Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
SpainChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
In one paragraph
Spain follows the normal European rule: personal data may leave the country once you have the right paperwork in place. But four named categories of data held by the Spanish state must physically stay inside the European Union, and may only travel further to a country Europe has officially approved. Spain's privacy regulator is one of the busiest in the world.
The catch
The relaxed headline stops being true the moment you touch the electoral roll, town-hall population registers, Spanish tax records or data about users of the Spanish national health service. For those four things a standard European transfer contract is not enough and never will be — the law allows only officially approved destinations. Online gambling, telecoms and any system sold to the Spanish public sector carry their own separate rules.
Does this apply to me?
Yes. A company with no office in Spain is still caught if it offers goods or services to people in Spain or watches what they do online. There is no size or revenue threshold to hide under. If you have no base anywhere in Europe you must appoint a written representative inside Europe, and Spain's regulator will happily deal with that representative instead of you.High confidence
Can the data leave the country?
For most businesses, yes, with paperwork — the ordinary European rules apply and nothing in Spanish law says data must sit on Spanish soil. The exception is sharp. If the data is the electoral roll, a town-hall population register, Spanish tax records, or information about users of the Spanish national health service, the computers holding it must be inside the European Union, and that data may only go outside Europe to a country Europe has officially approved. A standard European transfer contract does not work for those four things.High confidence
What do I have to do to send it abroad?
The model is an approved-list one, run at European level, not by Spain. You may send data outside Europe if the destination country is on Europe's approved list, or if you sign Europe's standard contract, or if your corporate group has approved internal rules. The list is real and populated. Spain adds one twist: if you want to use a home-made contract instead of the standard one, you must get written permission from the Spanish regulator first.High confidence
Who enforces this — and are they actually working?
The Spanish Data Protection Agency, and it is very much awake. Its public decision database held 46,925 decisions when we checked on 18 August 2026, with rulings signed as recently as 12 August 2026. Three regional authorities also enforce, covering public bodies in Catalonia, the Basque Country and Andalusia. Spain's artificial intelligence supervisor is now operating too and met the privacy agency in July 2026 to divide up the work.High confidence
How long must I keep it, and when must I delete it?
Both directions, and they collide. The longest floor is money laundering records: ten years, and the same law then orders you to destroy them. Business books run six years, clinical records at least five years from the end of each course of treatment, phone and internet connection records twelve months, and the taxman can come back four years. In the other direction Spain does something unusual: when someone asks you to delete their data you must not actually delete it, you must lock it away.High confidence
What happens when something goes wrong?
Count three clocks, not one. Everyone has 72 hours to tell the privacy regulator about a personal data breach. Phone and internet providers have only 24 hours under a separate European rule. And if you run something the state treats as an essential service, the cyber clock says report immediately, then send an update within 24 to 48 hours if the incident is critical, or 72 hours if it is very serious, with a final report 20 or 40 days later.High confidence
What's the trap?
Five things that ruin weekends. One: a child can consent at fourteen in Spain, not sixteen, so your global age gate is probably wrong here. Two: 'delete my data' legally means 'lock my data away', so a hard-delete pipeline breaks the law. Three: Spain forces far more organisations to appoint a data protection officer than Europe does, including every school, university, bank, insurer, energy supplier and online gambling operator. Four: misusing someone's personal records is a crime punishable by prison, and companies themselves can be prosecuted. Five: telecoms operators can be ordered to hand over the encryption method they use.High confidence
What's about to change?
The biggest thing is what has not happened. Spain still has not passed the law that brings Europe's new cybersecurity rules into Spanish law, so the old 2018 regime is still what binds — expect that to change and to widen sharply who must report incidents. From 12 January 2027 no cloud provider may charge you to leave or to pull your data out. Watch three switches the government can flip with no consultation: taking over telecoms networks, ordering gambling systems into Spain, and demanding an operator's encryption method.Medium confidence
Hardest industry wall
None found.
JapanChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Active
In one paragraph
Japan lets personal data leave the country, but you need paperwork. Only Europe and the United Kingdom are pre-approved. For anywhere else you either sign a contract that binds the recipient to Japanese-standard protection, or you get the person's consent after telling them which country the data goes to. There is no general rule forcing data to stay in Japan.
The catch
Two things break the calm headline. If you sell to the Japanese government, the data must physically sit in Japanese data centres. And if you run a website, an app or any online service used from Japan, the telecoms law reaches you even with no office here, requires a representative in Japan, and makes leaking a communication a criminal offence rather than a fine.
Does this apply to me?
Yes. Japan's privacy law reaches a foreign company with no office and no staff in Japan, as long as it handles the personal information of people in Japan while supplying them goods or services. There is no size, revenue or headcount threshold to fall below. Unlike Europe, the privacy law does not make you appoint a representative in Japan — but the telecoms law does, if your service counts as a telecommunications service.High confidence
Can the data leave the country?
Yes, with paperwork. Japan's general rating is conditional: personal data may go abroad once you have one of three things in place. There is no across-the-board law keeping data in Japan, and no financial, insurance, securities or health localisation rule of the kind India or China have — we searched for one and did not find it. The real wall is government work: anything running on the national Government Cloud must sit in data centres inside Japan.High confidence
What do I have to do to send it abroad?
The model is an allowlist, and the list has exactly two entries: the European Union and the United Kingdom. Send data there and it is treated almost like a domestic transfer. For every other destination you need one of two things instead. Either the recipient is contractually bound to protect the data to Japanese standards and you keep checking that it does, or you get the person's consent after first telling them the destination country, what its privacy law is like, and what the recipient will do to protect the data.High confidence
Who enforces this — and are they actually working?
The Personal Information Protection Commission, and it is genuinely working. It has a chair, eight commissioners and a staff ceiling of 231 people. In the year to March 2025 it handled just over 19,000 breach reports, gave 395 pieces of formal guidance and made one recommendation. In the first six months of the following year it sharpened up: two recommendations and its first emergency order, against a company misusing personal information. What it cannot do yet is fine you — Japan has no administrative money penalty for privacy breaches until the 2026 amendment starts.High confidence
How long must I keep it, and when must I delete it?
The floor is firm and the ceiling is soft. Tax law makes you keep books and records for seven years, stretching to ten if you carry a loss forward. Company accounting books run ten years. Against that, the privacy law only asks you to try to delete personal data once you no longer need it — it is a best-efforts duty, not a hard deadline. So when the two collide, the keep-it rule wins in practice.Medium confidence
What happens when something goes wrong?
Count three clocks. For a personal data breach you file a first report to the privacy regulator within three to five days of finding out, and a full report within 30 days — 60 days if someone did it on purpose. You must also tell the people affected. Critical infrastructure operators have a separate cyber incident duty with a report to the government within 30 days. Telecoms operators report leaks of communications to the communications ministry on their own timetable.High confidence
What's the trap?
Five. (1) Putting data on a foreign server is often not a 'transfer' at all — if the provider is contractually barred from touching it — but you then have to work out that country's privacy law and publish the country's name to your users. Most people miss this. (2) The privacy law has no fines: the sanctions are criminal, and a company can be fined about $650,000 for a staff member stealing a customer database. (3) Leaking a communication is a crime punishable with prison, and telecoms staff face a longer term than outsiders. (4) The telecoms rules catch ordinary websites and apps, not just phone companies, and reach foreign operators with no office in Japan. (5) Consent to send data 'overseas' is not valid — you have to name the country.High confidence
What's about to change?
The big one has already passed. On 17 July 2026 Japan published a large amendment to its privacy law. It introduces the country's first money penalty for privacy breaches, sets 16 as the age below which a guardian must be involved, adds rules for face and other biometric data, and raises the criminal penalties. It is not in force yet: the government has up to two years to switch it on by order, and no date has been announced. The other thing to watch is the new cyber defence law, which is being switched on in stages through 2027.High confidence
Hardest industry wall
  • Government デジタル庁におけるガバメントクラウド等の整備のためのクラウドサービスの提供 — 令和8年度募集 調達仕様書