Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
GermanyChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Contrary to widespread belief, neither Europe nor Germany requires personal data to be stored in Europe. What the law requires is a valid legal instrument before data leaves — an official decision that the destination is safe enough, or a standard contract, plus a documented risk assessment. Germany then adds its own layer on top, and one genuine hard wall: health and social data may only be processed in the cloud within Europe, by a provider holding a specific German security certificate.
- The catch
- 'Germany doesn't require local storage' is true right up until you sell to a hospital, a health insurer, a doctor, a lawyer or a tax adviser. In health and social care it is simply false, and for the professional-secrecy trades a standard data processing agreement is not enough and getting it wrong is a criminal matter.
- Does this apply to me?
- Yes, it reaches you with no office in Germany. Europe's privacy law applies to any organisation anywhere that offers goods or services to people in Europe or monitors their behaviour. If you have no European establishment you must also appoint a representative inside Europe.High confidence
- Can the data leave the country?
- Yes — with paperwork. This is the single most misunderstood point in the field. European law does not say where data must sit; it says what you must have in place before it leaves Europe. Storage location is a risk factor in that assessment, never a prohibition. For non-personal data, Europe goes further and actually forbids member states from imposing storage-location rules.High confidence
- What do I have to do to send it abroad?
- One of three routes. Best case, the destination is on Europe's official 'adequate' list and you need nothing extra — currently 17 entries including the UK, Japan, South Korea, Switzerland, Canada for commercial bodies, Brazil since January 2026, and the United States but only for companies self-certified under the EU-US Data Privacy Framework. Otherwise you sign Europe's standard contract clauses, or get group-wide internal rules approved. In either of those two cases you must also document an assessment of whether the destination country's surveillance laws undermine the protection.High confidence
- Who enforces this — and are they actually working?
- Eighteen separate authorities, and for a private company it is almost never the federal one. Each of the 16 states has its own regulator, and you answer to the one where your German office is. The federal regulator handles government bodies plus telecoms and postal operators. Bavaria splits it further, with different bodies for private and public sector. If you operate across Europe, a separate rule lets you deal mainly with the regulator where your main European establishment sits.High confidence
- How long must I keep it, and when must I delete it?
- Business records have a floor: accounting vouchers must be kept 8 years (cut from 10 with effect from 2025, and from 2026 for banks and insurers), the annual accounts and trading books still 10 years, and business correspondence 6 years. Privacy law pushes the other way — don't keep personal data longer than you need it. Where the two collide, German law has an elegant answer: you restrict processing of the data instead of deleting it.High confidence
- What happens when something goes wrong?
- 72 hours to tell your state regulator about a personal data breach, and without undue delay to tell affected people where the risk to them is high. Separately, since December 2025 Germany's cybersecurity law adds its own clocks for around 29,500 in-scope companies: a first warning within 24 hours, an update at 72 hours, and a full report within a month. Financial firms follow a separate European regime instead.High confidence
- What's the trap?
- Four. (1) Health and social data really does have to stay in Europe, with a specific German security certificate — the general 'no localisation' answer is wrong here. (2) For doctors, lawyers, tax advisers and notaries, a standard data processing agreement is NOT enough: you need explicit secrecy undertakings flowed down to every subcontractor, and breach is a criminal offence, not a fine. (3) Germany still requires a data protection officer at just 20 employees involved in data processing — far stricter than European law, and still in force despite a government promise to scrap it by the end of 2026. (4) The German rule people cite for employee data was effectively struck down by Europe's top court in 2023 but never removed from the statute book, so citing it as your legal basis is a mistake.High confidence
- What's about to change?
- Two hard dates and one live risk. From 12 January 2027 every cloud provider must drop switching and data egress fees to zero — renegotiate contracts now. By 31 December 2026 Germany's banking IT rulebook is fully withdrawn in favour of the European financial regime. The live risk is the US arrangement: Europe's data protection board formally asked the Commission on 31 July 2026 to review whether it is still valid, and a separate court appeal is pending. If it falls, thousands of transfers move to standard contracts overnight.High confidence
- Hardest industry wall
- Health and social care — § 393 SGB V — Cloud-Einsatz im Gesundheitswesen
- Telecoms — §§ 175–181 TKG — Vorratsdatenspeicherung
BulgariaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Bulgaria is an ordinary European Union country for data. Personal data can leave, as long as you use one of the standard European transfer tools. There is no general rule forcing data to stay in Bulgaria. But online gambling is a hard exception: a control server must physically sit on Bulgarian soil. Bulgaria switched to the euro on 1 January 2026, so all fines are now in euro.
- The catch
- The relaxed headline stops being true in two places. First, online gambling: an operator licensed in Bulgaria must keep a control local server on Bulgarian territory and stream live game data to the tax authority's server. Second, telecoms: operators must build and pay for interception equipment wired into two Bulgarian state agencies, which cannot be run from abroad. Mapping and aerial survey work also needs clearance from five Bulgarian ministries and agencies before you may even collect the data.
- Does this apply to me?
- Yes, it can reach you with no office in Bulgaria. The European Union's privacy rulebook applies to anyone who offers goods or services to people in Europe or watches what they do online. Bulgaria's own Personal Data Protection Act sits on top of that and adds extra local duties. There is no revenue or headcount threshold, and no Bulgaria-specific representative: the European-wide requirement to name a representative in Europe is the only one, and it can be in any European country.High confidence
- Can the data leave the country?
- In general, yes. Bulgaria has no law telling ordinary businesses to keep personal data inside the country. Data moves freely to the rest of Europe, to Switzerland, and to countries Europe has approved; anywhere else needs a standard contract or a similar tool. Two industries break that pattern. Online gambling operators must keep a control server physically in Bulgaria. Telecoms operators must build interception equipment that plugs into Bulgarian state agencies, which cannot sit abroad.High confidence
- What do I have to do to send it abroad?
- Bulgaria uses Europe's system, not its own. There is no Bulgarian list of banned countries and no Bulgarian permit to apply for. If the destination is inside Europe, the wider European Economic Area or Switzerland, nothing extra is needed. Otherwise you need either an official European approval of that country, or the standard European contract, or approved group-wide rules. One Bulgarian twist: Bulgarian law explicitly puts Switzerland on the same footing as a European Union country.High confidence
- Who enforces this — and are they actually working?
- The Commission for Personal Data Protection is the main regulator. It is real, staffed and it does issue formal decisions, including ones published across Europe. But it is not a heavy hitter. In a Europe-wide check on deletion rights reported in February 2026, it contacted twenty-three organisations, opened no formal investigations, imposed no penalties, and said it did not plan to. A separate inspectorate polices the courts and prosecutors. Cybersecurity has its own separate regulators.Medium confidence
- How long must I keep it, and when must I delete it?
- Bulgaria has strong minimum-keeping rules and a few sharp delete-by rules. You must keep payroll records for fifty years, accounting books and financial statements for ten years, and other accounting papers for three years. Telecoms firms keep connection records for six months. Going the other way, job applicants' data must be deleted within six months unless they agree otherwise, and data you were given with no legal basis must be returned or destroyed within one month.High confidence
- What happens when something goes wrong?
- There are at least three clocks and they do not agree. A personal data breach must reach the privacy regulator within seventy-two hours. Under the cybersecurity law rewritten in February 2026, an early warning must reach the response team within twenty-four hours and a fuller report within seventy-two hours. Trust service providers get twenty-four hours for that fuller report. Financial firms answer to the separate European financial-resilience rules on top.High confidence
- What's the trap?
- Five things bite people in Bulgaria. You may not photocopy someone's identity card, driving licence or residence permit unless a law lets you. Children need a parent's consent up to age fourteen, not sixteen. Job applicant files must go within six months. Your accounting software must be able to output in Bulgarian. And one clause of the privacy law was struck down by the Constitutional Court in 2019 but is still printed in the statute.High confidence
- What's about to change?
- Two dated changes are already fixed. From 12 January 2027 every cloud provider must let customers move their data out for free. Bulgaria's new cybersecurity duties started on 13 February 2026 and enforcement is only now warming up. The biggest live risk is not Bulgarian at all: Europe's approval of United States data transfers is being challenged, and Europe's own privacy board asked the Commission on 31 July 2026 to re-examine it.High confidence
- Hardest industry wall
- Online gaming — Закон за хазарта