Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
AustraliaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
In one paragraph
Australia has no general rule that data must stay in the country. You may send personal information anywhere, and no destination is banned. The catch is that you stay legally responsible for whatever your overseas supplier does with it. Small businesses under A$3 million turnover are exempt from the main privacy law. Specific industries are far stricter, and one of them carries a prison sentence.
The catch
The relaxed headline stops the moment you touch six areas. National electronic health records may not leave Australia at all, and taking them offshore is a crime punishable by five years in prison. Banks and insurers must tell the banking regulator before any offshore arrangement. Open banking data, critical infrastructure data, Australian Government hosting and Queensland state government data each have their own rules. Check your sector before you believe the headline.
Does this apply to me?
Yes, it reaches you even with no office in Australia. The national privacy law applies to any organisation that carries on business in Australia, whether or not the data is collected or stored here. But Australia has something most countries do not: a real size threshold you can fall below. A business with annual turnover of A$3 million (about US$2 million) or less is generally exempt. That exemption has big holes: it does not apply if you provide a health service, if you buy or sell personal information, or if you supply services under a federal government contract. No local representative and no registration are required.High confidence
Can the data leave the country?
In general, yes. Australia has no national law saying personal data must be kept in the country, and no country is blacklisted. You can pick any cloud region you like. What you cannot do is hand off the risk: if your overseas supplier does something with the data that would break Australian rules, the law treats that as your own breach. The hard walls are industry by industry, and the health one is absolute.High confidence
What do I have to do to send it abroad?
Before data leaves, you must take reasonable steps to make sure the overseas recipient will handle it the Australian way. In practice that means a contract with the right promises in it. There is no government form to file, no approval to wait for, and no list of approved countries to check. A power to approve countries was switched on in December 2024, but as of today the government has not named a single one. The alternative routes are narrow: you can rely on the recipient already being covered by a substantially similar law, or on the person's informed consent after you warn them you will no longer be responsible.High confidence
Who enforces this — and are they actually working?
The Office of the Australian Information Commissioner. It is staffed, it has a sitting Privacy Commissioner, and it is issuing decisions. In October 2025 the Federal Court ordered a pathology company to pay A$5.8 million (about US$3.8 million), the first court penalty in the law's history. The regulator sued Optus in August 2025, settled with Meta for A$50 million in December 2024, and in June 2026 alone published formal findings against Optus, American Express and two health providers. Banking, cyber security, online safety and open banking each have their own separate regulator, and all of them are working.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling and they pull in opposite directions. The clearest floor is telecoms: phone and internet providers must keep call and connection records for two years, and must encrypt them. The general ceiling has no number attached — you must destroy or de-identify personal information once you genuinely no longer need it. Two ceilings are sharp. A social media platform must destroy age-check information as soon as it has finished using it. A digital identity provider must destroy a face or fingerprint scan immediately after the identity check is complete.High confidence
What happens when something goes wrong?
Count four clocks, because they run at different speeds. If you pay a ransom and your Australian turnover is above A$3 million (about US$2 million), you have 72 hours to report the payment to the government. If you run critical infrastructure, you have 12 hours for an attack that seriously hits availability, and 72 hours for a lesser one. If you are a bank, insurer or superannuation fund, you have 72 hours for a security incident and only 24 hours if a critical service goes down beyond tolerance. For an ordinary personal data breach you get up to 30 days to assess whether it is serious, then you must tell the regulator and the affected people as soon as you practically can. There is no fixed hour count for that last one, which is the part people get wrong.High confidence
What's the trap?
Five things that will cost you a weekend. First, moving national electronic health record data offshore is a crime, not a fine: up to five years in prison. Second, you never stop owning your supplier's mistakes — a major bank had to get a special ruling from the Privacy Commissioner just to keep processing international money transfers. Third, since December 2025 social media platforms must keep under-16s off the service and then destroy the age-check data they collected. Fourth, Queensland's rule for state government data is stricter than the national one and is hidden in section 33 of the Act, not in the numbered principles — the principle numbered 8 says there is no equivalent. Fifth, the value of a penalty unit rose to A$364 (about US$240) on 1 July 2026, so every fine figure you looked up before then is now understated.High confidence
What's about to change?
One date dominates: 10 December 2026. On that day privacy policies must start explaining computer-made decisions that significantly affect people, and the new Children's Online Privacy Code must be finalised and registered. The draft of that code was out for public comment from 31 March to 5 June 2026. Further out, the tougher critical infrastructure duties made in June 2026 start biting from mid-2027 and mid-2028 as their grace periods run out. Watch three switches the government already holds and can flip with no consultation.High confidence
Hardest industry wall
  • Health and social care My Health Records Act 2012, section 77
LithuaniaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Lithuania has no general rule that data must stay in the country. Private companies follow the European rulebook: data can go abroad once the right paperwork is in place. The wall is in government. The data behind the state's most important computer systems must sit in Lithuanian state data centres — and a copy of the most critical state data must be kept abroad on purpose.
The catch
The easy answer stops being true the moment you sell computing to the Lithuanian state. State information resources are graded into four importance levels. The top two must be held in state data centres inside Lithuania. The bottom two may sit in a foreign or private data centre, but a copy must still be kept in a Lithuanian state data centre — and the government has only approved data centres in European Union, European Economic Area and NATO countries. Lithuania also runs a 'digital embassy': copies of the most critical state data are deliberately stored outside Lithuania so the state survives an invasion. Banking, payments, insurance, securities, telecoms and online gambling have no storage-location rule that we could find. Health records are not walled off by a location rule, but almost all of them flow into a state health system that lives inside that government wall.
Does this apply to me?
Yes. A company with no office in Lithuania is still caught if it offers goods or services to people in Lithuania, or watches what they do online. There is no size or revenue threshold to hide under — a two-person company is covered exactly like a bank. If you have no office anywhere in the European Union, you must appoint a representative inside the Union who can be contacted by regulators and by the public.High confidence
Can the data leave the country?
For an ordinary business, yes. Lithuania has not added a national storage-location rule on top of the European rules, so data can leave once you have the standard European paperwork. The exception is government. If a computer system counts as a state information resource, Lithuania grades it by importance, and the two top grades must be held in state data centres inside Lithuania. The two lower grades can sit abroad, but a copy must still be kept in a Lithuanian state data centre. Lithuania also forces the opposite move for its most critical state data: a copy must be kept outside the country, in what it calls a digital embassy.Medium confidence
What do I have to do to send it abroad?
Lithuania uses the European model: a destination is off-limits unless you have an approved route out. The easiest route is an approved-country list, which is populated and currently includes the United Kingdom, Switzerland, Japan, South Korea, Canada, Brazil and others, plus United States companies signed up to the European Union–United States Data Privacy Framework. If your destination is not on the list, the normal answer is a set of standard contract clauses published by the European Commission. Lithuania adds one local step: if you want to use your own custom contract wording instead of the standard clauses, you need written permission from the Lithuanian regulator first.High confidence
Who enforces this — and are they actually working?
The main regulator is the State Data Protection Inspectorate, and it is genuinely working. In 2025 it received 2,081 complaints, up 48 percent on the year before, ran 26 inspections and had 54 staff. By 31 July 2026 it had already published 122 decisions for the year. But the fines are small: it issued only five fines in the whole of 2025, the largest being 9,000 euros (about 9,800 US dollars). Lithuania also has a second, less well known data regulator for journalism, and a separate cyber regulator inside the defence ministry.High confidence
How long must I keep it, and when must I delete it?
Both directions apply and they pull against each other. The ceiling comes from Europe: you must delete personal data once you no longer need it for the purpose you collected it for. The floors come from Lithuanian sector rules and from retention tables issued by the Chief Archivist. Some floors are very long. Health records in the state e-health system are kept for the patient's whole life plus three years, then archived for 75 years. Online gambling systems must keep their logs for at least 90 days. When a floor and the ceiling clash, the floor wins for as long as it lasts, because keeping the data is then a legal duty.Medium confidence
What happens when something goes wrong?
Count at least two clocks, and they do not agree. If personal data is exposed, you have 72 hours to tell the State Data Protection Inspectorate. If you are covered by the Cybersecurity Law, a serious cyber incident must be reported to the National Cyber Security Centre within 24 hours — a full day earlier — with a fuller assessment at 72 hours and a final report within one month. Other incidents get 72 hours. Financial firms have a third clock under European digital resilience rules. Lithuanian organisations are visibly bad at the first clock: only 63 percent of breach reports in 2025 arrived on time.High confidence
What's the trap?
Five things that are not in the summary. Children can consent for themselves at 14 in Lithuania, not 16, so an age gate built for the European default is wrong here. You may never publish a Lithuanian personal identification number, and you may never use one for marketing. Complaining about a government body is worth less than you think, because fines on public institutions are capped at 30,000 or 60,000 euros. There are two data regulators, and journalism goes to the other one. And if you sell cloud services to the Lithuanian state, your data centre may simply be ineligible.High confidence
What's about to change?
Two dated changes matter in the next twelve months, and both are European. From 12 January 2027 every cloud provider must let customers move their data out for free — no exit fees at all. Around the same period, the technical security requirements of Lithuania's cyber law start biting for organisations registered in April 2025, roughly two years after registration. The bigger Lithuanian risk is not a new law at all: the government can change where state data must live by resolution, without going to parliament and without consulting anyone.Medium confidence
Hardest industry wall
  • Government Lietuvos Respublikos valstybes informaciniu istekliu valdymo istatymas, 45 straipsnis
  • Government Lietuvos Respublikos valstybes informaciniu istekliu valdymo istatymas — vidutines ir mazos svarbos istekliai
  • Government Skaitmenine ambasada — Vyriausybes nutarimas ir Valstybes informaciniu istekliu valdymo istatymo pakeitimai