Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
EstoniaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Estonia has no general rule forcing data to stay in the country, and it adds very little on top of the European privacy rules. Two industries are the exception. Phone and internet companies must keep connection records inside the European Union, with some records physically in Estonia. Online gambling firms may only run their game server from a short list of approved countries. The regulator works, but its fines are small.
- The catch
- The relaxed headline stops being true the moment you are a telecoms operator, an online gambling operator, a health care provider or a public body. Telecoms connection records may not leave the European Union at all and certain police-request records must sit on Estonian soil. Gambling servers are limited to an approved list of countries. Health records carry a 30-year minimum keep-time. Public bodies must run the Estonian national security standard and exchange data through the state's own data layer.
- Does this apply to me?
- Yes, it reaches you even with no office in Estonia. Estonia does not write its own reach test — it uses the European Union's. If you offer goods or services to people in Estonia, or track what they do online, the European privacy rules apply and Estonia's regulator can act against you. There is no size or revenue threshold to fall below. A company with no branch anywhere in Europe normally has to name a written representative inside Europe.High confidence
- Can the data leave the country?
- In general, yes. Estonia has no law telling companies to keep personal data in Estonia, and European law actually forbids member states from imposing one on non-personal data. Two industries break that headline. Phone and internet companies must keep their call and connection records inside the European Union, and certain police-request records must stay physically in Estonia. Online gambling companies may only place their game server in Estonia, in a country that has signed the cybercrime treaty, or in a country whose regulator has a cooperation deal with the Estonian Tax and Customs Board.High confidence
- What do I have to do to send it abroad?
- For the normal routes you file nothing with the Estonian regulator. If the destination country has been officially approved by the European Commission, you simply send the data. If it has not, you sign the European Commission's standard contract with the recipient and run a risk check on the destination first. Only two routes need Estonia's regulator to sign off: group-wide internal rules where the parent company is in Estonia, and a one-off contract you wrote yourself.High confidence
- Who enforces this — and are they actually working?
- The Data Protection Inspectorate, and it is genuinely working. It has 34 posts, a director general in her second term since May 2024, and it publishes its orders. In 2025 it took in 1,568 complaints, issued 13 orders and imposed 5 penalties. But note the shape of the risk: Estonian data protection penalties are handled like minor criminal charges, so they are slow and small, and no Estonian fine has ever approached the European ceilings. Cyber rules are enforced separately by the Information System Authority, which also publishes orders — the most recent on 5 June 2026.High confidence
- How long must I keep it, and when must I delete it?
- Estonia has some of the longest minimum keep-times in Europe. Health records must be kept for 30 years. Anti-money-laundering paperwork for 5 years after the customer leaves. Phone and internet connection records for 1 year, and the police request logs behind them for 5 years. Gambling records for 5 years. Going the other way, a dead person's data stays protected for 10 years after death, or 20 years if they died as a child, and a missed payment may only be reported to credit agencies between 30 days and 5 years after it happened.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. If personal data leaks, you have 72 hours to tell the Data Protection Inspectorate, and you must tell the affected people without delay if the risk to them is high. If you run an important or essential service, you have only 24 HOURS to send a first cyber-incident warning to the Information System Authority, then 72 hours for a fuller report, then one month for a final report. Trust service providers such as e-signature and certificate companies must send the fuller report inside 24 hours too. Missing the cyber deadline is punished separately from missing the privacy one.High confidence
- What's the trap?
- Six things that are not in the summary. (1) A child in Estonia is anyone under 13 for online services, not 16 as in much of Europe, so a consent flow tuned to Germany will over-block Estonian teenagers. (2) A dead person's data stays protected for 10 years after death, 20 if they died as a child, and the heirs control it. (3) Research on Estonians must be stripped of names BEFORE the data are handed over, an ethics committee must sign off sensitive projects, and you must name the individual who holds the key. (4) Data protection fines are handled like minor criminal charges, which makes them small but also drags a named human being into the process. (5) Since 1 January 2025 the regulator itself can sue you in court on behalf of a whole group of affected people. (6) Under the cyber law a named board member is personally responsible for security and must attend training.High confidence
- What's about to change?
- One near-term date stands out. Estonia's official gazette marks its own current texts of the privacy, public information, cybersecurity, telecoms, emergency, health services, health insurance and social welfare acts as valid only until 30 September 2026, so a further change starts on 1 October 2026. We could not identify the amending law, so treat that date as a hard diary entry. Beyond it, the cyber rules phase in: registration was due by 1 April 2026 and full compliance is due by 1 January 2029. From 12 January 2027 European rules make cloud switching and data export charges free.Medium confidence
- Hardest industry wall
- Telecoms — Elektroonilise side seadus (ESS), § 111-1
SerbiaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Serbia copied Europe's privacy law almost word for word, so the duties feel familiar. Data can leave the country, and for most of Europe and a long list of other countries it can leave with no paperwork at all. The privacy regulator is busy — over a thousand inspections in 2025 — but it hands out warnings, not fines. The biggest fine any Serbian court imposed for a privacy breach in 2025 was about $950.
- The catch
- Two industries break the general picture. Online gambling operators must keep a copy of their whole player and transaction database physically inside Serbia. Banks, insurers and other financial firms cannot move any IT work abroad without telling the central bank 30 days ahead, proving the foreign country would let Serbian supervisors inspect on site, and risking a veto that forces them to cancel the contract.
- Does this apply to me?
- Yes. The law reaches a company anywhere in the world if it offers goods or services to people in Serbia, or watches what they do in Serbia. There is no size or revenue threshold to hide behind. If you are caught this way you must appoint a written representative living or based in Serbia, unless your processing is occasional and low risk or you are a public body.High confidence
- Can the data leave the country?
- Yes, with paperwork — and often with none at all. Serbia treats a very long list of countries as automatically safe: every member of the Council of Europe's data protection treaty, which covers all of Europe plus Argentina, Mexico, Morocco, Mauritius, Senegal, Tunisia, Uruguay, Cape Verde and others, and separately every country the European Union has approved. Sending data there needs no permission and no contract. Everywhere else you sign the Commissioner's standard contract or use approved group rules. Only one industry has a hard wall: online gambling. Banking has a gate rather than a wall.High confidence
- What do I have to do to send it abroad?
- First check the destination. If it is on the safe list, you need nothing — no contract, no filing, no approval. If it is not, you sign the standard contract the Serbian regulator published in January 2020, or you get approved group-wide rules. If you want to use your own wording instead of the standard contract, the regulator must approve it and has 60 days to answer. As a last resort there are narrow exceptions such as the person's explicit consent.High confidence
- Who enforces this — and are they actually working?
- The Commissioner for Information of Public Importance and Personal Data Protection, and it is genuinely working. In 2025 it finished 1,169 inspections, received 5,310 cases and issued 102 corrective orders. But it almost never fines. Of those 102 orders, 101 were warnings and one was a ban on processing. It asked the courts to punish only three organisations all year. Banks answer to the National Bank of Serbia instead, and it is fully active. A brand-new Office for Information Security exists on paper since October 2025 but we could find no sign it is running yet.High confidence
- How long must I keep it, and when must I delete it?
- There is no single national rule. The privacy law says keep data only as long as you need it, and each sector sets its own clock. Online gambling operators must keep every transaction for at least ten years. Phone and internet companies must keep who-called-whom records for exactly 12 months and then destroy them. Anyone selling a phone line must keep the customer's identity check for 12 months after the service ends. Financial firms must keep a live register of every outsourced service, including which countries the data sits in.High confidence
- What happens when something goes wrong?
- Count three clocks. Privacy breach: tell the Commissioner without delay and at the latest within 72 hours, and if you miss that you must explain why. Cyber incident: if you run an information system the state has classed as important, you have only 24 hours to report it. Then a third clock starts — updates every 24 hours for a serious incident, every three days for a middling one, and a final report within 15 days of the incident ending. Banks report cyber incidents to the central bank instead, promptly, with no fixed hour count.High confidence
- What's the trap?
- Five. (1) A child can consent for themselves at 15, not 13 or 16 — plan your age gates around 15. (2) A foreign court order or foreign tax authority demand for data is recognised in Serbia only if a treaty backs it, so handing data to an overseas authority on request can itself be unlawful. (3) Individuals, not just companies, can be prosecuted; the regulator has filed 49 criminal complaints since 2010. (4) Dozens of older Serbian laws still contradict the privacy law and were never fixed. (5) The government's official list of safe destination countries has not been touched since 2019 and still names a United States framework that died in 2020.High confidence
- What's about to change?
- One dated change and several unscheduled ones. From 1 January 2027 the ministry formally takes over supervising the new Office for Information Security, which should mean the office is actually up and running by then. A rewrite of the privacy law is being drafted by a special working group covering video surveillance, biometrics, genetic data and artificial intelligence, and a separate group is drafting an artificial intelligence law. Neither has been published as a bill, so neither is binding.High confidence
- Hardest industry wall
- Online gaming — Pravilnik o informaciono-komunikacionom sistemu za priređivanje posebnih igara na sreću preko sredstava elektronske komunikacije