Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
BrazilChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
In one paragraph
Brazil does not force data to stay inside the country. Personal data can leave, but since August 2025 you normally need a contract written by the regulator, word for word, signed with whoever receives it. Sending data to the European Union needs nothing extra. The regulator is awake and has started switching features off large platforms.
The catch
Brazil is often listed as a data-localisation country. It is not one. The old rule that pushed federal government email and data onto Brazilian systems was scrapped in 2018, and today's federal cloud rules do not require Brazilian soil. The real constraints are different in shape: banks must keep the central bank able to reach their data wherever it sits, and since July 2026 digital platforms must have an actual office and a legal representative inside Brazil.
Does this apply to me?
Yes. Brazil's privacy law reaches a company with no office in Brazil, as long as it collects data in Brazil or offers goods or services to people here. There is no size or revenue threshold that lets you out. The privacy law itself does not make you appoint anyone local — but two newer rules do, and if you run a digital platform you now need a registered office and a legal representative in Brazil.High confidence
Can the data leave the country?
Yes, with paperwork. Brazil has no rule making anyone keep a copy of anything inside the country — not for banks, not for hospitals, not even for the federal government's own cloud. What it has instead is a permission slip: before personal data leaves, you need one of a short list of approved legal grounds. Industry rules add conditions on top, but none of them is a wall.High confidence
What do I have to do to send it abroad?
Pick one of five routes. The easy one is the European Union: since January 2026 Brazil treats it as safe, so nothing extra is needed. For everywhere else, the normal route is a set of standard contractual clauses that the regulator itself wrote — you copy them into your contract exactly, and you may not edit them. A deadline to retrofit older contracts already passed, on 23 August 2025.High confidence
Who enforces this — and are they actually working?
The National Data Protection Authority, and it is genuinely working. A law passed in February 2026 gave it real independence, 200 new specialist jobs and its own budget. In August 2026 it ordered Discord to switch off live video streaming in Brazil within three working days, to protect children. Banking, telecoms, insurance and securities regulators enforce their own rules in parallel and have done so for years.High confidence
How long must I keep it, and when must I delete it?
Both directions, and they pull against each other. The floor: internet access providers must keep connection records for one year, websites and apps must keep access records for six months, and tax records need five years. The ceiling: the privacy law says personal data must be deleted once you have finished doing what you collected it for. Where the two clash, the legal duty to keep wins — the law lists that as an express reason to hold on.High confidence
What happens when something goes wrong?
Count three clocks, not one. Privacy: three working days to tell the regulator AND the affected people, once you have confirmed a breach that could really hurt them. Platform content: two hours to take down intimate images shared without consent, once notified. On top of that, banks report incidents to the central bank and telecoms operators report to the telecoms regulator under their own separate timetables.High confidence
What's the trap?
Five. (1) Your European standard contract is not automatically good enough — Brazil wrote its own clauses and you must copy them exactly, unedited, and the deadline to fix old contracts passed on 23 August 2025. (2) A child in Brazil is under 12 and an adolescent is 12 to 17, but the social media rule bites at 16 — accounts for anyone up to 16 must be tied to a parent's account, and asking users to state their own age is banned. (3) Since 20 July 2026 a digital platform needs an actual registered office in Brazil, not just a lawyer on retainer. (4) The biggest fine is not in the privacy law: the internet law allows up to 10 percent of your group's Brazilian revenue. (5) The regulator can order your database blocked or your processing suspended, which usually hurts more than any cheque.High confidence
What's about to change?
One firm date: January 2027, when the regulator moves from monitoring platforms to full enforcement of the children's digital rules. Brazil's artificial intelligence bill is still only a bill — it was sitting in a committee waiting for a report as recently as June 2026, so do not plan around it. The bigger risk is not new law: it is that the regulator can add or withdraw approved destinations for data transfers by publishing a single resolution, with no consultation.High confidence
Hardest industry wall
None found.
JapanChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Active
In one paragraph
Japan lets personal data leave the country, but you need paperwork. Only Europe and the United Kingdom are pre-approved. For anywhere else you either sign a contract that binds the recipient to Japanese-standard protection, or you get the person's consent after telling them which country the data goes to. There is no general rule forcing data to stay in Japan.
The catch
Two things break the calm headline. If you sell to the Japanese government, the data must physically sit in Japanese data centres. And if you run a website, an app or any online service used from Japan, the telecoms law reaches you even with no office here, requires a representative in Japan, and makes leaking a communication a criminal offence rather than a fine.
Does this apply to me?
Yes. Japan's privacy law reaches a foreign company with no office and no staff in Japan, as long as it handles the personal information of people in Japan while supplying them goods or services. There is no size, revenue or headcount threshold to fall below. Unlike Europe, the privacy law does not make you appoint a representative in Japan — but the telecoms law does, if your service counts as a telecommunications service.High confidence
Can the data leave the country?
Yes, with paperwork. Japan's general rating is conditional: personal data may go abroad once you have one of three things in place. There is no across-the-board law keeping data in Japan, and no financial, insurance, securities or health localisation rule of the kind India or China have — we searched for one and did not find it. The real wall is government work: anything running on the national Government Cloud must sit in data centres inside Japan.High confidence
What do I have to do to send it abroad?
The model is an allowlist, and the list has exactly two entries: the European Union and the United Kingdom. Send data there and it is treated almost like a domestic transfer. For every other destination you need one of two things instead. Either the recipient is contractually bound to protect the data to Japanese standards and you keep checking that it does, or you get the person's consent after first telling them the destination country, what its privacy law is like, and what the recipient will do to protect the data.High confidence
Who enforces this — and are they actually working?
The Personal Information Protection Commission, and it is genuinely working. It has a chair, eight commissioners and a staff ceiling of 231 people. In the year to March 2025 it handled just over 19,000 breach reports, gave 395 pieces of formal guidance and made one recommendation. In the first six months of the following year it sharpened up: two recommendations and its first emergency order, against a company misusing personal information. What it cannot do yet is fine you — Japan has no administrative money penalty for privacy breaches until the 2026 amendment starts.High confidence
How long must I keep it, and when must I delete it?
The floor is firm and the ceiling is soft. Tax law makes you keep books and records for seven years, stretching to ten if you carry a loss forward. Company accounting books run ten years. Against that, the privacy law only asks you to try to delete personal data once you no longer need it — it is a best-efforts duty, not a hard deadline. So when the two collide, the keep-it rule wins in practice.Medium confidence
What happens when something goes wrong?
Count three clocks. For a personal data breach you file a first report to the privacy regulator within three to five days of finding out, and a full report within 30 days — 60 days if someone did it on purpose. You must also tell the people affected. Critical infrastructure operators have a separate cyber incident duty with a report to the government within 30 days. Telecoms operators report leaks of communications to the communications ministry on their own timetable.High confidence
What's the trap?
Five. (1) Putting data on a foreign server is often not a 'transfer' at all — if the provider is contractually barred from touching it — but you then have to work out that country's privacy law and publish the country's name to your users. Most people miss this. (2) The privacy law has no fines: the sanctions are criminal, and a company can be fined about $650,000 for a staff member stealing a customer database. (3) Leaking a communication is a crime punishable with prison, and telecoms staff face a longer term than outsiders. (4) The telecoms rules catch ordinary websites and apps, not just phone companies, and reach foreign operators with no office in Japan. (5) Consent to send data 'overseas' is not valid — you have to name the country.High confidence
What's about to change?
The big one has already passed. On 17 July 2026 Japan published a large amendment to its privacy law. It introduces the country's first money penalty for privacy breaches, sets 16 as the age below which a guardian must be involved, adds rules for face and other biometric data, and raises the criminal penalties. It is not in force yet: the government has up to two years to switch it on by order, and no date has been announced. The other thing to watch is the new cyber defence law, which is being switched on in stages through 2027.High confidence
Hardest industry wall
  • Government デジタル庁におけるガバメントクラウド等の整備のためのクラウドサービスの提供 — 令和8年度募集 調達仕様書