Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
Costa RicaChecked 19 August 2026
Yes, with paperworkWork: MediumEnforcement: Waking up
In one paragraph
Costa Rica does not force anyone to keep data inside the country. We found no storage-in-country rule in any industry. What it does instead is gate sharing: you may only hand personal data to another organisation if the person said yes, in Costa Rica or abroad. There is also a hard rule that most personal data must be deleted or anonymised after ten years. Fines are small, but the regulator can shut a database down for up to six months.
The catch
The consent gate is narrower than it sounds, and the sector layer adds paperwork rather than walls. Sending data to your own cloud provider, your own supplier, or another company in your own group does not legally count as a 'transfer' at all, so it needs no consent. Meanwhile banks and finance companies must tell the banking supervisor which country their cloud and their backups sit in, and telecoms companies must delete call and location records once they are no longer needed. Neither is a residency rule, but both catch people out.
Does this apply to me?
Yes. The rules follow the effect, not the office. If your handling of personal data has effects inside Costa Rica, the law applies even if you have no company, staff or server there. There is no size, revenue or headcount threshold to fall under. We found no general requirement to appoint a local representative, although if you have to register a database you must name a contact person who answers to the regulator and to the public.High confidence
Can the data leave the country?
Yes, and nothing has to stay behind. We searched for storage-in-country rules in banking, payments, insurance, securities, health, telecoms, government cloud, education, gambling, mapping and defence, and found none, checked on 19 August 2026. The catch is not geography, it is consent: handing personal data to another organisation, at home or abroad, needs the person's clear permission. Moving data to your own cloud provider or your own group company is not treated as handing it over, so it does not need consent.High confidence
What do I have to do to send it abroad?
There is no list of approved or banned countries, because Costa Rica does not use lists at all. The permission you need comes from the person, not from the government. Before data goes to another organisation you need three things: the person's clear and informed yes, a contract with the receiving organisation that puts it under the same duties you are under, and, if you had to register your database, a written handling protocol lodged with the regulator. If a complaint is made, you have to prove all of this, not the regulator.High confidence
Who enforces this — and are they actually working?
The Agency for the Protection of Inhabitants' Data, known as PRODHAB, sits inside the Ministry of Justice and Peace. It is real and it is staffed: it has a national director, David Rodriguez Suarez, who signed its mid-year 2026 performance report on 16 July 2026, and its website was updated in August 2026. But the last decisions it published on its own transparency page are from 2023, and its maximum fine is small. It made news in 2025 by ordering the central bank to stop collecting data that had not been anonymised. Verdict: awake and willing, not yet a heavy hitter.Medium confidence
How long must I keep it, and when must I delete it?
Costa Rica is unusual: it sets a hard delete date. Personal data that could harm the person in any way must not be kept more than ten years from the date of the events recorded, unless a specific law says otherwise. If you genuinely need it longer, you must strip it of anything that identifies the person. Separately, data must be deleted as soon as it stops being relevant for the purpose you collected it for. When a specific legal duty to keep records clashes with the ten-year ceiling, the specific duty wins.High confidence
What happens when something goes wrong?
The main clock is five working days. If personal data is lost, destroyed, mislaid or otherwise compromised, you must tell the affected people within five working days of the incident, and within the same window start a full review of how bad it is. You must also tell the regulator, giving what happened, which data was hit, what you fixed straight away, and where people can find out more. Telecoms companies have a second clock to the telecoms regulator, and government bodies report to the national cyber team.Medium confidence
What's the trap?
Five things bite. One: 'transfer' has a narrow legal meaning, so sending data to your own cloud or your own group needs no consent, but selling a list to an unrelated Costa Rican company does. Two: the ten-year delete ceiling has no equivalent in most countries and it is absolute. Three: sending Costa Ricans' data abroad without consent is the most serious class of offence and can shut your database for up to six months. Four: if you run a database to sell or share data, you must register it, pay 200 US dollars a year, and disclose where the data physically sits. Five: the fines are small, but the Act keeps criminal prosecution open on top.High confidence
What's about to change?
Nothing is confirmed to land in the next twelve months. A full replacement law, modelled on European rules, has been in parliament since 2022 under file number 23.097, but it had not passed as of 19 August 2026 and Costa Rica seated a new parliament on 1 May 2026. Treat it as a proposal, not a plan. The thing to actually watch is quieter: the detailed rules that make the current law workable sit in a decree the president can rewrite alone, and that decree has already been rewritten twice.Medium confidence
Hardest industry wall
None found.
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
The catch
The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
Does this apply to me?
Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
Can the data leave the country?
Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
What do I have to do to send it abroad?
The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
Who enforces this — and are they actually working?
The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
What happens when something goes wrong?
There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
What's the trap?
Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
What's about to change?
Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
Hardest industry wall
  • Telecoms Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
  • E-commerce Loi n° 18-05 relative au commerce electronique
  • Government Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees