Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
SwitzerlandChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Switzerland is easy to send data out of, as long as the destination is one the government trusts. An official list names about 44 approved places, including every European Union country and United States firms in one certification scheme. Anywhere else, you sign an approved contract first. The sting is elsewhere: getting it wrong is a crime, and the case lands on a person, not the company.
- The catch
- The relaxed headline stops the moment you touch three areas. Electronic patient record data must physically sit in Switzerland. Banking client data is protected by a criminal secrecy law with a three-year prison ceiling. Doctors, lawyers, notaries, pharmacists, psychologists and nurses are under a near-identical criminal secrecy rule, and a normal supplier contract does not cure it. Financial market infrastructures also need the regulator's permission before outsourcing anything important.
- Does this apply to me?
- Yes. Swiss privacy law reaches any organisation whose activities have an effect in Switzerland, even one with no office, staff or company here. There is no revenue or headcount threshold to duck under, and there is no register to sign up to. You only need a named representative inside Switzerland if four things are true at once: you are selling to people here or watching what they do, you are doing it on a large scale, you are doing it regularly, and the processing is high risk for the people involved. Very few foreign companies meet all four.High confidence
- Can the data leave the country?
- In general, yes. Switzerland publishes an official list of countries and territories it considers safe, and data can move to any of them with no extra paperwork. The list has about 44 entries. It covers all 27 European Union countries, the United Kingdom, Norway, Iceland, Liechtenstein, Canada, Israel, Argentina, Uruguay and New Zealand. It covers the United States only for companies signed up to one specific certification scheme. Japan is not on it, even though the European Union treats Japan as safe. For anywhere not on the list, you sign an approved contract first. But three industries override this completely, and one of them is an outright ban.High confidence
- What do I have to do to send it abroad?
- The model is an approved-destinations list, and it is well populated: about 44 countries, territories and one sector-specific entry are on it right now. Send data to a listed place and you need nothing at all. Send it anywhere else and you need one of a short menu of safeguards, the most common being a standard contract. Switzerland has formally accepted the European Union's standard contract template, so most companies can reuse the paperwork they already have.High confidence
- Who enforces this — and are they actually working?
- The main regulator is the Federal Data Protection and Information Commissioner. It is real, fully staffed and busy: in the year to 31 March 2026 it ran 156 low-level interventions, 22 preliminary enquiries and 9 formal investigations, and it had 2 cases running in the Federal Administrative Court. It has issued binding orders against a bank, a debt collection firm and a fashion group, and in October 2025 the court confirmed its new way of working. The catch is that this regulator cannot fine anyone. Fines under the privacy law are criminal, they are handed out by cantonal prosecutors, and they land on individual people.High confidence
- How long must I keep it, and when must I delete it?
- Both directions apply and they pull against each other. The floor: business books, accounting records and audit reports must be kept for ten years. Financial market infrastructures keep their records ten years, trade repositories keep trade data ten years after the contract matures, electronic patient record access logs are kept ten years, and telecoms companies keep connection records for six months. The ceiling: the privacy law says personal data must be destroyed or made anonymous as soon as it is no longer needed. There is no fixed number. Where the two clash, the specific legal duty to keep wins.High confidence
- What happens when something goes wrong?
- Count four clocks, not one. The privacy regulator must be told 'as quickly as possible' when a breach is likely to put people at serious risk, with no number of hours attached. If you run critical infrastructure, you have a hard 24 hours to tell the national cyber security office. If you are supervised by the financial regulator, you have 24 hours to notify your supervisor and 72 hours to file the full report. Electronic patient record communities have to report security incidents to the health office. Most failures come from teams who set a single deadline and miss the others.High confidence
- What's the trap?
- Five things that are not in the summary. One: the penalty is a criminal fine on a named human being, not an administrative fine on the company, so your compliance lead is personally exposed. Two: sending data abroad without a valid safeguard is itself a crime. Three: banking secrecy and medical or legal secrecy are criminal laws with prison ceilings, and a standard supplier contract does not fix them. Four: cantonal authorities and cantonal hospitals are outside the federal law entirely. Five: the 24-hour cyber report has no penalty for being late, which misleads people into thinking it is optional.High confidence
- What's about to change?
- Nothing in the next twelve months changes where Swiss data may be stored. The electronic identity law has passed but is not switched on yet, and the financial regulator is holding a rule change until it is. A company transparency law hits banks on 1 October 2026. A rewrite of the telecoms surveillance rules has been announced for years and still has not landed. The bigger risk is not new legislation at all: the government can rewrite the approved-destinations list by itself, overnight, with no vote and no consultation.Medium confidence
- Hardest industry wall
- Health and social care — Verordnung ueber das elektronische Patientendossier (EPDV)
- Finance — FINMA-Rundschreiben 2018/3 'Outsourcing - Banken, Versicherungsunternehmen und ausgewaehlte Finanzinstitute nach FINIG'
SwedenChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- Sweden has no general law forcing data to stay in the country. Personal data leaves under the ordinary European rules. But four walls override that: gambling systems must sit in Sweden, telecoms records kept for the police may never leave the European Union, classified material needs a state-to-state deal, and accounting books stay in Sweden unless you tell the tax agency.
- The catch
- The relaxed headline stops being true the moment you touch online gambling, telecoms records held for law enforcement, security-sensitive activity, detailed maps and sea-depth data, a public authority's secret files, or a Swedish company's accounting books. In those six areas Sweden is far stricter than its reputation suggests, and two of them carry prison sentences rather than fines.
- Does this apply to me?
- Yes. Sweden applies the European privacy rules, so a company anywhere in the world is caught if it offers goods or services to people in Sweden or watches what they do. There is no size or revenue floor to duck under. Sweden's own top-up law adds Swedish-only duties on top, and those apply to anyone processing data under Swedish law, not just Swedish companies. If you are outside Europe and caught, you normally have to name a representative inside Europe.High confidence
- Can the data leave the country?
- In general, yes. Sweden has no law that says personal data must physically stay in Sweden, and European law actually bans Sweden from imposing storage rules on non-personal data except for national security reasons. The exceptions are what matter. Online gambling systems must be placed in Sweden. Telephone and internet records that operators keep for the police may not be stored outside the European Union. Security-classified material cannot go to a foreign body without a government-to-government agreement. And a Swedish company's accounting records must be kept in Sweden unless it tells the tax agency where they are instead.High confidence
- What do I have to do to send it abroad?
- Sweden adds nothing of its own here — it uses the European toolkit unchanged. The model is an allowlist of approved destinations, and that list is well populated: the United Kingdom, Switzerland, Japan, South Korea, Canada, Brazil and about a dozen others are approved. For everywhere else you sign the European Commission's standard contract, or use group-wide rules approved by a regulator, and you write down why you think the data will still be safe. United States transfers work only if the receiving company has signed up to the European Union–United States Data Privacy Framework, and that arrangement is under legal pressure.High confidence
- Who enforces this — and are they actually working?
- The main privacy regulator is the Swedish Authority for Privacy Protection, and it is fully staffed and working. It published supervisory decisions in May, June and July 2026, including a reprimand to a large security company over filming its own staff, and in June 2026 it was also made Sweden's market surveillance authority for the European artificial intelligence rules. Other regulators matter just as much in their own lanes: the financial supervisor, the telecoms and post authority, the gambling authority, the Security Service and the Armed Forces.High confidence
- How long must I keep it, and when must I delete it?
- Sweden has a hard floor and a soft ceiling, and they pull in opposite directions. You must keep company accounting records for seven years after the end of the year they relate to, and patient records for at least ten years after the last entry. Against that, European privacy law says you must delete personal data once you no longer need it. Sweden resolves the clash the same way most of Europe does: a specific legal duty to keep something beats the general duty to delete it, so you keep it, lock it down and use it for nothing else.High confidence
- What happens when something goes wrong?
- Count at least three clocks, and they do not agree. For a personal data breach you have 72 hours to tell the privacy regulator, and you must tell the affected people without undue delay if the risk to them is high. Since 15 January 2026, organisations in important sectors must send an early warning to their cybersecurity supervisor within 24 hours of noticing a significant incident, then a fuller report within 72 hours — but trust service providers get only 24 hours for the full report. Financial firms have a fourth clock under the European digital resilience rules. The 24-hour warning is the one that catches people out.High confidence
- What's the trap?
- Five things that are not in any summary. One: a child can consent from age 13 in Sweden, the youngest age Europe allows, so a global default of 16 is wrong here. Two: you may only use a person's Swedish identity number without their consent when it is clearly justified — a Swedish-only rule with no European equivalent. Three: anything you send to a Swedish public authority can become a public document that any member of the public, including a competitor or a journalist, can demand a copy of. Four: giving a supplier access to a public authority's secret files is allowed only for purely technical processing or storage, and only if it is not inappropriate in the circumstances — the ordinary supplier contract is not enough. Five: mapping and sea-depth data is criminal law, not paperwork — spreading it without a permit can mean up to a year in prison.High confidence
- What's about to change?
- Two dated items. On 1 January 2027 a new law on the resilience of critical operators is proposed to start, covering eleven sectors and adding another 24-hour incident report. Also on 12 January 2027, European rules make it illegal for cloud providers to charge you to move your data out. Watch the government's national cloud policy, adopted on 28 May 2026: today it is only advice with no penalties, but it is the obvious vehicle for a future rule that public bodies must use European providers.High confidence
- Hardest industry wall
- Telecoms — Förordning (2022:511) om elektronisk kommunikation, 9 kap. 4 §
- Online gaming — Spellagen (2018:1138), 16 kap. 2 §
- Defence — Säkerhetsskyddslagen (2018:585) och Säkerhetsskyddsförordningen (2021:955)