Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
CyprusChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
For most businesses Cyprus behaves like a normal European country: data can leave, provided you use one of the standard European transfer tools. Two things make it stricter than its neighbours. If you move sensitive data such as health records out of Europe, you must tell the privacy regulator first. And breaking the privacy law in Cyprus is a crime, not just a fine.
The catch
The relaxed European headline stops being true in three places. Online betting operators must run a backup server physically inside Cyprus that mirrors their main one. Anyone sending sensitive data out of Europe must notify the regulator before the data moves, and she can order the transfer stopped. And insurers may not process genetic or fingerprint-type data for health or life cover at all. Outside those, Cyprus imposes no storage-location rule of its own.
Does this apply to me?
Yes. If you have no office anywhere in Europe but you sell to people in Cyprus, or you watch what they do online, the European privacy rules reach you and the Cypriot regulator can act. There is no minimum size or turnover that lets you escape. A company with no European base must name a written representative inside Europe, and the Cypriot law adds its own duties on top for anyone processing data here.High confidence
Can the data leave the country?
In general yes, with paperwork. Ordinary personal data leaves Cyprus on the same European terms as anywhere else in the bloc. But three Cypriot rules override that. Sensitive data going outside Europe must be notified to the regulator before it moves. Online betting operators must keep a mirror copy on a server inside Cyprus. And insurers cannot process genetic or fingerprint data for health or life cover at all.High confidence
What do I have to do to send it abroad?
The model is an approved-destination list. Data may go to a country the European Commission has approved, or you sign the European standard contract, or you use approved group-wide rules. Cyprus adds one step of its own: if the data is sensitive, tell the regulator before it goes, and if you are relying on a narrow exception rather than a contract, do a written risk assessment and consult her first.High confidence
Who enforces this — and are they actually working?
The Commissioner for Personal Data Protection, and she is genuinely working. In 2024 her office took 531 complaints and 94 breach reports, issued 88 decisions, and fined in 21 of them, totalling about 133,900 euros (roughly $146,000). The biggest single penalty, 46,500 euros, went to the state health services organisation. The current Commissioner is Maria Christofidou. A separate Digital Security Authority handles cyber incidents and is also active.High confidence
How long must I keep it, and when must I delete it?
There is no single national rule. The European ceiling applies: delete personal data once you no longer need it for the purpose you collected it for. The floors come from sector law. Betting operators must keep betting slips and related documents for five years, and may not destroy them afterwards without the regulator's permission. Where a floor and the ceiling collide, the specific legal duty to keep wins, but only for the data that duty actually covers.Medium confidence
What happens when something goes wrong?
Count three clocks and start with the shortest. If you run an essential or important service, Cyprus gives you SIX HOURS to send a first warning to the Digital Security Authority — one of the tightest deadlines in Europe, and far shorter than the 24 hours the European directive asked for. A full report follows within 72 hours and a final one within a month. Separately, a personal data breach goes to the privacy regulator within 72 hours, and to affected people if the risk to them is high.High confidence
What's the trap?
Five things that are not in the summary. (1) Breaking the privacy law in Cyprus is a crime — up to three years in prison, or five where national security is touched — and the law puts the blame on the company's most senior executive personally. (2) A child is anyone under 14 here, not 16 as in some neighbours. (3) Insurers may not use genetic or fingerprint-type data for health or life cover at all. (4) Sensitive data leaving Europe must be notified to the regulator first. (5) The cyber warning deadline is six hours, not 24.High confidence
What's about to change?
One hard European date matters most: from 12 January 2027 cloud providers must let customers move away with no exit or switching fees. Cyprus is also still building out its newest laws — the digital services law passed in 2025 and the artificial intelligence rules are being bedded in by the same privacy regulator, who now has three jobs instead of one. Watch three switches the government can flip with no warning.Medium confidence
Hardest industry wall
  • Insurance Νόμος 125(Ι)/2018, άρθρο 9 — Επεξεργασία γενετικών και βιομετρικών δεδομένων
  • Online gaming Ο περί Στοιχημάτων Νόμος του 2019
United StatesChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
In general the United States lets data go anywhere. There is no national privacy law and no permit is needed to move data abroad. Two things bite hard. Six countries are effectively off limits for large amounts of sensitive data, with prison sentences attached. And anything connected to government work must physically stay on American soil.
The catch
The open headline stops the moment you touch one of six areas: government contracting, police records, federal tax records, defence technical data, telecom licences, and bulk sensitive data flowing to China, Russia, Iran, North Korea, Cuba or Venezuela. Also note that the rule that actually binds you is almost always a state law or an industry regulator's rule, not a national privacy act. There isn't one.
Does this apply to me?
Yes. American rules reach a foreign company with no office in the country. California's privacy law applies to any for-profit business that 'does business in California' and crosses one of three thresholds, and physical presence is not one of them. The children's rule covers foreign websites aimed at American children. No state and no federal law requires you to appoint a local representative — a real difference from Europe.High confidence
Can the data leave the country?
It depends entirely on your industry, so the single national answer is misleading. For ordinary consumer or employee data, yes — send it anywhere, no paperwork. But six sectors have hard walls. Government contracting, police data, federal tax data and defence work require the data to physically stay in the United States. Telecom licences restrict which foreign staff may even look at records. And for anyone, sending large volumes of sensitive data to six named countries is now a crime.High confidence
What do I have to do to send it abroad?
For ordinary data, nothing. No standard contract, no government approval, no destination approval list. The model is a blocklist and it is now populated: six countries are named. Before you move large volumes of sensitive data, your only real job is to work out whether a country of concern, or a company or person they control, could end up with access — including through a vendor, an investor or an employee.High confidence
Who enforces this — and are they actually working?
Nobody, and everybody. There is no national privacy regulator. Instead the consumer protection regulator, the health department, the securities regulator, the communications regulator, the Justice Department, all fifty state attorneys general and one dedicated state privacy agency each enforce a slice. Almost all of them are visibly working right now. The one exception is the new national data transfer programme: it is staffed and issuing guidance but has published no enforcement action yet.High confidence
How long must I keep it, and when must I delete it?
There is a strong floor and a weak but growing ceiling. Investment firms must keep some books for six years and most others for three, with the first two years easy to reach. Health providers keep their paperwork for six years. In the other direction, state privacy laws now force you to publish how long you keep each type of data and to stop keeping it longer than you said, and since April 2026 children's data may no longer be kept indefinitely. Where a keep-it rule and a delete-it rule collide, the keep-it rule wins: every state law carves out data you are required by law to retain.High confidence
What happens when something goes wrong?
Count the clocks — there are at least seven, and they disagree. New York financial firms: 72 hours to the state regulator, and only 24 hours to report paying a ransom. Telecom carriers: seven working days to the police agencies and the communications regulator, and you may not warn customers until seven working days after that. Investment and finance firms: 30 days to affected customers. Health organisations: 60 days. Texas and many other states: 30 days to the state attorney general. Listed companies: four working days to disclose a material incident. The overlap, not any single deadline, is what people fail.High confidence
What's the trap?
Five that cost people their weekend. One: the national data transfer programme carries prison — up to twenty years for a deliberate breach. Two: Illinois lets individuals sue over fingerprints and face scans with fixed damages per person, no proof of harm needed, and that is where the largest privacy payouts happen. Three: the children's rule uses under 13, but several state laws use under 18, so a single age gate will not do. Four: government work means American soil, and police data allows only the United States, its territories, tribal lands and Canada. Five: a rule can be printed in the law book and still be unenforceable, because a court has blocked it.High confidence
What's about to change?
Four things in the next twelve months. The national critical infrastructure reporting rule should be finalised in late 2026, which will switch on a 72-hour incident clock and a 24-hour ransom-payment clock for a very wide range of businesses. California's rules on automated decision-making bite on 1 January 2027. The open banking rule is being rewritten after a court blocked it. And a federal privacy bill is moving in Congress, but it is only a bill and binds nobody.High confidence
Hardest industry wall
  • Government Criminal Justice Information Services (CJIS) Security Policy
  • Government Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies
  • Defence Defense Federal Acquisition Regulation Supplement clause 252.239-7010, Cloud Computing Services
  • Telecoms National security agreement / letter of assurance conditioning a section 214 authorisation, reviewed by the Committee for the Assessment of Foreign Participation in the United States Telecommunications Services Sector