Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
SwitzerlandChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Switzerland is easy to send data out of, as long as the destination is one the government trusts. An official list names about 44 approved places, including every European Union country and United States firms in one certification scheme. Anywhere else, you sign an approved contract first. The sting is elsewhere: getting it wrong is a crime, and the case lands on a person, not the company.
- The catch
- The relaxed headline stops the moment you touch three areas. Electronic patient record data must physically sit in Switzerland. Banking client data is protected by a criminal secrecy law with a three-year prison ceiling. Doctors, lawyers, notaries, pharmacists, psychologists and nurses are under a near-identical criminal secrecy rule, and a normal supplier contract does not cure it. Financial market infrastructures also need the regulator's permission before outsourcing anything important.
- Does this apply to me?
- Yes. Swiss privacy law reaches any organisation whose activities have an effect in Switzerland, even one with no office, staff or company here. There is no revenue or headcount threshold to duck under, and there is no register to sign up to. You only need a named representative inside Switzerland if four things are true at once: you are selling to people here or watching what they do, you are doing it on a large scale, you are doing it regularly, and the processing is high risk for the people involved. Very few foreign companies meet all four.High confidence
- Can the data leave the country?
- In general, yes. Switzerland publishes an official list of countries and territories it considers safe, and data can move to any of them with no extra paperwork. The list has about 44 entries. It covers all 27 European Union countries, the United Kingdom, Norway, Iceland, Liechtenstein, Canada, Israel, Argentina, Uruguay and New Zealand. It covers the United States only for companies signed up to one specific certification scheme. Japan is not on it, even though the European Union treats Japan as safe. For anywhere not on the list, you sign an approved contract first. But three industries override this completely, and one of them is an outright ban.High confidence
- What do I have to do to send it abroad?
- The model is an approved-destinations list, and it is well populated: about 44 countries, territories and one sector-specific entry are on it right now. Send data to a listed place and you need nothing at all. Send it anywhere else and you need one of a short menu of safeguards, the most common being a standard contract. Switzerland has formally accepted the European Union's standard contract template, so most companies can reuse the paperwork they already have.High confidence
- Who enforces this — and are they actually working?
- The main regulator is the Federal Data Protection and Information Commissioner. It is real, fully staffed and busy: in the year to 31 March 2026 it ran 156 low-level interventions, 22 preliminary enquiries and 9 formal investigations, and it had 2 cases running in the Federal Administrative Court. It has issued binding orders against a bank, a debt collection firm and a fashion group, and in October 2025 the court confirmed its new way of working. The catch is that this regulator cannot fine anyone. Fines under the privacy law are criminal, they are handed out by cantonal prosecutors, and they land on individual people.High confidence
- How long must I keep it, and when must I delete it?
- Both directions apply and they pull against each other. The floor: business books, accounting records and audit reports must be kept for ten years. Financial market infrastructures keep their records ten years, trade repositories keep trade data ten years after the contract matures, electronic patient record access logs are kept ten years, and telecoms companies keep connection records for six months. The ceiling: the privacy law says personal data must be destroyed or made anonymous as soon as it is no longer needed. There is no fixed number. Where the two clash, the specific legal duty to keep wins.High confidence
- What happens when something goes wrong?
- Count four clocks, not one. The privacy regulator must be told 'as quickly as possible' when a breach is likely to put people at serious risk, with no number of hours attached. If you run critical infrastructure, you have a hard 24 hours to tell the national cyber security office. If you are supervised by the financial regulator, you have 24 hours to notify your supervisor and 72 hours to file the full report. Electronic patient record communities have to report security incidents to the health office. Most failures come from teams who set a single deadline and miss the others.High confidence
- What's the trap?
- Five things that are not in the summary. One: the penalty is a criminal fine on a named human being, not an administrative fine on the company, so your compliance lead is personally exposed. Two: sending data abroad without a valid safeguard is itself a crime. Three: banking secrecy and medical or legal secrecy are criminal laws with prison ceilings, and a standard supplier contract does not fix them. Four: cantonal authorities and cantonal hospitals are outside the federal law entirely. Five: the 24-hour cyber report has no penalty for being late, which misleads people into thinking it is optional.High confidence
- What's about to change?
- Nothing in the next twelve months changes where Swiss data may be stored. The electronic identity law has passed but is not switched on yet, and the financial regulator is holding a rule change until it is. A company transparency law hits banks on 1 October 2026. A rewrite of the telecoms surveillance rules has been announced for years and still has not landed. The bigger risk is not new legislation at all: the government can rewrite the approved-destinations list by itself, overnight, with no vote and no consultation.Medium confidence
- Hardest industry wall
- Health and social care — Verordnung ueber das elektronische Patientendossier (EPDV)
- Finance — FINMA-Rundschreiben 2018/3 'Outsourcing - Banken, Versicherungsunternehmen und ausgewaehlte Finanzinstitute nach FINIG'
CambodiaChecked 18 August 2026
Depends on your industryWork: LowEnforcement: Dormant
- In one paragraph
- Cambodia has no general privacy law. A bill exists and went to a public review meeting in August 2026, but it is not law and there is no privacy regulator to complain to. For most businesses data can leave the country freely, with no paperwork. Banks and other lenders are the big exception: their main data centre must sit inside Cambodia.
- The catch
- The relaxed headline stops at the door of the financial sector. Any bank or lender supervised by Cambodia's central bank must keep at least one main data centre inside the country, and must get the central bank's permission in advance before customer personal data is moved to or hosted on servers abroad. Telecoms are also watched closely by an active regulator, and a suspended 2021 order that would push all internet traffic through a single government-controlled gateway can be switched back on at any time.
- Does this apply to me?
- There is no general data protection law in Cambodia, so there is nothing for a foreign company to be caught by. No size threshold, no revenue threshold, no registration, and no requirement to appoint someone in Cambodia to answer for your data. That changes the moment you need a local licence: banks, lenders and telecoms operators are licensed here and their licence conditions do reach their overseas systems. A draft privacy law was put to a validation workshop on 5 August 2026 and will proceed through the formal law-making process, so this answer has a shelf life.High confidence
- Can the data leave the country?
- In general, yes, and with nothing to sign. Cambodia has no rule that stops ordinary personal data leaving the country. Finance is the one hard wall we could verify: a bank or lender supervised by the central bank must have at least one main data centre in Cambodia, may only use a foreign data centre as a backup, and needs the central bank's approval before customer personal data is hosted abroad. Telecoms is the sector to watch, because a 2021 order that would route all internet traffic through a single national gateway was never switched on but was never cancelled either.Medium confidence
- What do I have to do to send it abroad?
- For most organisations, nothing at all. There is no approved-countries list, no banned-countries list, no standard contract to sign and no government form to file. The lists are not just empty, they do not exist, because there is no law that creates them. In finance the model is completely different: each move of customer personal data out of Cambodia needs its own approval from the central bank, decided case by case, and there is no published application process or timetable.Medium confidence
- Who enforces this — and are they actually working?
- For privacy, nobody. Cambodia has no data protection authority. The Ministry of Post and Telecommunications is writing the law and, in November 2025, ran a training workshop with Singapore's privacy regulator on how to build such an authority, which tells you plainly that one does not yet exist. Sector regulators are a different story and are genuinely working: the central bank supervises financial firms against its 2026 technology guidelines, and the telecoms regulator publicly named an operator in June 2026 for selling SIM cards without properly checking customers' identity documents.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and almost no ceiling. Tax and accounting law forces businesses to keep books and supporting documents for years, and financial firms must keep system logs and agree retention periods with their cloud providers. In the other direction there is no general rule telling anyone to delete personal data, because there is no privacy law. The only deletion duty we could verify applies to banks and lenders, who must keep customer personal data only as long as it is needed.Medium confidence
- What happens when something goes wrong?
- There is no breach reporting clock in Cambodia. No law requires you to tell a regulator or the affected people when personal data leaks, and there is no national cyber incident hotline with a deadline in hours. The nearest thing is in banking: the central bank tells supervised firms to report incidents as it requires, either on a regular cycle or one-off, with no fixed number of hours. Two draft laws would change this, so treat today's silence as temporary.Medium confidence
- What's the trap?
- Five things that are not in the summary. First, the e-commerce law reportedly bans encryption that would stop evidence being used in a criminal case, which cuts across normal end-to-end encryption promises. Second, a cloud-only bank cannot operate here: the main data centre must physically be in Cambodia. Third, moving customer banking data abroad needs the central bank's permission in advance, and there is no published process or timetable, so it must be planned months ahead. Fourth, telecoms operators must check identity documents before activating a SIM card, and the regulator names offenders in public. Fifth, no privacy law does not mean no risk, because your foreign customers will impose their own rules by contract.Medium confidence
- What's about to change?
- Four drafts are moving and none of them is law yet. The Personal Data Protection Law reached a validation workshop on 5 August 2026 and now heads into the formal law-making process. The Cybersecurity Law was still being argued over with the Ministry of Justice in July 2026. A Data Governance Policy for 2026 to 2035 was in consultation in March 2026 and is expected to cover where data may be stored and how it may cross borders. A Digital Government Law went to consultation in July 2025. No commencement date has been announced for any of them.High confidence
- Hardest industry wall
- Finance — Technology and Cyber Risk Management Guidelines (TCRMG)