Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
BruneiChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Waking up
- In one paragraph
- Brunei got its first privacy law in January 2025 and a senior official said on 17 August 2026 that it is now in force. Data may leave the country, but only if the place it goes to protects it about as well as Brunei does. Nothing has to be stored inside Brunei. The regulator is running training and has a breach form, but we found no fines or public decisions yet.
- The catch
- The relaxed national picture stops at four doors. Insurance and Islamic insurance firms need the central bank's approval before handing operations or hosting to an outside supplier. Investment firms must give the central bank 30 days' notice. Banks must tell the central bank before signing any cloud contract touching a critical system, and have ONE HOUR to report a suspected cyber attack. Operators of systems the government has labelled critical are told to keep a local anchor point inside Brunei even when they use a foreign cloud.
- Does this apply to me?
- Yes. The law reaches a company that has no office, no staff and no company registration in Brunei. It defines an 'organisation' as any person or body, whether or not it was set up under Brunei law and whether or not it lives or has a place of business in Brunei. There is no revenue or headcount threshold to fall below, and no requirement to appoint a local representative. You do have to name at least one person, anywhere, as your data protection officer, and publish their business contact details.High confidence
- Can the data leave the country?
- Yes, with conditions. Brunei has no rule saying data must stay in the country. The privacy law says you may only send personal data abroad if the people receiving it give it protection comparable to Brunei's. There is no list of approved or banned countries. Four industries add their own gates on top, and one of them comes close to a keep-a-copy-here rule.High confidence
- What do I have to do to send it abroad?
- There is no approved-country list and no banned-country list. Instead you carry the burden yourself: before data leaves, you must be able to show the recipient will protect it about as well as Brunei's own law does, normally by writing that promise into your contract. The regulator can also give a single company a written exemption from those conditions. That exemption does not have to be published and can be cancelled at any time.Medium confidence
- Who enforces this — and are they actually working?
- Three regulators matter. The communications regulator, known as AITI, runs the privacy law: it has a data protection office, a breach reporting form, a complaints form, published guides and a training programme for data protection officers, and it ran awareness sessions for industry in February 2026. We found no fines, orders or published decisions from it, so treat it as waking up rather than active. The central bank is genuinely active in banking, insurance and investment. The Commissioner of Cybersecurity, working through Cyber Security Brunei, runs the critical systems regime and has published binding codes and guidelines.Medium confidence
- How long must I keep it, and when must I delete it?
- The ceiling is a judgement call, not a number. You must stop keeping documents containing personal data, or strip out what identifies people, as soon as it is reasonable to assume the purpose is finished and there is no legal or business reason to keep it. Brunei sets no maximum number of years. On the floor side we could not verify the general tax and company record-keeping minimums from an official source, because the government's own law library was unreachable on the day we checked.Medium confidence
- What happens when something goes wrong?
- Count four clocks, and the shortest is brutal. A bank has ONE HOUR from discovering a suspected cyber intrusion to tell the central bank, then TWO HOURS to say whether it was real, and it must not make any public announcement before that. A Ministry of Health contractor has 24 hours. Under the privacy law you must first assess whether the breach is serious, then tell the regulator no later than THREE DAYS after you finish that assessment, and tell the affected people too. Owners of critical national systems must report to the Commissioner of Cybersecurity within a period the government sets, and we could not find that period published.High confidence
- What's the trap?
- Five things that are not in the summary. One: the privacy law does not apply to any government body, so a public hospital or ministry is outside it and your only protection is the contract they give you. Two: any other Brunei law beats the privacy law where the two disagree, so a banking secrecy or national security rule wins. Three: the regulator can quietly exempt one company from the transfer rules, need not publish that exemption, and can cancel it whenever it likes — so you cannot see what your competitor has been allowed to do. Four: ordinary staff, not just companies, commit a crime if they leak personal data, misuse it for gain, or work out who anonymous data belongs to. Five: texting or calling any Brunei phone number for marketing needs clear and unambiguous consent, with no soft opt-in from an existing customer relationship.High confidence
- What's about to change?
- The big missing piece is the industry-by-industry guidance. The regulator consulted banks, insurers, telecoms operators, hospitals and schools in February 2024 and promised the guidelines for 2025. They were still not published on 18 August 2026. The national cyber agency published a cloud policy for critical systems on 19 February 2026 that introduces the local anchor idea, and that idea could harden into a binding code. Brunei also has a guide on artificial intelligence ethics, now in a second edition, which is advice rather than law.Medium confidence
- Hardest industry wall
- Government — Cloud Security Policy Guidelines for Critical Information Infrastructure (CII)
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
- The catch
- The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
- Does this apply to me?
- Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
- Can the data leave the country?
- Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
- What do I have to do to send it abroad?
- The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
- Who enforces this — and are they actually working?
- The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
- What happens when something goes wrong?
- There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
- What's the trap?
- Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
- What's about to change?
- Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
- Hardest industry wall
- Telecoms — Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
- E-commerce — Loi n° 18-05 relative au commerce electronique
- Government — Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees