Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
SwitzerlandChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
In one paragraph
Switzerland is easy to send data out of, as long as the destination is one the government trusts. An official list names about 44 approved places, including every European Union country and United States firms in one certification scheme. Anywhere else, you sign an approved contract first. The sting is elsewhere: getting it wrong is a crime, and the case lands on a person, not the company.
The catch
The relaxed headline stops the moment you touch three areas. Electronic patient record data must physically sit in Switzerland. Banking client data is protected by a criminal secrecy law with a three-year prison ceiling. Doctors, lawyers, notaries, pharmacists, psychologists and nurses are under a near-identical criminal secrecy rule, and a normal supplier contract does not cure it. Financial market infrastructures also need the regulator's permission before outsourcing anything important.
Does this apply to me?
Yes. Swiss privacy law reaches any organisation whose activities have an effect in Switzerland, even one with no office, staff or company here. There is no revenue or headcount threshold to duck under, and there is no register to sign up to. You only need a named representative inside Switzerland if four things are true at once: you are selling to people here or watching what they do, you are doing it on a large scale, you are doing it regularly, and the processing is high risk for the people involved. Very few foreign companies meet all four.High confidence
Can the data leave the country?
In general, yes. Switzerland publishes an official list of countries and territories it considers safe, and data can move to any of them with no extra paperwork. The list has about 44 entries. It covers all 27 European Union countries, the United Kingdom, Norway, Iceland, Liechtenstein, Canada, Israel, Argentina, Uruguay and New Zealand. It covers the United States only for companies signed up to one specific certification scheme. Japan is not on it, even though the European Union treats Japan as safe. For anywhere not on the list, you sign an approved contract first. But three industries override this completely, and one of them is an outright ban.High confidence
What do I have to do to send it abroad?
The model is an approved-destinations list, and it is well populated: about 44 countries, territories and one sector-specific entry are on it right now. Send data to a listed place and you need nothing at all. Send it anywhere else and you need one of a short menu of safeguards, the most common being a standard contract. Switzerland has formally accepted the European Union's standard contract template, so most companies can reuse the paperwork they already have.High confidence
Who enforces this — and are they actually working?
The main regulator is the Federal Data Protection and Information Commissioner. It is real, fully staffed and busy: in the year to 31 March 2026 it ran 156 low-level interventions, 22 preliminary enquiries and 9 formal investigations, and it had 2 cases running in the Federal Administrative Court. It has issued binding orders against a bank, a debt collection firm and a fashion group, and in October 2025 the court confirmed its new way of working. The catch is that this regulator cannot fine anyone. Fines under the privacy law are criminal, they are handed out by cantonal prosecutors, and they land on individual people.High confidence
How long must I keep it, and when must I delete it?
Both directions apply and they pull against each other. The floor: business books, accounting records and audit reports must be kept for ten years. Financial market infrastructures keep their records ten years, trade repositories keep trade data ten years after the contract matures, electronic patient record access logs are kept ten years, and telecoms companies keep connection records for six months. The ceiling: the privacy law says personal data must be destroyed or made anonymous as soon as it is no longer needed. There is no fixed number. Where the two clash, the specific legal duty to keep wins.High confidence
What happens when something goes wrong?
Count four clocks, not one. The privacy regulator must be told 'as quickly as possible' when a breach is likely to put people at serious risk, with no number of hours attached. If you run critical infrastructure, you have a hard 24 hours to tell the national cyber security office. If you are supervised by the financial regulator, you have 24 hours to notify your supervisor and 72 hours to file the full report. Electronic patient record communities have to report security incidents to the health office. Most failures come from teams who set a single deadline and miss the others.High confidence
What's the trap?
Five things that are not in the summary. One: the penalty is a criminal fine on a named human being, not an administrative fine on the company, so your compliance lead is personally exposed. Two: sending data abroad without a valid safeguard is itself a crime. Three: banking secrecy and medical or legal secrecy are criminal laws with prison ceilings, and a standard supplier contract does not fix them. Four: cantonal authorities and cantonal hospitals are outside the federal law entirely. Five: the 24-hour cyber report has no penalty for being late, which misleads people into thinking it is optional.High confidence
What's about to change?
Nothing in the next twelve months changes where Swiss data may be stored. The electronic identity law has passed but is not switched on yet, and the financial regulator is holding a rule change until it is. A company transparency law hits banks on 1 October 2026. A rewrite of the telecoms surveillance rules has been announced for years and still has not landed. The bigger risk is not new legislation at all: the government can rewrite the approved-destinations list by itself, overnight, with no vote and no consultation.Medium confidence
Hardest industry wall
  • Health and social care Verordnung ueber das elektronische Patientendossier (EPDV)
  • Finance FINMA-Rundschreiben 2018/3 'Outsourcing - Banken, Versicherungsunternehmen und ausgewaehlte Finanzinstitute nach FINIG'
IsraelChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
In one paragraph
Israeli data can go abroad, but never by default. Either the destination country protects data as well as Israel does, or you fit one of eight listed exceptions — usually a contract in which the receiver promises to follow Israeli rules. A big reform started on 14 August 2025 and the regulator now issues real fines. No industry bans exports outright, but several add heavy conditions.
The catch
The general answer is 'yes, with paperwork'. It stops being true in four places. Banks may not put sensitive customer data on a cloud outside Israel unless they have checked the provider meets European-level protection. Insurers and pension bodies must report every offshore outsourcing arrangement to their regulator each year. Identifiable patient data used for research must generally stay inside the hospital or health fund that holds it, not merely inside Israel. And central government has moved its own cloud into Israeli data-centre regions on purpose, so selling cloud to the state effectively requires an Israeli region.
Does this apply to me?
Yes, it can reach a foreign company with no office in Israel — but the law never says so in words. Israeli privacy law simply applies to anyone who collects, uses or processes personal data, with no size or revenue threshold to fall under. There is no general requirement to appoint a local representative. Some organisations must appoint a privacy officer, and that person is allowed to be an outside contractor rather than a staff member.Medium confidence
Can the data leave the country?
Yes, with paperwork — and you must be able to name the route you are using. The default rule is that data may only go to a country whose law protects it at least as well as Israeli law does. If the destination fails that test, you have to fit one of eight listed exceptions, and whichever route you take you also need a written promise from the receiver. No Israeli industry has a flat 'the data stays here' rule, but four sectors bolt extra conditions on top.High confidence
What do I have to do to send it abroad?
The model is closest to an allowlist: you may not send data out unless the destination qualifies, and the qualifying list is already populated. It counts if the country signed the Council of Europe data protection convention, or if it receives data from European Union countries on the same terms — so Europe's approved-country list does much of the work. If your destination does not qualify, the usual fallback is a contract in which the receiver promises to meet Israeli standards. Either way you also need a separate written promise from the receiver that it will protect the data and pass it to nobody else.High confidence
Who enforces this — and are they actually working?
The Privacy Protection Authority, part of the Ministry of Justice, and it is fully operational. It has a serving commissioner, an administrative enforcement department, and it publishes its decisions with names and amounts. In 2026 it fined a national health fund about 256,000 shekels (roughly $72,000) for taking two months to report a security incident, and a small leisure company about 12,000 shekels (roughly $3,400) for a defective privacy notice. Industry regulators — the Bank of Israel, the insurance regulator and the Ministry of Health — enforce their own rules separately.High confidence
How long must I keep it, and when must I delete it?
There is a clear floor and a clear ceiling, and they sit close together. The floor: security and access-monitoring records must be kept for at least 24 months, and organisations with medium or high security databases must keep a restorable backup of them. The ceiling: if a database contains anything that came from Europe, you must run a mechanism that finds data you no longer need and delete it, and you must delete data on request. Where another law says you must keep something, that wins over the duty to delete.High confidence
What happens when something goes wrong?
There is one main clock and it has no hours attached to it: a severe security incident must be reported to the Privacy Protection Authority immediately, along with what you did about it. 'Immediately' is taken literally — a health fund was fined for a two-month delay. Telling the affected people is not automatic; the Authority decides, after consulting the national cyber agency, and can order you to notify them. Israel has no general law forcing every company to report cyber incidents to the state, so your second clock, if you have one, comes from your industry regulator.High confidence
What's the trap?
Five things that are not in the summary. One: a single record that arrived from Europe drags the whole database into the stricter European rules — since 1 January 2025 those rules apply to any other data sitting in the same database. Two: 'immediately' really means immediately, and there is no safe 72-hour habit to fall back on. Three: fines are calculated per person, not as a flat cap, so a large database turns a small breach into a very large bill. Four: privacy breaches are criminal offences, not just regulatory ones, with prison terms attached. Five: 'data security officer' and 'data protection officer' are two different Israeli roles with different triggers, and having one does not satisfy the other.High confidence
What's about to change?
The big change already happened on 14 August 2025. What is landing now is the detail underneath it. In April 2026 the regulator finalised its binding rules on the contract you must sign before sending data abroad, and separate regulations came into force giving a short grace period — a warning instead of a fine — for brand-new obligations. A guideline applying privacy law to artificial intelligence, including a requirement of consent before scraping the web to train models, is also in play. Watch three switches the government can flip without warning.Medium confidence
Hardest industry wall
  • Health and social care חוזרי מנכ"ל משרד הבריאות 1/2018 ו-2/2018 - שימושים משניים במידע בריאות
  • Government פרויקט נימבוס - מדיניות הענן הממשלתית