Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
SwitzerlandChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Switzerland is easy to send data out of, as long as the destination is one the government trusts. An official list names about 44 approved places, including every European Union country and United States firms in one certification scheme. Anywhere else, you sign an approved contract first. The sting is elsewhere: getting it wrong is a crime, and the case lands on a person, not the company.
- The catch
- The relaxed headline stops the moment you touch three areas. Electronic patient record data must physically sit in Switzerland. Banking client data is protected by a criminal secrecy law with a three-year prison ceiling. Doctors, lawyers, notaries, pharmacists, psychologists and nurses are under a near-identical criminal secrecy rule, and a normal supplier contract does not cure it. Financial market infrastructures also need the regulator's permission before outsourcing anything important.
- Does this apply to me?
- Yes. Swiss privacy law reaches any organisation whose activities have an effect in Switzerland, even one with no office, staff or company here. There is no revenue or headcount threshold to duck under, and there is no register to sign up to. You only need a named representative inside Switzerland if four things are true at once: you are selling to people here or watching what they do, you are doing it on a large scale, you are doing it regularly, and the processing is high risk for the people involved. Very few foreign companies meet all four.High confidence
- Can the data leave the country?
- In general, yes. Switzerland publishes an official list of countries and territories it considers safe, and data can move to any of them with no extra paperwork. The list has about 44 entries. It covers all 27 European Union countries, the United Kingdom, Norway, Iceland, Liechtenstein, Canada, Israel, Argentina, Uruguay and New Zealand. It covers the United States only for companies signed up to one specific certification scheme. Japan is not on it, even though the European Union treats Japan as safe. For anywhere not on the list, you sign an approved contract first. But three industries override this completely, and one of them is an outright ban.High confidence
- What do I have to do to send it abroad?
- The model is an approved-destinations list, and it is well populated: about 44 countries, territories and one sector-specific entry are on it right now. Send data to a listed place and you need nothing at all. Send it anywhere else and you need one of a short menu of safeguards, the most common being a standard contract. Switzerland has formally accepted the European Union's standard contract template, so most companies can reuse the paperwork they already have.High confidence
- Who enforces this — and are they actually working?
- The main regulator is the Federal Data Protection and Information Commissioner. It is real, fully staffed and busy: in the year to 31 March 2026 it ran 156 low-level interventions, 22 preliminary enquiries and 9 formal investigations, and it had 2 cases running in the Federal Administrative Court. It has issued binding orders against a bank, a debt collection firm and a fashion group, and in October 2025 the court confirmed its new way of working. The catch is that this regulator cannot fine anyone. Fines under the privacy law are criminal, they are handed out by cantonal prosecutors, and they land on individual people.High confidence
- How long must I keep it, and when must I delete it?
- Both directions apply and they pull against each other. The floor: business books, accounting records and audit reports must be kept for ten years. Financial market infrastructures keep their records ten years, trade repositories keep trade data ten years after the contract matures, electronic patient record access logs are kept ten years, and telecoms companies keep connection records for six months. The ceiling: the privacy law says personal data must be destroyed or made anonymous as soon as it is no longer needed. There is no fixed number. Where the two clash, the specific legal duty to keep wins.High confidence
- What happens when something goes wrong?
- Count four clocks, not one. The privacy regulator must be told 'as quickly as possible' when a breach is likely to put people at serious risk, with no number of hours attached. If you run critical infrastructure, you have a hard 24 hours to tell the national cyber security office. If you are supervised by the financial regulator, you have 24 hours to notify your supervisor and 72 hours to file the full report. Electronic patient record communities have to report security incidents to the health office. Most failures come from teams who set a single deadline and miss the others.High confidence
- What's the trap?
- Five things that are not in the summary. One: the penalty is a criminal fine on a named human being, not an administrative fine on the company, so your compliance lead is personally exposed. Two: sending data abroad without a valid safeguard is itself a crime. Three: banking secrecy and medical or legal secrecy are criminal laws with prison ceilings, and a standard supplier contract does not fix them. Four: cantonal authorities and cantonal hospitals are outside the federal law entirely. Five: the 24-hour cyber report has no penalty for being late, which misleads people into thinking it is optional.High confidence
- What's about to change?
- Nothing in the next twelve months changes where Swiss data may be stored. The electronic identity law has passed but is not switched on yet, and the financial regulator is holding a rule change until it is. A company transparency law hits banks on 1 October 2026. A rewrite of the telecoms surveillance rules has been announced for years and still has not landed. The bigger risk is not new legislation at all: the government can rewrite the approved-destinations list by itself, overnight, with no vote and no consultation.Medium confidence
- Hardest industry wall
- Health and social care — Verordnung ueber das elektronische Patientendossier (EPDV)
- Finance — FINMA-Rundschreiben 2018/3 'Outsourcing - Banken, Versicherungsunternehmen und ausgewaehlte Finanzinstitute nach FINIG'
MexicoChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Waking up
- In one paragraph
- Mexico's general privacy law does not care where you store data. There is no approved-country list, no standard contract to sign and no permission to ask for. You need the right wording in your privacy notice and, usually, the person's consent. The rules that actually pin data to Mexico live in banking, money-laundering and tax law, not in the privacy law.
- The catch
- The relaxed headline stops the moment you are a bank, a stockbroker, a crowdfunding platform, an insurer or a phone company. Banks need written permission from the banking regulator before any processing happens abroad. Separately, anti-money-laundering law and tax law require many ordinary businesses to keep their records at a Mexican address for ten and five years. Those rules bind companies that have never read a privacy law.
- Does this apply to me?
- Probably yes, but Mexico is unusually vague about it. The privacy law says only that it applies across Mexican territory. It does not spell out when it reaches a company based abroad. The old rulebook did say the law caught a foreign company that used equipment or systems located in Mexico, and let that company appoint a local representative instead of opening an office. That old rulebook belonged to a law that was scrapped in March 2025, so its status today is genuinely unclear. There is no revenue or headcount threshold to fall below.Medium confidence
- Can the data leave the country?
- Under the general privacy law, yes, and with very little paperwork. Mexico has no list of approved countries and no list of banned ones. Sending data to a company abroad is treated exactly like sending it to a company down the road: say so in your privacy notice, get the person's consent unless one of seven exceptions applies, and pass the privacy notice on to whoever receives the data. Handing data to your own supplier who only follows your instructions is not even counted as a transfer. Five sectors override this, and in three of them the override is severe.High confidence
- What do I have to do to send it abroad?
- Nothing needs approval and no list exists in either direction. The model is simply unrestricted: any destination is allowed. What you need is a privacy notice that names the transfer and carries a clause where the person accepts or refuses it, plus that person's consent unless one of seven legal exceptions covers you. Because there is no list to populate, the government cannot make this stricter by adding a country. It would take a new law or a new regulation.High confidence
- Who enforces this — and are they actually working?
- Mexico abolished its independent privacy regulator. The National Institute for Transparency, Access to Information and Data Protection was wound up in March 2025 and its staff, files and cases were moved into a government ministry, the Anti-Corruption and Good Government Ministry. So the referee is now part of the government rather than independent of it. The ministry is staffed, but the law says the detailed procedure for complaints, inspections and fines will be set out in a regulation, and that regulation still has not been published. Financial regulators, by contrast, are visibly active and update their rulebooks almost monthly.Medium confidence
- How long must I keep it, and when must I delete it?
- There is no single retention period. The privacy law says delete data once it is no longer needed, after a blocking period equal to the time limit for suing over the relationship. One hard ceiling is written into the law: information about someone breaking a contract must be erased six years after the default. The floors are longer and come from other laws. Tax records must be kept five years and their supporting documents must be available at your Mexican tax address. Anti-money-laundering records must be kept ten years at an address you register with the Finance Ministry. Phone companies keep call and location records for two years. Where a floor and a ceiling clash, the floor wins, because the privacy law lets you keep data to meet a legal duty.High confidence
- What happens when something goes wrong?
- There are at least three clocks and they do not agree. Under the general privacy law you must tell the affected people immediately if a breach significantly harms their money or their reputation, and there is no duty to tell the regulator at all. Banks face a much tighter set: tell the banking regulator immediately, tell affected customers within forty-eight hours, file a full report within five working days, and send a remediation plan within fifteen working days of the incident ending. Phone companies must hand requested records to the authorities within twenty-four hours and keep a team available every hour of every day. Mexico has no general cyber-incident reporting law that catches everyone.High confidence
- What's the trap?
- Five things catch people out. Every private business in Mexico is now legally required to ask customers for their national population ID number. Anti-money-laundering rules force many ordinary businesses to keep ten years of records at a Mexican address, which quietly rules out a pure foreign cloud setup. Mishandling data can put a person in prison, not just cost a company money. Banks must get written permission before any processing happens abroad, and that includes routine cloud hosting. And the rulebook the privacy law keeps pointing at does not exist.High confidence
- What's about to change?
- The biggest thing coming is a regulation that is already overdue. The privacy law repeatedly says a rulebook will set the deadlines for complaints, inspections and fines, and the government missed its own June 2025 deadline to publish it. When it lands it could change how enforcement works overnight, with no consultation. Health law was changed in January 2026 to put telehealth on a statutory footing, and the biometric national ID is still being rolled out. The dangerous powers are the ones the government already holds rather than any bill in parliament.Medium confidence
- Hardest industry wall
- Payments — Disposiciones de carácter general aplicables a las instituciones de tecnología financiera, artículos 85 a 87
- Finance — Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita, artículos 15 y 18
- All industries — Código Fiscal de la Federación, artículos 28 y 30
- Telecoms — Ley en Materia de Telecomunicaciones y Radiodifusión, artículo 183