Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
DenmarkChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
In one paragraph
Denmark follows the European Union rulebook: personal data may leave the country once you have the right legal paperwork in place. There is no general rule that data must stay in Denmark. But there are three real walls. Named Danish state computer systems must run inside Denmark. Every business must keep a backup of its accounting records on a server inside Europe. And Denmark punishes data protection breaches as crimes, not with administrative fines.
The catch
The relaxed headline stops being true in four places. A list of named Danish government systems, including the national identity login, digital post, the civil registration system and the police systems, must be operated inside Denmark. The weekly backup of a company's digital bookkeeping must sit with an unrelated third party on a server in a European Union or European Economic Area country, and getting that wrong is a criminal offence. Detailed population statistics released to researchers can never be taken off the government's own machines. And schools and town halls were told in February 2026 that their existing setups for cloud classroom software were not lawful.
Does this apply to me?
Yes. The Danish data protection law reaches a company with no office in Denmark, as long as it offers goods or services to people located in Denmark, or watches what they do here. There is no size or revenue threshold to hide below. A company based entirely outside Europe must appoint a representative inside Europe under the European Union rules, but Denmark does not add a second, Denmark-only representative on top for ordinary businesses.High confidence
Can the data leave the country?
In general, yes. Denmark is an ordinary European Union member, so data can go abroad once the standard European paperwork is in place, and there is no Danish rule that personal data must stay in Denmark. But four areas override that. Named Danish state computer systems must run inside Denmark. Accounting backups must sit on a server inside Europe. Detailed population statistics given to researchers can never leave the government's own machines. And schools and town halls have been told their cloud classroom setups did not meet the rules.High confidence
What do I have to do to send it abroad?
Denmark adds nothing of its own. You use the European Union machinery: send data to a country the European Commission has approved, or sign the European standard contract, or use approved group-wide rules. There is no Danish permit, no Danish filing and no Danish waiting period. The one Danish twist is at the other end: sending data abroad without a proper legal basis is a criminal offence here, not just something you get fined for.High confidence
Who enforces this — and are they actually working?
The Danish Data Protection Agency, and it is fully staffed and busy. It opened 20,536 new cases in 2025 and received 9,849 breach reports. But it cannot fine you. Denmark is almost alone in Europe in treating data protection breaches as crimes, so the agency has to hand the case to the police, who then prosecute in court. In all of 2025 it did that just twice. So expect orders, bans and public criticism rather than large fines.High confidence
How long must I keep it, and when must I delete it?
Denmark sets several minimum keeping periods. Accounting records: five years after the financial year ends. Patient records: ten years for doctors and dentists, five for other health professionals. Gambling records: five years. Telephone and internet traffic records: one year. In the other direction, the European rules say delete personal data once you no longer need it. Where the two collide, the specific Danish keeping duty wins for as long as it runs, and you delete after it expires.High confidence
What happens when something goes wrong?
Count at least three clocks and they run at different speeds. For a personal data breach you have 72 hours to tell the Danish Data Protection Agency, and you must tell affected people without delay if the risk to them is high. If you are a company covered by the Danish cyber security law, you have only 24 hours to send an early warning, then 72 hours for a fuller report, then one month for the final report. Financial firms report separately under the European resilience rules.High confidence
What's the trap?
Five things catch people out. A child in Denmark is anyone under 15 for online consent, not 13 and not 16. Breaking the data rules is a crime here, with prison on the books. The Danish personal identity number has its own rulebook and must never be published. Your accounting backup must be on a European server, and getting that wrong is a criminal offence. And the Justice Minister can order any government system to run only in Denmark, overnight, with no consultation.High confidence
What's about to change?
Three things are already law and biting now: the cyber security regime, the new health digitisation body, and the last stage of the digital bookkeeping rules. One big thing is promised but not yet law: an age limit of 15 for social media, agreed by politicians in November 2025 but with no bill found as of August 2026. And two switches can flip without warning: the list of government systems that must stay in Denmark, and the telephone logging order, which has to be renewed every year.Medium confidence
Hardest industry wall
  • Government Bekendtgørelse om hel eller delvis opbevaring her i landet af personoplysninger, der behandles i nærmere bestemte it-systemer, og som føres for den offentlige forvaltning
  • All industries Bekendtgørelse om krav til virksomheders digitale bogføringssystemer der ikke er registreret efter bogføringsloven
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
The catch
The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
Does this apply to me?
Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
Can the data leave the country?
Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
What do I have to do to send it abroad?
The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
Who enforces this — and are they actually working?
The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
What happens when something goes wrong?
There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
What's the trap?
Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
What's about to change?
Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
Hardest industry wall
  • Telecoms Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
  • E-commerce Loi n° 18-05 relative au commerce electronique
  • Government Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees