Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
EstoniaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Estonia has no general rule forcing data to stay in the country, and it adds very little on top of the European privacy rules. Two industries are the exception. Phone and internet companies must keep connection records inside the European Union, with some records physically in Estonia. Online gambling firms may only run their game server from a short list of approved countries. The regulator works, but its fines are small.
- The catch
- The relaxed headline stops being true the moment you are a telecoms operator, an online gambling operator, a health care provider or a public body. Telecoms connection records may not leave the European Union at all and certain police-request records must sit on Estonian soil. Gambling servers are limited to an approved list of countries. Health records carry a 30-year minimum keep-time. Public bodies must run the Estonian national security standard and exchange data through the state's own data layer.
- Does this apply to me?
- Yes, it reaches you even with no office in Estonia. Estonia does not write its own reach test — it uses the European Union's. If you offer goods or services to people in Estonia, or track what they do online, the European privacy rules apply and Estonia's regulator can act against you. There is no size or revenue threshold to fall below. A company with no branch anywhere in Europe normally has to name a written representative inside Europe.High confidence
- Can the data leave the country?
- In general, yes. Estonia has no law telling companies to keep personal data in Estonia, and European law actually forbids member states from imposing one on non-personal data. Two industries break that headline. Phone and internet companies must keep their call and connection records inside the European Union, and certain police-request records must stay physically in Estonia. Online gambling companies may only place their game server in Estonia, in a country that has signed the cybercrime treaty, or in a country whose regulator has a cooperation deal with the Estonian Tax and Customs Board.High confidence
- What do I have to do to send it abroad?
- For the normal routes you file nothing with the Estonian regulator. If the destination country has been officially approved by the European Commission, you simply send the data. If it has not, you sign the European Commission's standard contract with the recipient and run a risk check on the destination first. Only two routes need Estonia's regulator to sign off: group-wide internal rules where the parent company is in Estonia, and a one-off contract you wrote yourself.High confidence
- Who enforces this — and are they actually working?
- The Data Protection Inspectorate, and it is genuinely working. It has 34 posts, a director general in her second term since May 2024, and it publishes its orders. In 2025 it took in 1,568 complaints, issued 13 orders and imposed 5 penalties. But note the shape of the risk: Estonian data protection penalties are handled like minor criminal charges, so they are slow and small, and no Estonian fine has ever approached the European ceilings. Cyber rules are enforced separately by the Information System Authority, which also publishes orders — the most recent on 5 June 2026.High confidence
- How long must I keep it, and when must I delete it?
- Estonia has some of the longest minimum keep-times in Europe. Health records must be kept for 30 years. Anti-money-laundering paperwork for 5 years after the customer leaves. Phone and internet connection records for 1 year, and the police request logs behind them for 5 years. Gambling records for 5 years. Going the other way, a dead person's data stays protected for 10 years after death, or 20 years if they died as a child, and a missed payment may only be reported to credit agencies between 30 days and 5 years after it happened.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. If personal data leaks, you have 72 hours to tell the Data Protection Inspectorate, and you must tell the affected people without delay if the risk to them is high. If you run an important or essential service, you have only 24 HOURS to send a first cyber-incident warning to the Information System Authority, then 72 hours for a fuller report, then one month for a final report. Trust service providers such as e-signature and certificate companies must send the fuller report inside 24 hours too. Missing the cyber deadline is punished separately from missing the privacy one.High confidence
- What's the trap?
- Six things that are not in the summary. (1) A child in Estonia is anyone under 13 for online services, not 16 as in much of Europe, so a consent flow tuned to Germany will over-block Estonian teenagers. (2) A dead person's data stays protected for 10 years after death, 20 if they died as a child, and the heirs control it. (3) Research on Estonians must be stripped of names BEFORE the data are handed over, an ethics committee must sign off sensitive projects, and you must name the individual who holds the key. (4) Data protection fines are handled like minor criminal charges, which makes them small but also drags a named human being into the process. (5) Since 1 January 2025 the regulator itself can sue you in court on behalf of a whole group of affected people. (6) Under the cyber law a named board member is personally responsible for security and must attend training.High confidence
- What's about to change?
- One near-term date stands out. Estonia's official gazette marks its own current texts of the privacy, public information, cybersecurity, telecoms, emergency, health services, health insurance and social welfare acts as valid only until 30 September 2026, so a further change starts on 1 October 2026. We could not identify the amending law, so treat that date as a hard diary entry. Beyond it, the cyber rules phase in: registration was due by 1 April 2026 and full compliance is due by 1 January 2029. From 12 January 2027 European rules make cloud switching and data export charges free.Medium confidence
- Hardest industry wall
- Telecoms — Elektroonilise side seadus (ESS), § 111-1
LuxembourgChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- For most businesses, data can leave Luxembourg on the same terms as anywhere else in the European Union: you need the right paperwork, not a local data centre. Finance is the exception, and finance is most of the economy here. Banks and insurers are bound by a secrecy duty that is a crime to break, and a bank that runs its accounts abroad must still keep a daily backup inside Europe.
- The catch
- The relaxed general answer stops the moment you touch banking, insurance or investment funds. There, three things bite: breaking client secrecy is a criminal offence, not a fine; you may only send client information to a supplier abroad if the client has accepted the outsourcing, the type of information and the country the supplier sits in; and if a bank's accounting system is hosted outside Luxembourg it must still hold a full end-of-day backup on premises inside the European Economic Area. Telecoms firms face a separate 6-month duty to keep call and location records.
- Does this apply to me?
- Yes. If you sell to people in Luxembourg or watch what they do online, the European privacy rules reach you even with no office here. There is no revenue or headcount threshold to hide under. A company with no base anywhere in Europe must appoint a representative in Europe, though it does not have to be in Luxembourg. The extra Luxembourg-only duties in the national law mostly apply to organisations that are actually set up here.High confidence
- Can the data leave the country?
- In general, yes, with paperwork. Luxembourg has no national law telling ordinary companies to keep data in the country, and European law actually forbids member states from forcing non-personal data to stay put except on public-security grounds. But this is a banking and fund centre, and the finance rules change the answer. A bank or insurer may only hand client information to a supplier abroad if the client has been told and has accepted which country that supplier is in. And a bank whose accounting system sits outside Luxembourg must still keep a full daily backup somewhere inside the European Economic Area.High confidence
- What do I have to do to send it abroad?
- The model is a European approved-list. Sending personal data outside Europe is barred unless the destination is on the European Commission's approved list, or you put an approved safeguard in place first. The list is real and populated. Luxembourg adds no national permit and the regulator does not pre-approve ordinary transfers. In finance, though, you also need the client's acceptance of the destination country before their information moves.High confidence
- Who enforces this — and are they actually working?
- Yes, the regulators here really work. The privacy regulator is the National Commission for Data Protection, known as the CNPD. It is staffed, it publishes decisions, and in 2025 it handled 846 complaints, 425 breach reports and 59 investigations. It issued the largest privacy fine ever recorded in Europe, against Amazon in 2021. The financial regulator and the insurance regulator are heavyweight supervisors in their own right, and since May 2026 the telecoms regulator also runs the national cybersecurity regime.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling, and they collide often. You must keep anti-money-laundering records for 5 years after the relationship ends, patient files for at least 10 years after care ends, and telephone and internet connection records for 6 months. In the other direction, European privacy law says delete personal data once you no longer need it, and the anti-money-laundering law says delete it when the 5 years are up unless another law makes you keep it longer. That last sentence is how Luxembourg resolves the clash: the longest specific legal duty wins, and after that you must actually erase.High confidence
- What happens when something goes wrong?
- Count four clocks, because they overlap and they start at different moments. Privacy breach: 72 hours to tell the privacy regulator. Telephone and internet providers: 24 hours to report a personal data breach. Cybersecurity incidents at important companies: an early warning in 24 hours, a fuller report in 72 hours, and a final report a month later. Banks and insurers have their own European reporting on top. The trap is that one incident can start all of them at once, on different teams, with different forms.High confidence
- What's the trap?
- Five things that are not in any summary. (1) Breaking bank or insurance client secrecy is a crime, not a fine, and it survives the end of the job. (2) Your works council can freeze an employee-monitoring project: staff have 15 days to ask the privacy regulator for an opinion, and that request suspends the project for a month. (3) Research projects carry a fixed list of 12 extra safeguards you must apply or justify skipping. (4) Using genetic data for employment or insurance purposes is banned outright. (5) The privacy regulator cannot fine the State or a commune, so a public body has far less to lose than you do.High confidence
- What's about to change?
- Two dated changes and several switches already in someone's hand. The dated ones: from 12 January 2027 cloud providers must let customers move away with no exit or transfer fees at all, and Luxembourg's new cybersecurity law, in force since 10 May 2026, is still being filled in with guidance and templates. The switches to watch: the European approval of United States transfers is under formal challenge, and the 6-month duty on telecoms firms to keep call records sits uneasily with European court rulings and could be struck at any time.Medium confidence
- Hardest industry wall
- Finance — Circulaire CSSF 22/806 relative aux arrangements d'externalisation, telle que modifiee par la circulaire CSSF 25/883