Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
CyprusChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
For most businesses Cyprus behaves like a normal European country: data can leave, provided you use one of the standard European transfer tools. Two things make it stricter than its neighbours. If you move sensitive data such as health records out of Europe, you must tell the privacy regulator first. And breaking the privacy law in Cyprus is a crime, not just a fine.
The catch
The relaxed European headline stops being true in three places. Online betting operators must run a backup server physically inside Cyprus that mirrors their main one. Anyone sending sensitive data out of Europe must notify the regulator before the data moves, and she can order the transfer stopped. And insurers may not process genetic or fingerprint-type data for health or life cover at all. Outside those, Cyprus imposes no storage-location rule of its own.
Does this apply to me?
Yes. If you have no office anywhere in Europe but you sell to people in Cyprus, or you watch what they do online, the European privacy rules reach you and the Cypriot regulator can act. There is no minimum size or turnover that lets you escape. A company with no European base must name a written representative inside Europe, and the Cypriot law adds its own duties on top for anyone processing data here.High confidence
Can the data leave the country?
In general yes, with paperwork. Ordinary personal data leaves Cyprus on the same European terms as anywhere else in the bloc. But three Cypriot rules override that. Sensitive data going outside Europe must be notified to the regulator before it moves. Online betting operators must keep a mirror copy on a server inside Cyprus. And insurers cannot process genetic or fingerprint data for health or life cover at all.High confidence
What do I have to do to send it abroad?
The model is an approved-destination list. Data may go to a country the European Commission has approved, or you sign the European standard contract, or you use approved group-wide rules. Cyprus adds one step of its own: if the data is sensitive, tell the regulator before it goes, and if you are relying on a narrow exception rather than a contract, do a written risk assessment and consult her first.High confidence
Who enforces this — and are they actually working?
The Commissioner for Personal Data Protection, and she is genuinely working. In 2024 her office took 531 complaints and 94 breach reports, issued 88 decisions, and fined in 21 of them, totalling about 133,900 euros (roughly $146,000). The biggest single penalty, 46,500 euros, went to the state health services organisation. The current Commissioner is Maria Christofidou. A separate Digital Security Authority handles cyber incidents and is also active.High confidence
How long must I keep it, and when must I delete it?
There is no single national rule. The European ceiling applies: delete personal data once you no longer need it for the purpose you collected it for. The floors come from sector law. Betting operators must keep betting slips and related documents for five years, and may not destroy them afterwards without the regulator's permission. Where a floor and the ceiling collide, the specific legal duty to keep wins, but only for the data that duty actually covers.Medium confidence
What happens when something goes wrong?
Count three clocks and start with the shortest. If you run an essential or important service, Cyprus gives you SIX HOURS to send a first warning to the Digital Security Authority — one of the tightest deadlines in Europe, and far shorter than the 24 hours the European directive asked for. A full report follows within 72 hours and a final one within a month. Separately, a personal data breach goes to the privacy regulator within 72 hours, and to affected people if the risk to them is high.High confidence
What's the trap?
Five things that are not in the summary. (1) Breaking the privacy law in Cyprus is a crime — up to three years in prison, or five where national security is touched — and the law puts the blame on the company's most senior executive personally. (2) A child is anyone under 14 here, not 16 as in some neighbours. (3) Insurers may not use genetic or fingerprint-type data for health or life cover at all. (4) Sensitive data leaving Europe must be notified to the regulator first. (5) The cyber warning deadline is six hours, not 24.High confidence
What's about to change?
One hard European date matters most: from 12 January 2027 cloud providers must let customers move away with no exit or switching fees. Cyprus is also still building out its newest laws — the digital services law passed in 2025 and the artificial intelligence rules are being bedded in by the same privacy regulator, who now has three jobs instead of one. Watch three switches the government can flip with no warning.Medium confidence
Hardest industry wall
  • Insurance Νόμος 125(Ι)/2018, άρθρο 9 — Επεξεργασία γενετικών και βιομετρικών δεδομένων
  • Online gaming Ο περί Στοιχημάτων Νόμος του 2019
SerbiaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
In one paragraph
Serbia copied Europe's privacy law almost word for word, so the duties feel familiar. Data can leave the country, and for most of Europe and a long list of other countries it can leave with no paperwork at all. The privacy regulator is busy — over a thousand inspections in 2025 — but it hands out warnings, not fines. The biggest fine any Serbian court imposed for a privacy breach in 2025 was about $950.
The catch
Two industries break the general picture. Online gambling operators must keep a copy of their whole player and transaction database physically inside Serbia. Banks, insurers and other financial firms cannot move any IT work abroad without telling the central bank 30 days ahead, proving the foreign country would let Serbian supervisors inspect on site, and risking a veto that forces them to cancel the contract.
Does this apply to me?
Yes. The law reaches a company anywhere in the world if it offers goods or services to people in Serbia, or watches what they do in Serbia. There is no size or revenue threshold to hide behind. If you are caught this way you must appoint a written representative living or based in Serbia, unless your processing is occasional and low risk or you are a public body.High confidence
Can the data leave the country?
Yes, with paperwork — and often with none at all. Serbia treats a very long list of countries as automatically safe: every member of the Council of Europe's data protection treaty, which covers all of Europe plus Argentina, Mexico, Morocco, Mauritius, Senegal, Tunisia, Uruguay, Cape Verde and others, and separately every country the European Union has approved. Sending data there needs no permission and no contract. Everywhere else you sign the Commissioner's standard contract or use approved group rules. Only one industry has a hard wall: online gambling. Banking has a gate rather than a wall.High confidence
What do I have to do to send it abroad?
First check the destination. If it is on the safe list, you need nothing — no contract, no filing, no approval. If it is not, you sign the standard contract the Serbian regulator published in January 2020, or you get approved group-wide rules. If you want to use your own wording instead of the standard contract, the regulator must approve it and has 60 days to answer. As a last resort there are narrow exceptions such as the person's explicit consent.High confidence
Who enforces this — and are they actually working?
The Commissioner for Information of Public Importance and Personal Data Protection, and it is genuinely working. In 2025 it finished 1,169 inspections, received 5,310 cases and issued 102 corrective orders. But it almost never fines. Of those 102 orders, 101 were warnings and one was a ban on processing. It asked the courts to punish only three organisations all year. Banks answer to the National Bank of Serbia instead, and it is fully active. A brand-new Office for Information Security exists on paper since October 2025 but we could find no sign it is running yet.High confidence
How long must I keep it, and when must I delete it?
There is no single national rule. The privacy law says keep data only as long as you need it, and each sector sets its own clock. Online gambling operators must keep every transaction for at least ten years. Phone and internet companies must keep who-called-whom records for exactly 12 months and then destroy them. Anyone selling a phone line must keep the customer's identity check for 12 months after the service ends. Financial firms must keep a live register of every outsourced service, including which countries the data sits in.High confidence
What happens when something goes wrong?
Count three clocks. Privacy breach: tell the Commissioner without delay and at the latest within 72 hours, and if you miss that you must explain why. Cyber incident: if you run an information system the state has classed as important, you have only 24 hours to report it. Then a third clock starts — updates every 24 hours for a serious incident, every three days for a middling one, and a final report within 15 days of the incident ending. Banks report cyber incidents to the central bank instead, promptly, with no fixed hour count.High confidence
What's the trap?
Five. (1) A child can consent for themselves at 15, not 13 or 16 — plan your age gates around 15. (2) A foreign court order or foreign tax authority demand for data is recognised in Serbia only if a treaty backs it, so handing data to an overseas authority on request can itself be unlawful. (3) Individuals, not just companies, can be prosecuted; the regulator has filed 49 criminal complaints since 2010. (4) Dozens of older Serbian laws still contradict the privacy law and were never fixed. (5) The government's official list of safe destination countries has not been touched since 2019 and still names a United States framework that died in 2020.High confidence
What's about to change?
One dated change and several unscheduled ones. From 1 January 2027 the ministry formally takes over supervising the new Office for Information Security, which should mean the office is actually up and running by then. A rewrite of the privacy law is being drafted by a special working group covering video surveillance, biometrics, genetic data and artificial intelligence, and a separate group is drafting an artificial intelligence law. Neither has been published as a bill, so neither is binding.High confidence
Hardest industry wall
  • Online gaming Pravilnik o informaciono-komunikacionom sistemu za priređivanje posebnih igara na sreću preko sredstava elektronske komunikacije