Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
SwitzerlandChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
In one paragraph
Switzerland is easy to send data out of, as long as the destination is one the government trusts. An official list names about 44 approved places, including every European Union country and United States firms in one certification scheme. Anywhere else, you sign an approved contract first. The sting is elsewhere: getting it wrong is a crime, and the case lands on a person, not the company.
The catch
The relaxed headline stops the moment you touch three areas. Electronic patient record data must physically sit in Switzerland. Banking client data is protected by a criminal secrecy law with a three-year prison ceiling. Doctors, lawyers, notaries, pharmacists, psychologists and nurses are under a near-identical criminal secrecy rule, and a normal supplier contract does not cure it. Financial market infrastructures also need the regulator's permission before outsourcing anything important.
Does this apply to me?
Yes. Swiss privacy law reaches any organisation whose activities have an effect in Switzerland, even one with no office, staff or company here. There is no revenue or headcount threshold to duck under, and there is no register to sign up to. You only need a named representative inside Switzerland if four things are true at once: you are selling to people here or watching what they do, you are doing it on a large scale, you are doing it regularly, and the processing is high risk for the people involved. Very few foreign companies meet all four.High confidence
Can the data leave the country?
In general, yes. Switzerland publishes an official list of countries and territories it considers safe, and data can move to any of them with no extra paperwork. The list has about 44 entries. It covers all 27 European Union countries, the United Kingdom, Norway, Iceland, Liechtenstein, Canada, Israel, Argentina, Uruguay and New Zealand. It covers the United States only for companies signed up to one specific certification scheme. Japan is not on it, even though the European Union treats Japan as safe. For anywhere not on the list, you sign an approved contract first. But three industries override this completely, and one of them is an outright ban.High confidence
What do I have to do to send it abroad?
The model is an approved-destinations list, and it is well populated: about 44 countries, territories and one sector-specific entry are on it right now. Send data to a listed place and you need nothing at all. Send it anywhere else and you need one of a short menu of safeguards, the most common being a standard contract. Switzerland has formally accepted the European Union's standard contract template, so most companies can reuse the paperwork they already have.High confidence
Who enforces this — and are they actually working?
The main regulator is the Federal Data Protection and Information Commissioner. It is real, fully staffed and busy: in the year to 31 March 2026 it ran 156 low-level interventions, 22 preliminary enquiries and 9 formal investigations, and it had 2 cases running in the Federal Administrative Court. It has issued binding orders against a bank, a debt collection firm and a fashion group, and in October 2025 the court confirmed its new way of working. The catch is that this regulator cannot fine anyone. Fines under the privacy law are criminal, they are handed out by cantonal prosecutors, and they land on individual people.High confidence
How long must I keep it, and when must I delete it?
Both directions apply and they pull against each other. The floor: business books, accounting records and audit reports must be kept for ten years. Financial market infrastructures keep their records ten years, trade repositories keep trade data ten years after the contract matures, electronic patient record access logs are kept ten years, and telecoms companies keep connection records for six months. The ceiling: the privacy law says personal data must be destroyed or made anonymous as soon as it is no longer needed. There is no fixed number. Where the two clash, the specific legal duty to keep wins.High confidence
What happens when something goes wrong?
Count four clocks, not one. The privacy regulator must be told 'as quickly as possible' when a breach is likely to put people at serious risk, with no number of hours attached. If you run critical infrastructure, you have a hard 24 hours to tell the national cyber security office. If you are supervised by the financial regulator, you have 24 hours to notify your supervisor and 72 hours to file the full report. Electronic patient record communities have to report security incidents to the health office. Most failures come from teams who set a single deadline and miss the others.High confidence
What's the trap?
Five things that are not in the summary. One: the penalty is a criminal fine on a named human being, not an administrative fine on the company, so your compliance lead is personally exposed. Two: sending data abroad without a valid safeguard is itself a crime. Three: banking secrecy and medical or legal secrecy are criminal laws with prison ceilings, and a standard supplier contract does not fix them. Four: cantonal authorities and cantonal hospitals are outside the federal law entirely. Five: the 24-hour cyber report has no penalty for being late, which misleads people into thinking it is optional.High confidence
What's about to change?
Nothing in the next twelve months changes where Swiss data may be stored. The electronic identity law has passed but is not switched on yet, and the financial regulator is holding a rule change until it is. A company transparency law hits banks on 1 October 2026. A rewrite of the telecoms surveillance rules has been announced for years and still has not landed. The bigger risk is not new legislation at all: the government can rewrite the approved-destinations list by itself, overnight, with no vote and no consultation.Medium confidence
Hardest industry wall
  • Health and social care Verordnung ueber das elektronische Patientendossier (EPDV)
  • Finance FINMA-Rundschreiben 2018/3 'Outsourcing - Banken, Versicherungsunternehmen und ausgewaehlte Finanzinstitute nach FINIG'
NepalChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Dormant
In one paragraph
Nepal's privacy law says nothing about sending data abroad, so on paper data can leave freely. There is no privacy regulator at all: breaches are criminal matters taken to a local court, the maximum fine is about 215 US dollars, and no case has produced a public penalty. The real constraint is a 2025 rule on data centres and cloud services, which says customers may only buy hosting from providers on a government list.
The catch
The relaxed headline stops being true the moment you look at where the data physically sits. Since January 2025 anyone buying data centre or cloud services in Nepal is supposed to use only providers listed by the Department of Information Technology, and to get listed a provider must be a Nepal-registered company with a physical building in Nepal. Government security agencies must use the state's own data centre, other government bodies are being moved into it, and card payments made in Nepali rupees must be settled inside Nepal.
Does this apply to me?
It is unclear, and that is the honest answer. The Privacy Act covers public bodies and companies handling people's information, but it never says whether it reaches a company sitting outside Nepal, and it does not ask you to appoint anyone locally. Two other laws clearly do reach you from abroad: the computer-crime law applies to acts done outside Nepal that involve a computer located in Nepal, and the central bank's payment licensing policy expressly covers firms set up abroad that carry out payment business inside Nepal. There is no revenue or company-size threshold to fall below.Medium confidence
Can the data leave the country?
Under the privacy law, yes — it is silent on sending personal data out of Nepal, so there is nothing to comply with. But the country still has walls, and they are about where the machines are rather than where the data goes. Since January 2025 anyone buying data centre or cloud services is meant to use only providers on the government's published list, and listing requires a Nepal-registered company with a building in Nepal. Government security agencies must use the state's own data centre, and card payments made in Nepali rupees must be settled inside Nepal.Medium confidence
What do I have to do to send it abroad?
Nothing. There is no approval to get, no standard contract to sign and no list of approved countries, because Nepal's privacy law simply does not deal with sending data abroad. The control that does exist works the other way round: it is an approved-supplier list for hosting. The Department of Information Technology lists data centre and cloud providers, and customers are told to use only listed ones.Medium confidence
Who enforces this — and are they actually working?
For personal data, nobody. Nepal has no privacy regulator and no data protection authority. A person whose privacy is breached files a criminal complaint in their local district court within three months, and the court can also award compensation. The bodies that are genuinely active work on cyber security and on industry rules, not on privacy: the National Cyber Security Center published advisories as recently as April 2026, the telecoms authority collects security audit reports, the central bank issues payment directives, and the Department of Information Technology is running the data centre listing scheme.Medium confidence
How long must I keep it, and when must I delete it?
There is a floor and almost no ceiling. Tax records must be kept for five years after the tax year ends. Telecom operators must keep security logs for at least six months and internet address-translation logs for at least three months. Data centres must keep camera footage for at least three months. Going the other way, the privacy law has no general delete-by date, so the only real deletion duty found is a telecom rule that says paper customer forms must be destroyed once they have been scanned.Medium confidence
What happens when something goes wrong?
There is no general duty to report a personal data breach in Nepal — not to a regulator, and not to the people affected. No rule found sets a deadline in hours. Two narrower duties do exist. A data centre or cloud provider that finds someone has got into its systems must tell the regulator and the National Cyber Security Center immediately, by the fastest means available. A telecom operator hit by a security incident must work with a standing task force at the telecoms authority.Medium confidence
What's the trap?
Five. First, privacy breaches are criminal, not administrative — the exposure is up to three years in prison for an individual, not a corporate fine. Second, a victim has only three months from the act to complain, so most claims die of old age. Third, your cloud vendor must be on the government's list, which makes this a supplier problem rather than a policy problem. Fourth, anyone under 18 needs a guardian's consent — there is no lower digital age. Fifth, the online-content offence in the electronic transactions law carries up to five years in prison for material judged contrary to public morality, and it is written vaguely enough to catch ordinary posts.High confidence
What's about to change?
No data protection law is on the way that we could find, and no bill for one is before parliament. What is moving is telecoms and broadcasting: the ministry published discussion papers for a new Telecommunications Bill and a National Mass Communication Bill on 5 August 2026. The telecoms authority is consulting on amending its 2020 cyber security rules, on a framework for streaming and messaging services, and on a rule to force the move to newer internet addressing.Medium confidence
Hardest industry wall
  • All industries डाटा सेन्टर तथा क्लाउड सेवा (सञ्चालन तथा व्यवस्थापन) निर्देशिका, २०८१ (Data Center and Cloud Service (Operation and Management) Directives, 2081)
  • Payments भुक्तानी प्रणालीसम्बन्धी एकीकृत निर्देशन, २०८२ (Unified Directive on Payment Systems, 2082)