Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
BahrainChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Bahrain bans sending personal data abroad unless you fit an exception. The main exception is an official list of more than eighty approved countries, which includes the United States, China, Russia and every Gulf neighbour. Nothing has to be stored inside Bahrain. The paperwork is heavy: you usually tell the regulator before you start, and breaking the rules is a crime.
- The catch
- Bahrain has no data localisation rule in any sector we could find, but banks, insurers, investment firms and payment companies need the central bank's written approval, thirty days ahead, before handing work to a supplier outside Bahrain.
- Does this apply to me?
- Yes. The law catches a company anywhere in the world if it handles people's data using equipment sitting inside Bahrain, even with no office and no staff there. There is no size, revenue or headcount threshold to fall below. A foreign company in that position must appoint a representative in Bahrain who takes on its duties, and must tell the regulator who that is.High confidence
- Can the data leave the country?
- Yes, but only through a defined gate. The starting position is that moving personal data out of Bahrain is forbidden. It becomes legal if the destination is on the government's approved-country list, which names more than eighty places including the United States, China, Russia, India and all of Bahrain's Gulf neighbours. If your destination is not on that list, you ask the regulator for permission for that specific transfer, or you rely on one of six narrow exceptions such as the person's consent.High confidence
- What do I have to do to send it abroad?
- This is an approved-list system: banned unless allowed. The list is real and full, not empty, and it was published in March 2022 with more than eighty countries and territories on it. Send data to a listed place and you need no paperwork and no permission. Send it anywhere else and you need written permission from the regulator for that transfer, or one of six exceptions: the person agreed, the data came from a public register, the transfer is needed for a contract, to protect someone's life, to obey a law or court order, or to bring or defend a legal claim.High confidence
- Who enforces this — and are they actually working?
- On paper the Personal Data Protection Authority. In practice there is no separate authority: a royal decree in 2019 handed its powers to the Ministry of Justice, with the minister acting as the board and the ministry's undersecretary as chief executive, until money and a board decree arrive. That arrangement is still in place in August 2026. It does work - it publishes ten binding orders and runs live forms for registrations, permissions, breach reports and complaints - but we found no published fines or decisions, so treat enforcement as switched on and quiet rather than aggressive. The central bank, by contrast, supervises finance actively and consults on new rules constantly.Medium confidence
- How long must I keep it, and when must I delete it?
- There is a ceiling in the general law and floors in specific industries. The ceiling: once you have done what you collected the data for, you may not keep it in a form that still identifies the person, and anything held long term should be anonymous or encrypted. You must also set and follow your own written retention and deletion schedule. The clearest floor we could verify is in finance, where security event logs must be kept for at least five years.Medium confidence
- What happens when something goes wrong?
- You have 72 hours. From the moment you discover a personal data breach, you must tell the regulator, using its online breach form, and you must also tell the people affected unless the data was unreadable to outsiders, for example properly encrypted, or the risk has since been removed. You must keep your own written record of every breach, its causes, its effects and what you did about it. Financial firms have a second, separate reporting line to their supervisor and to the national cyber centre.High confidence
- What's the trap?
- Five things catch people out. First, breaking these rules is a crime: up to one year in prison and a fine of 1,000 to 20,000 Bahraini dinars, roughly 2,600 to 53,000 US dollars, including for sending data abroad unlawfully. Second, you normally have to tell the regulator before you start automated processing at all, and get written permission first for sensitive data, biometrics, genetic data, security cameras and linking databases. Third, if the regulator says nothing within thirty days, that counts as a refusal, not approval. Fourth, a foreign company using equipment in Bahrain must appoint a local representative. Fifth, banks and insurers need central bank sign-off thirty days before signing an offshore supplier.High confidence
- What's about to change?
- Nothing new is scheduled to hit the general privacy law in the next twelve months as far as we can see. The action is in finance: the central bank is rewriting its payments rules, with a new payment service provider module out for comment in February 2026 and a buy-now-pay-later module from November 2025. The bigger risks are two switches the government can flip without warning: the approved-country list can be changed by a ministerial order, and a single decree could finally stand up a real data protection authority with its own board.Medium confidence
- Hardest industry wall
- None found.
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
- The catch
- The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
- Does this apply to me?
- Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
- Can the data leave the country?
- Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
- What do I have to do to send it abroad?
- The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
- Who enforces this — and are they actually working?
- The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
- What happens when something goes wrong?
- There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
- What's the trap?
- Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
- What's about to change?
- Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
- Hardest industry wall
- Telecoms — Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
- E-commerce — Loi n° 18-05 relative au commerce electronique
- Government — Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees