Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
AzerbaijanChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Azerbaijan has had a personal data law since 2010. Data may leave the country, but only if you decide the destination protects it as well as Azerbaijan does, and you must declare those exports up front. The real cost is not the export rule. It is that you must register your database with the state before you collect a single record.
The catch
The easy-sounding export rule hides where the work actually is. Nothing may be collected until the system holding it sits on a state register, and the government's security rules are unusually specific, down to the encryption key length and where the archive building may stand. Banking and payments have no separate storage wall, but a new cybersecurity regime started in August 2026 and a social media law bites in 2027.
Does this apply to me?
The law is silent about foreign companies, and that silence is the answer. Unlike Europe's rules, Azerbaijan's personal data law has no clause reaching organisations abroad that sell to Azerbaijanis. What it does have is a duty on the 'owner' of a database to register it with the state before collecting anything, and that duty is enforced through the register in Baku. A foreign company with no Azerbaijani entity has no realistic way to register, and no regulator has said whether it must. From 2027 one narrow group of foreign firms is caught by name: social network providers offering services to users in Azerbaijan must set up a local branch or representative office.Medium confidence
Can the data leave the country?
Yes, with conditions, and the condition is a judgement call you make yourself. Azerbaijan bans sending personal data abroad in only two situations: where it would threaten national security, or where the destination country's law does not protect the data to the standard Azerbaijani law sets. Nobody publishes a list of good or bad countries, so you decide, and you carry the risk. If the person has consented, or if the transfer is needed to protect their life or health, the destination's standard stops mattering at all. We looked hard for industry walls in banking, payments, insurance, securities, telecoms and health and found none that force data to stay in the country.High confidence
What do I have to do to send it abroad?
There is no form to file and no approval to get. You need three things instead: a lawful basis for the processing in the first place, your own written assessment that the destination country protects the data well enough, and a declaration of the transfer in your entry on the state register. That last point is the one people miss. The registration form asks you to list the categories of personal data you send to other countries and to international organisations, so an undeclared export is also a registration failure.High confidence
Who enforces this — and are they actually working?
This changed three months ago. On 3 June 2026 the President abolished the Electronic Security Service and created the National Cybersecurity Agency in its place, under the Ministry of Digital Development and Transport, with express powers over personal data as well as cyber security. The agency is real and working: it runs the state register, takes complaints about data misuse through its website, publishes advisories most weeks, and signed a cooperation agreement with Latvia's data protection inspectorate in July 2026. It is not independent of government, and we found no published fines. The register itself is the strongest evidence it functions: 444 systems are listed and the most recent approval is dated 7 August 2026.High confidence
How long must I keep it, and when must I delete it?
The ceiling is strict and the floor is thin. Once you have achieved the purpose you collected the data for, and there is no longer a need to keep it, you must destroy it without delay. If your registration is cancelled, everything in that system must be blocked immediately and destroyed. Sensitive data must go as soon as the reason for holding it disappears, unless the person agrees to it staying or being archived. In the other direction, the personal data law itself sets no minimum keeping period. The clearest floor we could verify is new: from 2026, records of a digital forensic investigation into a cyber incident must be kept for at least three years.Medium confidence
What happens when something goes wrong?
There is no personal data breach notification duty at all. The 2010 law never created one, and nothing since has added one, so losing customer records triggers no report to any regulator and no letter to the people affected. What does exist is a cyber incident duty, and it is fast: since August 2026, organisations that run information infrastructure must pass information about cyber threats, attacks and incidents to the National CERT immediately. Once the National CERT asks you something, you have 24 hours to answer a threat research request and 5 working days to answer a digital investigation request. Financial firms have a second clock through the Central Bank's FinCERT portal.High confidence
What's the trap?
Five. One: you cannot start. Collecting or processing personal data in an unregistered system is an offence, and registration takes up to a month. Two: the security rules are engineering specifications, not principles, and include a minimum 256-bit encryption key, a data centre archive system housed in a separate building, and state expert review of your system design documents. Three: every operator must set things up so that police and intelligence bodies can carry out surveillance, and must keep the methods secret. Four: the fine for breaking the data law is 300 to 500 manat, roughly 175 to 290 US dollars, which tells you the real risk is being ordered to stop, not being fined. Five: the law says data system work needs a special licence, and no licensing regime matching it appears to be running.High confidence
What's about to change?
One big date and one big gap. The big date is roughly August 2027, twelve months after publication, when Azerbaijan's minimum age of 16 for social network accounts starts. Providers must verify age using a bank card, an email address and a mobile number, must delete what they collected for that check immediately, and must open a local branch. The penalty ladder ends with a court ordering the platform's traffic in Azerbaijan cut by 90 per cent. The big gap is that the July 2026 cybersecurity law leaves the important lists and technical requirements to be written by ministries, and they are not out yet.High confidence
Hardest industry wall
  • Government “Hökumət buludu”nun (G-cloud) yaradılması və “bulud” xidmətlərinin göstərilməsi sahəsində tədbirlər haqqında Azərbaycan Respublikası Prezidentinin Fərmanı
GreeceChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
For most businesses Greece is a normal European country: personal data can leave, as long as you use one of the standard European transfer tools. But Greece has two hard walls that Europe does not. Phone and internet connection records must physically sit on machines inside Greece. Online gambling operators must keep their records on a server inside Greece too. The privacy regulator is fully staffed and fining companies today.
The catch
The relaxed European headline stops being true the moment you touch three things. Telecoms connection records must be stored on physical media inside Greek territory for twelve months. Online gambling records must sit on a server or safe inside Greece for ten years. And Greek public bodies must run their central systems on the Greek state's own clouds, not on a commercial cloud of their choosing. Outside those three, plus the health and public sectors, Greece imposes no storage-location rule of its own.
Does this apply to me?
Yes, it reaches a foreign company with no office in Greece. The European privacy rules apply to anyone anywhere who offers goods or services to people in Greece, or who watches what they do online. The Greek national law adds that it also covers anyone processing data on Greek soil. There is no size or revenue threshold that lets you off. If you have no establishment anywhere in Europe, you must appoint a written representative inside the European Union.High confidence
Can the data leave the country?
In general, yes. Greece adds no storage-location rule of its own to the European baseline, so ordinary business data can be sent abroad once you have the right European transfer paperwork. Three industries break that rule completely. Telecoms companies must keep their connection records on machines physically inside Greece. Online gambling operators must keep their records on a server inside Greece. And Greek government bodies must run their main systems on state-operated clouds. Health, banking and insurance have extra hoops but no location rule.High confidence
What do I have to do to send it abroad?
You need one of the standard European transfer tools before data leaves Europe. The simplest is sending it to a country the European Commission has already approved. If the destination is not approved, you sign the European Commission's standard contract with the recipient, or use approved group-wide internal rules, and you write down why you think the data will still be safe there. Greece adds no extra permission, filing or fee of its own.High confidence
Who enforces this — and are they actually working?
Six bodies, and all six are genuinely working. The Hellenic Data Protection Authority is the main privacy regulator and is issuing numbered decisions and fines every month — its most recent published decisions run to July 2026 and include fines on a bank and an electricity supplier. A separate constitutional authority polices the secrecy of communications. There is also a national cybersecurity authority, a telecoms regulator, the central bank for finance and insurance, and a gambling regulator. This is not a paper regime.High confidence
How long must I keep it, and when must I delete it?
Both directions apply, and they collide. Business books must be kept five years. Medical files must be kept ten years in a private practice and twenty years everywhere else. Online gambling records must be kept ten years. Telecoms connection records must be kept exactly twelve months and then automatically deleted. In the other direction, the European rule says you must not keep personal data longer than you need it. When a specific keeping rule and the general deleting rule clash, the specific keeping rule wins.High confidence
What happens when something goes wrong?
Count three clocks, not one. If personal data is lost or exposed, you have 72 hours to tell the privacy regulator. If you run important infrastructure, you have only 24 hours to send a first warning to the national cybersecurity authority, then 72 hours for a fuller report and one month for the final one. If you are a phone or internet provider, you have 24 hours to report a personal data breach and a separate duty to tell the communications secrecy authority. Missing the 24-hour clocks is the most common failure.High confidence
What's the trap?
Five things that will cost you a weekend. First, a child in Greece can consent to an online service at fifteen, not sixteen — so an age gate built to the European default is set wrong. Second, misusing personal data is a crime here, with prison time, not just a fine. Third, several articles of the Greek privacy law are printed in the statute but the regulator has formally said they must not be applied, because they clash with European law. Fourth, telecoms connection records must physically stay in Greece. Fifth, government bodies cannot simply pick a commercial cloud.High confidence
What's about to change?
Three dated changes. Electronic invoicing between businesses became compulsory for large Greek companies on 2 March 2026 and becomes compulsory for everyone else on 1 October 2026. Greece's new artificial intelligence law took effect on 22 July 2026 and forces public bodies to register every artificial intelligence system before switching it on. And from 12 January 2027 European law bans cloud providers from charging you to move your data out.High confidence
Hardest industry wall
  • Telecoms Νόμος 3917/2011 — Διατήρηση δεδομένων που παράγονται ή υποβάλλονται σε επεξεργασία σε συνάρτηση με την παροχή υπηρεσιών ηλεκτρονικών επικοινωνιών
  • Online gaming Νόμος 4002/2011 — Ρύθμιση της αγοράς παιγνίων, άρθρο 47, και Κανονισμοί Παιγνίων (ΥΑ 79305/2020 και 79835/2020)
  • Government Νόμος 4727/2020 — Ψηφιακή Διακυβέρνηση, άρθρο 87 (Κυβερνητικά νέφη)