Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
AustraliaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
In one paragraph
Australia has no general rule that data must stay in the country. You may send personal information anywhere, and no destination is banned. The catch is that you stay legally responsible for whatever your overseas supplier does with it. Small businesses under A$3 million turnover are exempt from the main privacy law. Specific industries are far stricter, and one of them carries a prison sentence.
The catch
The relaxed headline stops the moment you touch six areas. National electronic health records may not leave Australia at all, and taking them offshore is a crime punishable by five years in prison. Banks and insurers must tell the banking regulator before any offshore arrangement. Open banking data, critical infrastructure data, Australian Government hosting and Queensland state government data each have their own rules. Check your sector before you believe the headline.
Does this apply to me?
Yes, it reaches you even with no office in Australia. The national privacy law applies to any organisation that carries on business in Australia, whether or not the data is collected or stored here. But Australia has something most countries do not: a real size threshold you can fall below. A business with annual turnover of A$3 million (about US$2 million) or less is generally exempt. That exemption has big holes: it does not apply if you provide a health service, if you buy or sell personal information, or if you supply services under a federal government contract. No local representative and no registration are required.High confidence
Can the data leave the country?
In general, yes. Australia has no national law saying personal data must be kept in the country, and no country is blacklisted. You can pick any cloud region you like. What you cannot do is hand off the risk: if your overseas supplier does something with the data that would break Australian rules, the law treats that as your own breach. The hard walls are industry by industry, and the health one is absolute.High confidence
What do I have to do to send it abroad?
Before data leaves, you must take reasonable steps to make sure the overseas recipient will handle it the Australian way. In practice that means a contract with the right promises in it. There is no government form to file, no approval to wait for, and no list of approved countries to check. A power to approve countries was switched on in December 2024, but as of today the government has not named a single one. The alternative routes are narrow: you can rely on the recipient already being covered by a substantially similar law, or on the person's informed consent after you warn them you will no longer be responsible.High confidence
Who enforces this — and are they actually working?
The Office of the Australian Information Commissioner. It is staffed, it has a sitting Privacy Commissioner, and it is issuing decisions. In October 2025 the Federal Court ordered a pathology company to pay A$5.8 million (about US$3.8 million), the first court penalty in the law's history. The regulator sued Optus in August 2025, settled with Meta for A$50 million in December 2024, and in June 2026 alone published formal findings against Optus, American Express and two health providers. Banking, cyber security, online safety and open banking each have their own separate regulator, and all of them are working.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling and they pull in opposite directions. The clearest floor is telecoms: phone and internet providers must keep call and connection records for two years, and must encrypt them. The general ceiling has no number attached — you must destroy or de-identify personal information once you genuinely no longer need it. Two ceilings are sharp. A social media platform must destroy age-check information as soon as it has finished using it. A digital identity provider must destroy a face or fingerprint scan immediately after the identity check is complete.High confidence
What happens when something goes wrong?
Count four clocks, because they run at different speeds. If you pay a ransom and your Australian turnover is above A$3 million (about US$2 million), you have 72 hours to report the payment to the government. If you run critical infrastructure, you have 12 hours for an attack that seriously hits availability, and 72 hours for a lesser one. If you are a bank, insurer or superannuation fund, you have 72 hours for a security incident and only 24 hours if a critical service goes down beyond tolerance. For an ordinary personal data breach you get up to 30 days to assess whether it is serious, then you must tell the regulator and the affected people as soon as you practically can. There is no fixed hour count for that last one, which is the part people get wrong.High confidence
What's the trap?
Five things that will cost you a weekend. First, moving national electronic health record data offshore is a crime, not a fine: up to five years in prison. Second, you never stop owning your supplier's mistakes — a major bank had to get a special ruling from the Privacy Commissioner just to keep processing international money transfers. Third, since December 2025 social media platforms must keep under-16s off the service and then destroy the age-check data they collected. Fourth, Queensland's rule for state government data is stricter than the national one and is hidden in section 33 of the Act, not in the numbered principles — the principle numbered 8 says there is no equivalent. Fifth, the value of a penalty unit rose to A$364 (about US$240) on 1 July 2026, so every fine figure you looked up before then is now understated.High confidence
What's about to change?
One date dominates: 10 December 2026. On that day privacy policies must start explaining computer-made decisions that significantly affect people, and the new Children's Online Privacy Code must be finalised and registered. The draft of that code was out for public comment from 31 March to 5 June 2026. Further out, the tougher critical infrastructure duties made in June 2026 start biting from mid-2027 and mid-2028 as their grace periods run out. Watch three switches the government already holds and can flip with no consultation.High confidence
Hardest industry wall
  • Health and social care My Health Records Act 2012, section 77
SpainChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
In one paragraph
Spain follows the normal European rule: personal data may leave the country once you have the right paperwork in place. But four named categories of data held by the Spanish state must physically stay inside the European Union, and may only travel further to a country Europe has officially approved. Spain's privacy regulator is one of the busiest in the world.
The catch
The relaxed headline stops being true the moment you touch the electoral roll, town-hall population registers, Spanish tax records or data about users of the Spanish national health service. For those four things a standard European transfer contract is not enough and never will be — the law allows only officially approved destinations. Online gambling, telecoms and any system sold to the Spanish public sector carry their own separate rules.
Does this apply to me?
Yes. A company with no office in Spain is still caught if it offers goods or services to people in Spain or watches what they do online. There is no size or revenue threshold to hide under. If you have no base anywhere in Europe you must appoint a written representative inside Europe, and Spain's regulator will happily deal with that representative instead of you.High confidence
Can the data leave the country?
For most businesses, yes, with paperwork — the ordinary European rules apply and nothing in Spanish law says data must sit on Spanish soil. The exception is sharp. If the data is the electoral roll, a town-hall population register, Spanish tax records, or information about users of the Spanish national health service, the computers holding it must be inside the European Union, and that data may only go outside Europe to a country Europe has officially approved. A standard European transfer contract does not work for those four things.High confidence
What do I have to do to send it abroad?
The model is an approved-list one, run at European level, not by Spain. You may send data outside Europe if the destination country is on Europe's approved list, or if you sign Europe's standard contract, or if your corporate group has approved internal rules. The list is real and populated. Spain adds one twist: if you want to use a home-made contract instead of the standard one, you must get written permission from the Spanish regulator first.High confidence
Who enforces this — and are they actually working?
The Spanish Data Protection Agency, and it is very much awake. Its public decision database held 46,925 decisions when we checked on 18 August 2026, with rulings signed as recently as 12 August 2026. Three regional authorities also enforce, covering public bodies in Catalonia, the Basque Country and Andalusia. Spain's artificial intelligence supervisor is now operating too and met the privacy agency in July 2026 to divide up the work.High confidence
How long must I keep it, and when must I delete it?
Both directions, and they collide. The longest floor is money laundering records: ten years, and the same law then orders you to destroy them. Business books run six years, clinical records at least five years from the end of each course of treatment, phone and internet connection records twelve months, and the taxman can come back four years. In the other direction Spain does something unusual: when someone asks you to delete their data you must not actually delete it, you must lock it away.High confidence
What happens when something goes wrong?
Count three clocks, not one. Everyone has 72 hours to tell the privacy regulator about a personal data breach. Phone and internet providers have only 24 hours under a separate European rule. And if you run something the state treats as an essential service, the cyber clock says report immediately, then send an update within 24 to 48 hours if the incident is critical, or 72 hours if it is very serious, with a final report 20 or 40 days later.High confidence
What's the trap?
Five things that ruin weekends. One: a child can consent at fourteen in Spain, not sixteen, so your global age gate is probably wrong here. Two: 'delete my data' legally means 'lock my data away', so a hard-delete pipeline breaks the law. Three: Spain forces far more organisations to appoint a data protection officer than Europe does, including every school, university, bank, insurer, energy supplier and online gambling operator. Four: misusing someone's personal records is a crime punishable by prison, and companies themselves can be prosecuted. Five: telecoms operators can be ordered to hand over the encryption method they use.High confidence
What's about to change?
The biggest thing is what has not happened. Spain still has not passed the law that brings Europe's new cybersecurity rules into Spanish law, so the old 2018 regime is still what binds — expect that to change and to widen sharply who must report incidents. From 12 January 2027 no cloud provider may charge you to leave or to pull your data out. Watch three switches the government can flip with no consultation: taking over telecoms networks, ordering gambling systems into Spain, and demanding an operator's encryption method.Medium confidence
Hardest industry wall
None found.