Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
ChinaChecked 18 August 2026
Yes, with paperworkWork: Very highEnforcement: Active
In one paragraph
Data can leave China, but only through one of three official gates: a government security review, a government-written contract you file with the regulator, or a certificate from an approved body. Which gate you need depends on how many people's data you move, not on where you send it. Small exporters are exempt. Several industries are walled off entirely.
The catch
The 'paperwork, then it can go' answer is only true for ordinary companies. Payment firms, credit bureaus, hospitals, genetic labs, online map services, telecom and industrial operators, and anything the government labels critical national infrastructure must keep the data in China. In those areas a copy staying behind is not optional.
Does this apply to me?
Yes. China's privacy law reaches a company with no office and no staff in China if it offers goods or services to people in China, or analyses their behaviour. There is no revenue or headcount threshold that lets you out. If you are caught this way, you must set up a dedicated office in China or name a representative there, and give the regulator their details.High confidence
Can the data leave the country?
In general yes, once you clear the right gate — but the gate is set by volume, not by destination. China has no list of banned or approved countries. Below 100,000 people a year you can usually send data abroad with no filing at all. Above that you need a contract filed with the regulator or a certificate; above a million people, or if you hold data the state calls 'important', you need a full government security review. Then come the industry walls, which override all of this.High confidence
What do I have to do to send it abroad?
Three routes, and you do not get to pick freely — your volume picks for you. Route one is a government security review, run by the national internet regulator through your provincial office; an approval lasts three years and only covers the exact purpose, scope and method you declared. Route two is China's own standard contract, which you sign with the overseas recipient and file with the provincial regulator along with a risk assessment. Route three is a certificate from an accredited body, which since 1 March 2026 has a national standard behind it. You also need each person's separate, specific consent before their data goes abroad.High confidence
Who enforces this — and are they actually working?
The Cyberspace Administration of China leads, and it is fully staffed and busy. It runs a nationwide enforcement campaign every year, tests apps itself and publishes the names of the ones that fail, and puts out batches of worked enforcement cases. Police, the industry ministry and the market regulator enforce alongside it, and finance, health, mapping and securities regulators run their own rules. Fines are usually modest and paired with an order to fix things; the eye-watering penalties in the statute are rarely used.High confidence
How long must I keep it, and when must I delete it?
Both directions apply, and they pull against each other. The floor: network logs must be kept for at least six months, and accounting records have their own long minimum periods set by a national schedule. The ceiling: personal data may only be kept for the shortest time needed for the purpose you collected it for, and must be deleted once that purpose is met, the service ends, or consent is withdrawn. Where a law sets a minimum, that minimum wins over the delete duty — you keep the record and stop using it for anything else.High confidence
What happens when something goes wrong?
Three clocks, and they overlap. If you run critical national infrastructure you have ONE HOUR to report a serious incident to your supervising department and the police. Everyone else has four hours to tell the provincial internet office. On top of that, a network data incident that could harm national security or the public interest must be reported within 24 hours. You must also tell affected people immediately, by phone, text, message, email or public notice.High confidence
What's the trap?
Five things that ruin weekends. (1) Sending data abroad needs each person's separate, specific consent — a line buried in a global privacy notice will not do. (2) A child is anyone under 14, and their data is treated as sensitive, so you need a parent's consent and a separate set of processing rules. (3) You may not hand data stored in China to a foreign court, police force or regulator without Chinese government approval — this catches routine legal discovery and overseas audit requests. (4) You have to work out for yourself whether you hold 'important data' and report it, because the official catalogues are incomplete. (5) The widely repeated claim that all personal financial data must be stored in China does not appear where people think it does.High confidence
What's about to change?
The next twelve months are about size-based rules. A draft published on 7 August 2026 would create a heavy new tier for any company holding data on ten million people or more: store it in China, appoint a chief privacy officer, set up an outside supervision committee, publish an annual report and honour data portability requests within 30 working days. Comments closed on 7 September 2026 and it is not law yet. A companion draft going the other way would simplify life for small processors. Watch the dormant switches — several can flip with no consultation at all.High confidence
Hardest industry wall
  • All industries 中华人民共和国网络安全法(2025年修正)
  • Payments 非银行支付机构监督管理条例
  • Finance 征信业务管理办法
  • Banking 中国人民银行业务领域数据安全管理办法
  • Securities 关于加强境内企业境外发行证券和上市相关保密和档案管理工作的规定
  • Health and social care 国家健康医疗大数据标准、安全和服务管理办法(试行)
  • Mapping and location 地图管理条例
  • Telecoms 工业和信息化领域数据安全管理办法(试行)
HungaryChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
In one paragraph
Hungary has no general rule that data must stay in the country. It runs on the European rulebook: you may send data abroad if you have the right legal paperwork in place. Hungary used to force state registers to be processed on Hungarian soil, but that rule was scrapped in April 2024. The privacy regulator is real, staffed and issuing decisions, though its fines are small by European standards.
The catch
Two things break the easy answer. Since January 2025 a large slice of the economy — energy, transport, banking, health, water, digital infrastructure, waste, manufacturing and most of the public sector — may only use a shared cloud or process data outside Hungary after completing a formal data classification under the cybersecurity law. And an online casino serving Hungarian players must keep its game server inside the European Economic Area, full stop.
Does this apply to me?
Yes. A company with no office in Hungary is still caught if it offers goods or services to people in Hungary or watches their behaviour, because the European privacy rules reach outside Europe. There is no revenue or headcount threshold to hide under. If you have no establishment anywhere in Europe you must appoint a written representative inside Europe, and Hungary is a perfectly ordinary place to put one.High confidence
Can the data leave the country?
Yes, on the normal European terms — nothing in general Hungarian law says data must be stored in Hungary. This is a change worth noticing: the rule that state registers could only be processed on Hungarian soil was repealed with effect from 1 April 2024, and the law that replaced it has no territorial restriction at all. Two sectors override this. An online casino must keep its game server inside the European Economic Area. And any company or public body inside the scope of Hungary's cybersecurity law must finish a formal data classification before it uses a shared cloud service or processes data abroad.Medium confidence
What do I have to do to send it abroad?
You need a European transfer tool before the data leaves, and Hungary adds no extra permit, filing or fee on top. The model is an approved-list one: you may send data to a country the European Commission has declared safe, or you sign the standard European contract clauses and write down a risk assessment of the destination. There is no Hungarian government sign-off, and no Hungarian list of banned countries. For police, security and other work outside the European privacy rules, Hungary's own Info Act sets the conditions instead.High confidence
Who enforces this — and are they actually working?
The National Authority for Data Protection and Freedom of Information, known by its Hungarian initials NAIH, and it is genuinely working. It has published decisions right through to May 2026, released its report on 2025 activity on 30 March 2026, and issued public statements in July and August 2026. Its president is Dr Attila Peterfalvi. The catch is size, not activity: a typical fine is small — two million forint, roughly six thousand dollars, in an April 2025 data-security case.High confidence
How long must I keep it, and when must I delete it?
Hungary pushes hard in both directions. The floor is long: accounting records and vouchers must be kept for eight years, and health records for decades — the health data law works in periods of thirty years and more. The ceiling is the European rule that you delete personal data once the purpose is spent. When the two collide, the specific statutory keep-period wins, so a deletion request does not empty your ledgers or a hospital's files.Medium confidence
What happens when something goes wrong?
Count at least two clocks, and three if you are a bank. A personal data breach goes to the privacy regulator within 72 hours. A cyber incident at a company or public body covered by the cybersecurity law goes to the national incident response centre, and the European rules that Hungary is copying use a 24-hour first alert followed by a fuller report at 72 hours. Financial firms have a separate and faster set of deadlines under the European operational resilience rules.Medium confidence
What's the trap?
Five things that are not in the summary. One: mishandling personal data is a crime in Hungary, not just a fine — up to one year in prison, two years for sensitive data, three years for public officials. Two: the old rule forcing state data to stay in Hungary is dead, so quoting it makes you look out of date, while the new cybersecurity classification gate is very much alive and most checklists miss it. Three: several cybersecurity deadlines have already passed, so newly in-scope companies are late on day one. Four: an online casino's game server must sit in the European Economic Area. Five: Hungary's freedom-of-information regime can make your contract with a state body public.High confidence
What's about to change?
Three dated items. The Court of Justice will rule on Hungary's sovereignty protection law; the court's adviser said on 12 February 2026 that it breaks European law, and the judgment could land any time. From 12 January 2027 cloud providers across Europe, Hungary included, must charge nothing to move your data out. And Hungary's cybersecurity supervision moves from paperwork to inspections now that the first audit deadline of 30 June 2026 has passed.Medium confidence
Hardest industry wall
  • Online gaming 1991. evi XXXIV. torveny a szerencsejatek szervezeserol es a vegrehajtasi rendeletei (online kaszinojatek engedelyezesi feltetelei)
  • Government 2021. evi XCI. torveny a nemzeti adatvagyonrol, 13. §