Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
BrazilChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Brazil does not force data to stay inside the country. Personal data can leave, but since August 2025 you normally need a contract written by the regulator, word for word, signed with whoever receives it. Sending data to the European Union needs nothing extra. The regulator is awake and has started switching features off large platforms.
- The catch
- Brazil is often listed as a data-localisation country. It is not one. The old rule that pushed federal government email and data onto Brazilian systems was scrapped in 2018, and today's federal cloud rules do not require Brazilian soil. The real constraints are different in shape: banks must keep the central bank able to reach their data wherever it sits, and since July 2026 digital platforms must have an actual office and a legal representative inside Brazil.
- Does this apply to me?
- Yes. Brazil's privacy law reaches a company with no office in Brazil, as long as it collects data in Brazil or offers goods or services to people here. There is no size or revenue threshold that lets you out. The privacy law itself does not make you appoint anyone local — but two newer rules do, and if you run a digital platform you now need a registered office and a legal representative in Brazil.High confidence
- Can the data leave the country?
- Yes, with paperwork. Brazil has no rule making anyone keep a copy of anything inside the country — not for banks, not for hospitals, not even for the federal government's own cloud. What it has instead is a permission slip: before personal data leaves, you need one of a short list of approved legal grounds. Industry rules add conditions on top, but none of them is a wall.High confidence
- What do I have to do to send it abroad?
- Pick one of five routes. The easy one is the European Union: since January 2026 Brazil treats it as safe, so nothing extra is needed. For everywhere else, the normal route is a set of standard contractual clauses that the regulator itself wrote — you copy them into your contract exactly, and you may not edit them. A deadline to retrofit older contracts already passed, on 23 August 2025.High confidence
- Who enforces this — and are they actually working?
- The National Data Protection Authority, and it is genuinely working. A law passed in February 2026 gave it real independence, 200 new specialist jobs and its own budget. In August 2026 it ordered Discord to switch off live video streaming in Brazil within three working days, to protect children. Banking, telecoms, insurance and securities regulators enforce their own rules in parallel and have done so for years.High confidence
- How long must I keep it, and when must I delete it?
- Both directions, and they pull against each other. The floor: internet access providers must keep connection records for one year, websites and apps must keep access records for six months, and tax records need five years. The ceiling: the privacy law says personal data must be deleted once you have finished doing what you collected it for. Where the two clash, the legal duty to keep wins — the law lists that as an express reason to hold on.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. Privacy: three working days to tell the regulator AND the affected people, once you have confirmed a breach that could really hurt them. Platform content: two hours to take down intimate images shared without consent, once notified. On top of that, banks report incidents to the central bank and telecoms operators report to the telecoms regulator under their own separate timetables.High confidence
- What's the trap?
- Five. (1) Your European standard contract is not automatically good enough — Brazil wrote its own clauses and you must copy them exactly, unedited, and the deadline to fix old contracts passed on 23 August 2025. (2) A child in Brazil is under 12 and an adolescent is 12 to 17, but the social media rule bites at 16 — accounts for anyone up to 16 must be tied to a parent's account, and asking users to state their own age is banned. (3) Since 20 July 2026 a digital platform needs an actual registered office in Brazil, not just a lawyer on retainer. (4) The biggest fine is not in the privacy law: the internet law allows up to 10 percent of your group's Brazilian revenue. (5) The regulator can order your database blocked or your processing suspended, which usually hurts more than any cheque.High confidence
- What's about to change?
- One firm date: January 2027, when the regulator moves from monitoring platforms to full enforcement of the children's digital rules. Brazil's artificial intelligence bill is still only a bill — it was sitting in a committee waiting for a report as recently as June 2026, so do not plan around it. The bigger risk is not new law: it is that the regulator can add or withdraw approved destinations for data transfers by publishing a single resolution, with no consultation.High confidence
- Hardest industry wall
- None found.
UkraineChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Ukraine still runs its 2010 privacy law, not a European-style one. Personal data may leave the country only to a country the law treats as safe — that means Europe and the 50-odd countries that signed a Council of Europe data treaty. The United States is not on that list. Fines are tiny, but the human rights Commissioner really does inspect, and misusing data can be a crime.
- The catch
- The general picture changes completely once government is involved. If a Ukrainian state body is the organisation deciding how personal data is used, only a Ukrainian state-owned or municipal company may process that data for it — a private or foreign supplier cannot. State systems, defence data and critical infrastructure also carry hard location rules, and several of the current permissions exist only because the country is under martial law.
- Does this apply to me?
- Probably not, if you have nothing in Ukraine. The 2010 law simply says it covers the processing of personal data by automated means or in structured paper files. It contains no clause reaching foreign companies that only sell into Ukraine from abroad, and it does not make you appoint a local representative. There is no size or revenue threshold either — a corner shop and a bank are treated the same.Medium confidence
- Can the data leave the country?
- Yes, but only to countries Ukraine already treats as safe. Those are the European Economic Area countries plus every country that has signed the Council of Europe's data protection treaty — roughly 55 states. The United States has signed neither, so routine transfers to American servers do not fit the safe-country route and need one of the narrow exceptions instead. Whole sectors then override this: government, defence and critical infrastructure are far tighter, and securities firms are unusually looser.High confidence
- What do I have to do to send it abroad?
- There is no form to file and no government permission to obtain. You either send the data to a country the law already treats as safe, or you rely on one of five narrow exceptions. Those are: the person's clear consent, necessity for a contract made for that person's benefit, protecting someone's life, an important public interest or a legal claim, and the sender giving guarantees that private and family life will not be interfered with. That last one is a catch-all that a lot of Ukrainian practice leans on.High confidence
- Who enforces this — and are they actually working?
- The Ukrainian Parliament Commissioner for Human Rights — the national ombudsman — is the data protection regulator, and it is genuinely working. It publishes a fresh inspection programme every three months; the one for July to September 2026 went up on 2 July 2026. It also publishes what it found, including a run of checks on the national electronic health system. The catch is the money: the regulator cannot fine anyone itself, it writes up a case and sends it to a court, and the maximum penalty is about $800.High confidence
- How long must I keep it, and when must I delete it?
- The floor comes from tax law. Companies must keep primary accounting documents and financial statements for 1,825 days — five years. Papers needed for transfer pricing checks run to 2,555 days, which is seven years. Everything else the tax authority may ask for runs 1,095 days, three years. The ceiling comes from the privacy law: you must delete personal data when the agreed storage period runs out, or when your relationship with the person ends, unless another law tells you to keep it.High confidence
- What happens when something goes wrong?
- This is the biggest surprise in Ukrainian law: if you lose personal data, there is no duty to tell the regulator and no duty to tell the people affected. The 2010 privacy law simply has no breach reporting clause. The only mandatory clocks sit in the cyber security regime, and they only bite if you run a state system or a piece of critical information infrastructure. Even there the law does not set the hours — it leaves the deadline to an order of the cyber agency.Medium confidence
- What's the trap?
- Five. (1) If a Ukrainian government body is the one deciding how personal data is used, only a Ukrainian state-owned or municipal company may handle that data for it — a private or foreign supplier is not allowed at all. (2) Misusing personal data is a crime, not just a fine, and repeat offences carry up to five years in prison. (3) The fines are aimed at named individuals and sole traders, not at companies. (4) Posting anything that shows where Ukrainian troops are carries five to eight years in prison. (5) Martial law lets the government limit the constitutional right to privacy that the whole system rests on.High confidence
- What's about to change?
- The date to watch is not a new law — it is the end of the war. Martial law was extended again on 13 July 2026 and now runs from 2 August 2026 for 90 days, so to about 31 October 2026. Several of today's permissions exist only while it lasts, and they die six months after it ends. A European-style replacement privacy law has been discussed for years and has still not been passed, so nothing about the current regime should be planned around its arrival.High confidence
- Hardest industry wall
- Government — Закон України "Про захист персональних даних", частина третя статті 4
- Government — Закон України "Про захист інформації в інформаційно-комунікаційних системах"
- Defence — Закон України "Про хмарні послуги"
- Mapping and location — Кримінальний кодекс України, стаття 114-2