Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
CyprusChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- For most businesses Cyprus behaves like a normal European country: data can leave, provided you use one of the standard European transfer tools. Two things make it stricter than its neighbours. If you move sensitive data such as health records out of Europe, you must tell the privacy regulator first. And breaking the privacy law in Cyprus is a crime, not just a fine.
- The catch
- The relaxed European headline stops being true in three places. Online betting operators must run a backup server physically inside Cyprus that mirrors their main one. Anyone sending sensitive data out of Europe must notify the regulator before the data moves, and she can order the transfer stopped. And insurers may not process genetic or fingerprint-type data for health or life cover at all. Outside those, Cyprus imposes no storage-location rule of its own.
- Does this apply to me?
- Yes. If you have no office anywhere in Europe but you sell to people in Cyprus, or you watch what they do online, the European privacy rules reach you and the Cypriot regulator can act. There is no minimum size or turnover that lets you escape. A company with no European base must name a written representative inside Europe, and the Cypriot law adds its own duties on top for anyone processing data here.High confidence
- Can the data leave the country?
- In general yes, with paperwork. Ordinary personal data leaves Cyprus on the same European terms as anywhere else in the bloc. But three Cypriot rules override that. Sensitive data going outside Europe must be notified to the regulator before it moves. Online betting operators must keep a mirror copy on a server inside Cyprus. And insurers cannot process genetic or fingerprint data for health or life cover at all.High confidence
- What do I have to do to send it abroad?
- The model is an approved-destination list. Data may go to a country the European Commission has approved, or you sign the European standard contract, or you use approved group-wide rules. Cyprus adds one step of its own: if the data is sensitive, tell the regulator before it goes, and if you are relying on a narrow exception rather than a contract, do a written risk assessment and consult her first.High confidence
- Who enforces this — and are they actually working?
- The Commissioner for Personal Data Protection, and she is genuinely working. In 2024 her office took 531 complaints and 94 breach reports, issued 88 decisions, and fined in 21 of them, totalling about 133,900 euros (roughly $146,000). The biggest single penalty, 46,500 euros, went to the state health services organisation. The current Commissioner is Maria Christofidou. A separate Digital Security Authority handles cyber incidents and is also active.High confidence
- How long must I keep it, and when must I delete it?
- There is no single national rule. The European ceiling applies: delete personal data once you no longer need it for the purpose you collected it for. The floors come from sector law. Betting operators must keep betting slips and related documents for five years, and may not destroy them afterwards without the regulator's permission. Where a floor and the ceiling collide, the specific legal duty to keep wins, but only for the data that duty actually covers.Medium confidence
- What happens when something goes wrong?
- Count three clocks and start with the shortest. If you run an essential or important service, Cyprus gives you SIX HOURS to send a first warning to the Digital Security Authority — one of the tightest deadlines in Europe, and far shorter than the 24 hours the European directive asked for. A full report follows within 72 hours and a final one within a month. Separately, a personal data breach goes to the privacy regulator within 72 hours, and to affected people if the risk to them is high.High confidence
- What's the trap?
- Five things that are not in the summary. (1) Breaking the privacy law in Cyprus is a crime — up to three years in prison, or five where national security is touched — and the law puts the blame on the company's most senior executive personally. (2) A child is anyone under 14 here, not 16 as in some neighbours. (3) Insurers may not use genetic or fingerprint-type data for health or life cover at all. (4) Sensitive data leaving Europe must be notified to the regulator first. (5) The cyber warning deadline is six hours, not 24.High confidence
- What's about to change?
- One hard European date matters most: from 12 January 2027 cloud providers must let customers move away with no exit or switching fees. Cyprus is also still building out its newest laws — the digital services law passed in 2025 and the artificial intelligence rules are being bedded in by the same privacy regulator, who now has three jobs instead of one. Watch three switches the government can flip with no warning.Medium confidence
- Hardest industry wall
- Insurance — Νόμος 125(Ι)/2018, άρθρο 9 — Επεξεργασία γενετικών και βιομετρικών δεδομένων
- Online gaming — Ο περί Στοιχημάτων Νόμος του 2019
FranceChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
- In one paragraph
- France follows the European rule: data may leave, but only once the right paperwork is in place. France then adds hard walls of its own. Health records must be stored inside Europe. Online gambling records must sit on a machine in mainland France. From 1 September 2026 the invoicing platform every French business must use has to run entirely from inside Europe.
- The catch
- "France has no local storage rule" is true for an ordinary business and false the moment you touch health data, online gambling, electronic invoicing or a government contract involving sensitive state data. In those four areas France is among the strictest countries in Europe. Since March 2026 the health rule sits in a decree, not just a certification standard, so it now binds the customer as well as the supplier.
- Does this apply to me?
- Yes. France reaches a company with no office in the country. European law already applies to anyone offering goods or services to people in Europe. On top of that, France's own privacy law says its national rules apply as soon as the person concerned lives in France, even when the company is based somewhere else. There is no size or revenue threshold that lets you escape.High confidence
- Can the data leave the country?
- For an ordinary business, yes, with paperwork: the European transfer rules apply and nothing extra is added. But four French sectors override that. Health records must be stored inside Europe and nowhere else. Online gambling records must be archived in real time on hardware in mainland France. Electronic invoicing platforms must run their whole system from inside Europe. And sensitive state data must sit on a cloud that the French cyber agency has certified as beyond the reach of foreign authorities.High confidence
- What do I have to do to send it abroad?
- The model is an approved-list one, run from Brussels rather than Paris. Data may go to a country the European Commission has formally approved, or anywhere else if you sign the official standard contract and write down why you think the data will still be safe. The list of approved countries is full, not empty: it includes the United Kingdom, Japan, South Korea, Canada, Switzerland, Brazil and about a dozen others, plus American companies that have signed up to the transatlantic framework. France adds no separate national approval step.High confidence
- Who enforces this — and are they actually working?
- The privacy regulator is the CNIL, and it is one of the busiest in Europe. In 2025 alone it issued 83 penalties totalling about 487 million euros (roughly 530 million dollars), plus 143 formal warnings. It is still fining in 2026: 5 million euros against the national employment agency in January and 5 million against a health data company in May. Separate regulators run the sector walls, and all of them are staffed and working.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling and they pull in opposite directions. You must keep accounting books and supporting documents for ten years, tax records for six, employment contracts and pay records for five, and telephone and internet subscriber identity data for five. In the other direction, European law says you must delete personal data once you no longer need it. France resolves the clash the same way most of Europe does: the legal minimum wins, but only for the specific documents the law names, and only for as long as it names.High confidence
- What happens when something goes wrong?
- Count the clocks, because France has at least four and they run at different speeds. Every organisation has 72 hours to tell the CNIL about a personal data breach. Telephone and internet providers have only 24 hours. Hospitals and clinics must report a serious computer security incident to their regional health agency immediately. Banks, insurers and investment firms have their own European deadlines: an initial report within 4 hours of classifying a major incident and no later than 24 hours after they notice it.High confidence
- What's the trap?
- Five things that are not in the summary. (1) Breaking the privacy law in France is a crime, not just a fine: sending data out of Europe unlawfully carries up to five years in prison and a 300,000 euro fine (about 330,000 dollars), and it attaches to people, not only companies. (2) A child is anyone under 15 for consent, not 13 or 16. (3) A 2023 law setting a social media age of 15 is printed in the statute book but has never come into force and cannot be enforced. (4) Handing documents to a foreign court or regulator can itself be a criminal offence in France. (5) Cookies are policed separately from the rest of privacy law, so a foreign company cannot hide behind its lead European regulator.High confidence
- What's about to change?
- Four dates in the next twelve months. 1 September 2026: every French business must be able to send and receive invoices through an approved platform, and those platforms must run entirely from inside Europe. Around 27 September 2026: the second phase of the health data hosting decree starts. 21 October 2026: the order forcing telephone and internet companies to keep everyone's connection records for a year expires unless the Prime Minister renews it. 12 January 2027: cloud providers across Europe must drop switching and data export fees to zero.Medium confidence
- Hardest industry wall
- Health and social care — Decret n° 2026-209 du 24 mars 2026 portant modification de certaines dispositions du code de la sante publique relatives a l'hebergement de donnees de sante a caractere personnel
- Government — Decret n° 2026-272 du 14 avril 2026 relatif a la protection des donnees d'une sensibilite particuliere des administrations, operateurs et groupements d'interet public de l'Etat traitees par un service d'informatique en nuage fourni par un prestataire prive
- All industries — Immatriculation des plateformes agreees (ex plateformes de dematerialisation partenaires) - facturation electronique
- Online gaming — Article 31 de la loi n° 2010-476 du 12 mai 2010 relative a l'ouverture a la concurrence et a la regulation du secteur des jeux d'argent et de hasard en ligne