apply, and they pull against each other. The floor: network logs must be kept for at least six months, and accounting records have their own long minimum periods set by a national schedule. The ceiling: personal data may only be kept for the shortest time needed for the purpose you collected it for, and must be deleted once that purpose is met, the service ends, or consent is withdrawn. Where a law sets a minimum, that minimum wins over the delete duty — you keep the record and stop using it for anything else.High confidence
What happens when something goes wrong?
Three clocks, and they overlap. If you run critical national infrastructure you have ONE HOUR to report a serious incident to your supervising department and the police. Everyone else has four hours to tell the provincial internet office. On top of that, a network data incident that could harm national security or the public interest must be reported within 24 hours. You must also tell affected people immediately, by phone, text, message, email or public notice.High confidence
What's the trap?
Five things that ruin weekends. (1) Sending data abroad needs each person's separate, specific consent — a line buried in a global privacy notice will not do. (2) A child is anyone under 14, and their data is treated as sensitive, so you need a parent's consent and a separate set of processing rules. (3) You may not hand data stored in China to a foreign court, police force or regulator without Chinese government approval — this catches routine legal discovery and overseas audit requests. (4) You have to work out for yourself whether you hold 'important data' and report it, because the official catalogues are incomplete. (5) The widely repeated claim that all personal financial data must be stored in China does not appear where people think it does.High confidence
What's about to change?
The next twelve months are about size-based rules. A draft published on 7 August 2026 would create a heavy new tier for any company holding data on ten million people or more: store it in China, appoint a chief privacy officer, set up an outside supervision committee, publish an annual report and honour data portability requests within 30 working days. Comments closed on 7 September 2026 and it is not law yet. A companion draft going the other way would simplify life for small processors. Watch the dormant switches — several can flip with no consultation at all.High confidence
Hardest industry wall
  • All industries 中华人民共和国网络安全法(2025年修正)
  • Payments 非银行支付机构监督管理条例
  • Finance 征信业务管理办法
  • Banking 中国人民银行业务领域数据安全管理办法
  • Securities 关于加强境内企业境外发行证券和上市相关保密和档案管理工作的规定
  • Health and social care 国家健康医疗大数据标准、安全和服务管理办法(试行)
  • Mapping and location 地图管理条例
  • Telecoms 工业和信息化领域数据安全管理办法(试行)