Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
SwitzerlandChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Switzerland is easy to send data out of, as long as the destination is one the government trusts. An official list names about 44 approved places, including every European Union country and United States firms in one certification scheme. Anywhere else, you sign an approved contract first. The sting is elsewhere: getting it wrong is a crime, and the case lands on a person, not the company.
- The catch
- The relaxed headline stops the moment you touch three areas. Electronic patient record data must physically sit in Switzerland. Banking client data is protected by a criminal secrecy law with a three-year prison ceiling. Doctors, lawyers, notaries, pharmacists, psychologists and nurses are under a near-identical criminal secrecy rule, and a normal supplier contract does not cure it. Financial market infrastructures also need the regulator's permission before outsourcing anything important.
- Does this apply to me?
- Yes. Swiss privacy law reaches any organisation whose activities have an effect in Switzerland, even one with no office, staff or company here. There is no revenue or headcount threshold to duck under, and there is no register to sign up to. You only need a named representative inside Switzerland if four things are true at once: you are selling to people here or watching what they do, you are doing it on a large scale, you are doing it regularly, and the processing is high risk for the people involved. Very few foreign companies meet all four.High confidence
- Can the data leave the country?
- In general, yes. Switzerland publishes an official list of countries and territories it considers safe, and data can move to any of them with no extra paperwork. The list has about 44 entries. It covers all 27 European Union countries, the United Kingdom, Norway, Iceland, Liechtenstein, Canada, Israel, Argentina, Uruguay and New Zealand. It covers the United States only for companies signed up to one specific certification scheme. Japan is not on it, even though the European Union treats Japan as safe. For anywhere not on the list, you sign an approved contract first. But three industries override this completely, and one of them is an outright ban.High confidence
- What do I have to do to send it abroad?
- The model is an approved-destinations list, and it is well populated: about 44 countries, territories and one sector-specific entry are on it right now. Send data to a listed place and you need nothing at all. Send it anywhere else and you need one of a short menu of safeguards, the most common being a standard contract. Switzerland has formally accepted the European Union's standard contract template, so most companies can reuse the paperwork they already have.High confidence
- Who enforces this — and are they actually working?
- The main regulator is the Federal Data Protection and Information Commissioner. It is real, fully staffed and busy: in the year to 31 March 2026 it ran 156 low-level interventions, 22 preliminary enquiries and 9 formal investigations, and it had 2 cases running in the Federal Administrative Court. It has issued binding orders against a bank, a debt collection firm and a fashion group, and in October 2025 the court confirmed its new way of working. The catch is that this regulator cannot fine anyone. Fines under the privacy law are criminal, they are handed out by cantonal prosecutors, and they land on individual people.High confidence
- How long must I keep it, and when must I delete it?
- Both directions apply and they pull against each other. The floor: business books, accounting records and audit reports must be kept for ten years. Financial market infrastructures keep their records ten years, trade repositories keep trade data ten years after the contract matures, electronic patient record access logs are kept ten years, and telecoms companies keep connection records for six months. The ceiling: the privacy law says personal data must be destroyed or made anonymous as soon as it is no longer needed. There is no fixed number. Where the two clash, the specific legal duty to keep wins.High confidence
- What happens when something goes wrong?
- Count four clocks, not one. The privacy regulator must be told 'as quickly as possible' when a breach is likely to put people at serious risk, with no number of hours attached. If you run critical infrastructure, you have a hard 24 hours to tell the national cyber security office. If you are supervised by the financial regulator, you have 24 hours to notify your supervisor and 72 hours to file the full report. Electronic patient record communities have to report security incidents to the health office. Most failures come from teams who set a single deadline and miss the others.High confidence
- What's the trap?
- Five things that are not in the summary. One: the penalty is a criminal fine on a named human being, not an administrative fine on the company, so your compliance lead is personally exposed. Two: sending data abroad without a valid safeguard is itself a crime. Three: banking secrecy and medical or legal secrecy are criminal laws with prison ceilings, and a standard supplier contract does not fix them. Four: cantonal authorities and cantonal hospitals are outside the federal law entirely. Five: the 24-hour cyber report has no penalty for being late, which misleads people into thinking it is optional.High confidence
- What's about to change?
- Nothing in the next twelve months changes where Swiss data may be stored. The electronic identity law has passed but is not switched on yet, and the financial regulator is holding a rule change until it is. A company transparency law hits banks on 1 October 2026. A rewrite of the telecoms surveillance rules has been announced for years and still has not landed. The bigger risk is not new legislation at all: the government can rewrite the approved-destinations list by itself, overnight, with no vote and no consultation.Medium confidence
- Hardest industry wall
- Health and social care — Verordnung ueber das elektronische Patientendossier (EPDV)
- Finance — FINMA-Rundschreiben 2018/3 'Outsourcing - Banken, Versicherungsunternehmen und ausgewaehlte Finanzinstitute nach FINIG'
BulgariaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Bulgaria is an ordinary European Union country for data. Personal data can leave, as long as you use one of the standard European transfer tools. There is no general rule forcing data to stay in Bulgaria. But online gambling is a hard exception: a control server must physically sit on Bulgarian soil. Bulgaria switched to the euro on 1 January 2026, so all fines are now in euro.
- The catch
- The relaxed headline stops being true in two places. First, online gambling: an operator licensed in Bulgaria must keep a control local server on Bulgarian territory and stream live game data to the tax authority's server. Second, telecoms: operators must build and pay for interception equipment wired into two Bulgarian state agencies, which cannot be run from abroad. Mapping and aerial survey work also needs clearance from five Bulgarian ministries and agencies before you may even collect the data.
- Does this apply to me?
- Yes, it can reach you with no office in Bulgaria. The European Union's privacy rulebook applies to anyone who offers goods or services to people in Europe or watches what they do online. Bulgaria's own Personal Data Protection Act sits on top of that and adds extra local duties. There is no revenue or headcount threshold, and no Bulgaria-specific representative: the European-wide requirement to name a representative in Europe is the only one, and it can be in any European country.High confidence
- Can the data leave the country?
- In general, yes. Bulgaria has no law telling ordinary businesses to keep personal data inside the country. Data moves freely to the rest of Europe, to Switzerland, and to countries Europe has approved; anywhere else needs a standard contract or a similar tool. Two industries break that pattern. Online gambling operators must keep a control server physically in Bulgaria. Telecoms operators must build interception equipment that plugs into Bulgarian state agencies, which cannot sit abroad.High confidence
- What do I have to do to send it abroad?
- Bulgaria uses Europe's system, not its own. There is no Bulgarian list of banned countries and no Bulgarian permit to apply for. If the destination is inside Europe, the wider European Economic Area or Switzerland, nothing extra is needed. Otherwise you need either an official European approval of that country, or the standard European contract, or approved group-wide rules. One Bulgarian twist: Bulgarian law explicitly puts Switzerland on the same footing as a European Union country.High confidence
- Who enforces this — and are they actually working?
- The Commission for Personal Data Protection is the main regulator. It is real, staffed and it does issue formal decisions, including ones published across Europe. But it is not a heavy hitter. In a Europe-wide check on deletion rights reported in February 2026, it contacted twenty-three organisations, opened no formal investigations, imposed no penalties, and said it did not plan to. A separate inspectorate polices the courts and prosecutors. Cybersecurity has its own separate regulators.Medium confidence
- How long must I keep it, and when must I delete it?
- Bulgaria has strong minimum-keeping rules and a few sharp delete-by rules. You must keep payroll records for fifty years, accounting books and financial statements for ten years, and other accounting papers for three years. Telecoms firms keep connection records for six months. Going the other way, job applicants' data must be deleted within six months unless they agree otherwise, and data you were given with no legal basis must be returned or destroyed within one month.High confidence
- What happens when something goes wrong?
- There are at least three clocks and they do not agree. A personal data breach must reach the privacy regulator within seventy-two hours. Under the cybersecurity law rewritten in February 2026, an early warning must reach the response team within twenty-four hours and a fuller report within seventy-two hours. Trust service providers get twenty-four hours for that fuller report. Financial firms answer to the separate European financial-resilience rules on top.High confidence
- What's the trap?
- Five things bite people in Bulgaria. You may not photocopy someone's identity card, driving licence or residence permit unless a law lets you. Children need a parent's consent up to age fourteen, not sixteen. Job applicant files must go within six months. Your accounting software must be able to output in Bulgarian. And one clause of the privacy law was struck down by the Constitutional Court in 2019 but is still printed in the statute.High confidence
- What's about to change?
- Two dated changes are already fixed. From 12 January 2027 every cloud provider must let customers move their data out for free. Bulgaria's new cybersecurity duties started on 13 February 2026 and enforcement is only now warming up. The biggest live risk is not Bulgarian at all: Europe's approval of United States data transfers is being challenged, and Europe's own privacy board asked the Commission on 31 July 2026 to re-examine it.High confidence
- Hardest industry wall
- Online gaming — Закон за хазарта