Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
BelgiumChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- For an ordinary business Belgium follows the normal European rules: data may leave the country once you have the right paperwork. Belgium adds no general permission step of its own. Three specific areas are much harder. Online gambling operators must run their servers on Belgian soil. Phone and internet companies must keep the connection records they hold for the police inside Europe. And a foreign company with a Belgian branch must keep that branch's accounting records in Belgium.
- The catch
- The relaxed headline stops being true the moment you touch online gambling, telephone or internet network records, or the books of a Belgian branch of a foreign company. Belgium is also one of the few European countries where sending data abroad without the right safeguards is a criminal offence, not just a regulator's fine, and where a public prosecutor taking the file can strip the privacy regulator of its power to act.
- Does this apply to me?
- Yes. Europe's General Data Protection Regulation reaches any company anywhere in the world that offers goods or services to people in Belgium, or that monitors what they do. There is no minimum size, revenue or number of customers. If your company has no establishment anywhere in Europe you must appoint a representative inside Europe who can be contacted and, in practice, sued. Belgium adds its own layer on top of the European rules, and one Belgian choice matters early: a child can consent for themselves from the age of thirteen.High confidence
- Can the data leave the country?
- In general, yes, with the standard European paperwork, and Belgium adds no extra approval of its own. But check your industry before you believe that. Online gambling companies must keep the servers that run their website and its data in a permanent establishment in Belgium. Telephone and internet companies must keep the subscriber and connection records they hold for the authorities inside the European Union, and must hand them over in Belgium. A foreign company with a Belgian branch must keep that branch's books and receipts in Belgium, at least as a copy. Banking, insurance, health and government work have no Belgian storage-location rule that we could find.High confidence
- What do I have to do to send it abroad?
- Use the ordinary European toolkit. If the destination country is on Europe's approved list, nothing more is needed. If it is not, you sign Europe's standard contract clauses and check whether local surveillance law undermines them. Large corporate groups can instead get their own internal rules approved, and the Belgian regulator does approve them: it signed off one multinational's group rules in May 2026. Belgium adds no national filing, translation or approval step on top.High confidence
- Who enforces this — and are they actually working?
- The Data Protection Authority, and it is genuinely working. It has a president, five internal bodies and a published register of 1,242 decisions, of which 224 were issued in 2025 and 111 in the first seven and a half months of 2026. Its most recent published opinions are dated 17 August 2026, the day before this record was written. Appeals go to the Market Court, a chamber of the Brussels Court of Appeal, which has published 99 judgments in these cases. Several other regulators enforce alongside it, and they are all staffed.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling, and they point in opposite directions. Business records must be kept seven years, counted from the first of January after the year you close the books; receipts that will never be used as proof against an outsider can go after three. Phone and internet companies must keep subscriber records for twelve months after the service ends. In the other direction, security camera footage must normally be deleted within one month, and everything else must go once you no longer need it. When a keeping duty and a deletion duty collide, the keeping duty wins, because European law expressly allows you to refuse an erasure request where a legal obligation requires you to hold the data.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. For a personal data breach you have 72 hours to tell the privacy regulator. For a significant cybersecurity incident, if you fall under Belgium's network and information security law, you have 24 hours for a first warning, 72 hours for the full report, and one month for the final report. Trust service providers get 24 hours for that middle step, not 72. Financial firms report separately under Europe's operational resilience rules. Missing the 24-hour warning while you are still assembling the 72-hour privacy notification is the most common failure.High confidence
- What's the trap?
- Five things that are not in the summary. One: sending personal data abroad without the right safeguards is a crime in Belgium, not just a regulator's fine, and a court can order the judgment printed in newspapers at your expense. Two: if a public prosecutor picks up the same facts within two months, the privacy regulator loses the power to punish you, so your risk moves from an administrative file to a criminal one. Three: government bodies in Belgium generally cannot be fined at all under the European rules, so a complaint against a public body ends in orders, not money. Four: you may not use the Belgian national identity number without permission from the Interior Minister. Five: security cameras need a notification, an internal register and a one-month deletion rule of their own.High confidence
- What's about to change?
- The biggest change is a change of style, not of law. The privacy regulator published a three-year plan in December 2025 saying it will stop being driven mainly by complaints and start picking its own targets, with two named priorities: very large data operations that put people at real risk, and anything involving children. Europe adds two dates: from the twelfth of January 2027 cloud providers may no longer charge you to move your data out, and the approval that lets data flow to self-certified American companies is under formal challenge. Watch the quiet levers too: Belgium's telephone-record retention map can be redrawn by a ministerial decree with no consultation.High confidence
- Hardest industry wall
- Online gaming — Loi du 7 mai 1999 sur les jeux de hasard, les paris, les etablissements de jeux de hasard et la protection des joueurs, article 43/8
- Telecoms — Loi du 20 juillet 2022 relative a la collecte et a la conservation des donnees d'identification et des metadonnees dans le secteur des communications electroniques et a la fourniture de ces donnees aux autorites
- All industries — Loi comptable du 17 juillet 1975, article 1er, alinea 2, recodifiee dans le Code de droit economique
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
- The catch
- The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
- Does this apply to me?
- Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
- Can the data leave the country?
- Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
- What do I have to do to send it abroad?
- The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
- Who enforces this — and are they actually working?
- The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
- What happens when something goes wrong?
- There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
- What's the trap?
- Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
- What's about to change?
- Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
- Hardest industry wall
- Telecoms — Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
- E-commerce — Loi n° 18-05 relative au commerce electronique
- Government — Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees