Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
Dominican RepublicChecked 19 August 2026
Yes, with paperworkWork: MediumEnforcement: Dormant
- In one paragraph
- The Dominican Republic has had a personal data law since December 2013, and it never got a regulator. Data may leave the country whenever one of nine reasons in the law applies, and consent is the easy one. There is no list of banned countries, no filing, no registration and no breach report to send. But breaking the law is a crime, not a paperwork slip, and the money-laundering and tax rules make you keep records for ten years.
- The catch
- The country looks relaxed because nobody is watching, not because the rules are generous. There is no data protection authority to fine you, so the real risk sits with criminal prosecutors, with judges hearing individual claims, and with the banking regulator, which is genuinely active. One narrow storage rule does exist: records showing who really owns a company must be kept inside the country.
- Does this apply to me?
- The law says it applies throughout the national territory. It does not say it follows Dominicans' data abroad, and it does not ask a foreign company to appoint anyone locally. There is no size or revenue threshold, and no register to join. If you have no office, no staff and no equipment in the country, there is no authority with power to fine you, but a Dominican judge can still hear a claim from a person here and a prosecutor can still act if the conduct is a crime.High confidence
- Can the data leave the country?
- Yes, but only for one of nine reasons written into the law. The first is that the person freely decided to allow it, which is how almost everyone does it. The others cover medical care and epidemics, bank and stock market transactions, treaties and free trade agreements, crime-fighting cooperation, performing a contract with the person, legal claims and tax or customs demands, international judicial assistance, and requests from an international body drawing on a public register. There is no list of banned countries and no list of approved ones. We searched banking, payments, insurance, securities, health, telecommunications, government cloud, education, gambling and mapping and found no rule ordering personal data to stay in the country. The one storage rule we did find is narrow: records showing who really owns a company must be kept inside the Dominican Republic.High confidence
- What do I have to do to send it abroad?
- There is nothing to sign with the government and nobody to ask. No approval, no standard contract, no registration, no adequacy list. You only need to be able to show that one of the nine reasons in the law applied when the data moved, and in ordinary business that means a consent that was free, informed and unambiguous. Because no authority polices this, the person who checks your homework is a judge, and only after someone complains.High confidence
- Who enforces this — and are they actually working?
- Nobody, in the way most countries mean it. The Dominican Republic has no data protection authority. The only body the law gives fining power to is the Superintendency of Banks, and only over credit reference companies. Everyone else is policed by criminal prosecutors, by the high-technology crime police unit, and by ordinary judges hearing claims brought by individuals. The Constitutional Court was issuing rulings as recently as the seventeenth of August 2026, so the court route is real. The sector regulators are genuinely working: the Superintendency of Banks published circulars throughout 2026, and the National Cybersecurity Centre was signing cooperation agreements in July 2026.High confidence
- How long must I keep it, and when must I delete it?
- The floors are much stronger than the ceilings. Businesses covered by the money-laundering rules must keep transaction records, customer checks, account files and business correspondence for at least ten years after the relationship ends. Tax and accounting records also run ten years. Internet and telephone providers must keep traffic, connection and access records for at least ninety days. Anyone who runs a credit check must keep the customer's written permission for six months. Going the other way, the only real deletion rule is that a credit history may not report events older than forty-eight months, and that inaccurate or incomplete data must be corrected or removed. If a keep-it rule and a delete-it rule collide, the keep-it rule wins, because the law says the right to have data erased does not apply where another law requires it to be kept.High confidence
- What happens when something goes wrong?
- There is no general duty to report a data breach. The 2013 law does not contain one, so a private company that loses customer data owes no report to any authority and no notice to the people affected. Two narrower clocks do exist. Government bodies must report a cybersecurity incident immediately, and the report must reach the national cyber team or the sector team within twenty-four hours of detection. Banks and payment system participants must run a documented incident process and answer to the financial sector's own incident response team, but the regulation sets no fixed number of hours. Everyone can also report voluntarily to the National Cybersecurity Centre, which runs a public reporting page.High confidence
- What's the trap?
- Five things that are not in the summary. First, breaking this law is a crime: any person or company that violates it faces six months to two years in prison plus a fine of one hundred to one hundred and fifty times the monthly minimum wage, which runs to tens of thousands of US dollars. Second, selling or offering a list of email addresses without the owners' express consent is a separate crime under the anti-spam law, carrying six months to five years, and it is the public prosecutor who brings it. Third, the absence of a breach report duty is not protection, because the person harmed can sue and a prosecutor can charge. Fourth, records of who really owns a company must be held inside the country, which quietly breaks a fully offshore corporate-records setup. Fifth, there is no authority to give you a ruling, a licence or a comfort letter, so there is no way to buy certainty in advance.High confidence
- What's about to change?
- Three things are moving. A cybersecurity bill of sixty-four articles, covering public administration and critical infrastructure, went to a Senate committee in September 2025 and was still being studied there; it is a bill, so it binds nobody yet. The telecommunications institute has put forward a proposal for a new telecommunications law to replace the 1998 statute. And the operational risk rules for banks, approved in November 2025, have parts that only start to bite on the first of April 2027. We found no bill in either chamber to replace the 2013 data protection law or to create a data protection authority.Medium confidence
- Hardest industry wall
- Finance — Ley No. 155-17 contra el Lavado de Activos y el Financiamiento del Terrorismo
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
- The catch
- The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
- Does this apply to me?
- Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
- Can the data leave the country?
- Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
- What do I have to do to send it abroad?
- The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
- Who enforces this — and are they actually working?
- The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
- What happens when something goes wrong?
- There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
- What's the trap?
- Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
- What's about to change?
- Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
- Hardest industry wall
- Telecoms — Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
- E-commerce — Loi n° 18-05 relative au commerce electronique
- Government — Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees