Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
SpainChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
- In one paragraph
- Spain follows the normal European rule: personal data may leave the country once you have the right paperwork in place. But four named categories of data held by the Spanish state must physically stay inside the European Union, and may only travel further to a country Europe has officially approved. Spain's privacy regulator is one of the busiest in the world.
- The catch
- The relaxed headline stops being true the moment you touch the electoral roll, town-hall population registers, Spanish tax records or data about users of the Spanish national health service. For those four things a standard European transfer contract is not enough and never will be — the law allows only officially approved destinations. Online gambling, telecoms and any system sold to the Spanish public sector carry their own separate rules.
- Does this apply to me?
- Yes. A company with no office in Spain is still caught if it offers goods or services to people in Spain or watches what they do online. There is no size or revenue threshold to hide under. If you have no base anywhere in Europe you must appoint a written representative inside Europe, and Spain's regulator will happily deal with that representative instead of you.High confidence
- Can the data leave the country?
- For most businesses, yes, with paperwork — the ordinary European rules apply and nothing in Spanish law says data must sit on Spanish soil. The exception is sharp. If the data is the electoral roll, a town-hall population register, Spanish tax records, or information about users of the Spanish national health service, the computers holding it must be inside the European Union, and that data may only go outside Europe to a country Europe has officially approved. A standard European transfer contract does not work for those four things.High confidence
- What do I have to do to send it abroad?
- The model is an approved-list one, run at European level, not by Spain. You may send data outside Europe if the destination country is on Europe's approved list, or if you sign Europe's standard contract, or if your corporate group has approved internal rules. The list is real and populated. Spain adds one twist: if you want to use a home-made contract instead of the standard one, you must get written permission from the Spanish regulator first.High confidence
- Who enforces this — and are they actually working?
- The Spanish Data Protection Agency, and it is very much awake. Its public decision database held 46,925 decisions when we checked on 18 August 2026, with rulings signed as recently as 12 August 2026. Three regional authorities also enforce, covering public bodies in Catalonia, the Basque Country and Andalusia. Spain's artificial intelligence supervisor is now operating too and met the privacy agency in July 2026 to divide up the work.High confidence
- How long must I keep it, and when must I delete it?
- Both directions, and they collide. The longest floor is money laundering records: ten years, and the same law then orders you to destroy them. Business books run six years, clinical records at least five years from the end of each course of treatment, phone and internet connection records twelve months, and the taxman can come back four years. In the other direction Spain does something unusual: when someone asks you to delete their data you must not actually delete it, you must lock it away.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. Everyone has 72 hours to tell the privacy regulator about a personal data breach. Phone and internet providers have only 24 hours under a separate European rule. And if you run something the state treats as an essential service, the cyber clock says report immediately, then send an update within 24 to 48 hours if the incident is critical, or 72 hours if it is very serious, with a final report 20 or 40 days later.High confidence
- What's the trap?
- Five things that ruin weekends. One: a child can consent at fourteen in Spain, not sixteen, so your global age gate is probably wrong here. Two: 'delete my data' legally means 'lock my data away', so a hard-delete pipeline breaks the law. Three: Spain forces far more organisations to appoint a data protection officer than Europe does, including every school, university, bank, insurer, energy supplier and online gambling operator. Four: misusing someone's personal records is a crime punishable by prison, and companies themselves can be prosecuted. Five: telecoms operators can be ordered to hand over the encryption method they use.High confidence
- What's about to change?
- The biggest thing is what has not happened. Spain still has not passed the law that brings Europe's new cybersecurity rules into Spanish law, so the old 2018 regime is still what binds — expect that to change and to widen sharply who must report incidents. From 12 January 2027 no cloud provider may charge you to leave or to pull your data out. Watch three switches the government can flip with no consultation: taking over telecoms networks, ordering gambling systems into Spain, and demanding an operator's encryption method.Medium confidence
- Hardest industry wall
- None found.
Saudi ArabiaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Saudi Arabia, but never for free. You need a purpose the law allows, a written safeguard such as the government's own standard contract, and a written risk assessment that asks whether the transfer could harm the Kingdom itself. Banks need the central bank's written permission before anything goes abroad. The privacy regulator is fully set up but publishes no fines.
- The catch
- The 'paperwork and you can send it' answer is true for an ordinary business. It is false for banks and finance companies, where the central bank must give written no-objection first and cloud is expected to sit inside the country. It is also unsettled for government bodies and critical national infrastructure: the old rule forcing them to host inside Saudi Arabia was deleted in 2024 and replaced by a duty to ask a government office for a decision, and that office has published no replacement rule.
- Does this apply to me?
- Yes. The law reaches a company anywhere in the world with no office in Saudi Arabia, as long as it handles the data of people living in the Kingdom. There is no size, revenue or headcount threshold to fall below. There is no general duty to appoint a local representative, but many organisations must register on the government's data platform and some must name a data protection officer.High confidence
- Can the data leave the country?
- Yes, with real paperwork. First the reason for sending it has to be on the government's short list of allowed purposes. Then you need a safeguard: the government's own standard contract, approved group-wide rules, or a certificate from a licensed body. Then you must write a risk assessment that includes whether the transfer could damage the Kingdom's vital interests. Two industries are much harder. Banks and finance companies must get the central bank's written no-objection before any data goes to an overseas supplier, and the central bank's rules say cloud services should sit inside Saudi Arabia unless it approves otherwise. For government bodies and critical national infrastructure the picture changed in 2024 and is now genuinely unclear.High confidence
- What do I have to do to send it abroad?
- The model is an approved-destination list, and the list is empty. The law says data may go to a country the regulator has judged good enough, but no such list has been published, so in practice nobody uses that route. Instead almost everyone relies on the escape hatches: sign the government's word-for-word standard contract, or get approved group-wide rules for a multinational, or send to a body holding a certificate from a licensed Saudi accreditation body. On top of that you must run a written risk assessment before the data moves.High confidence
- Who enforces this — and are they actually working?
- The Saudi Data and Artificial Intelligence Authority is the privacy regulator, and it is genuinely up and running. Its National Data Governance Platform is live and takes registrations, self-assessments, breach reports and complaints, and it has published the rulebook for the panels that hear violations and issue fines. What we could not find is a single published fine or named decision, so how hard it bites is still unknown. The financial regulator and the cybersecurity authority, by contrast, have supervised their sectors for years.Medium confidence
- How long must I keep it, and when must I delete it?
- Both directions apply, and the floor wins when they clash. The ceiling: you must destroy personal data without undue delay once the reason you collected it has gone, and also when someone asks, when they withdraw the only consent you relied on, or when you learn you processed it unlawfully. Destruction must reach backups too. The floor: your written record of processing activities must be kept for five years after the activity ends. If another law sets a keeping period, the law says keep the data until whichever is longer.High confidence
- What happens when something goes wrong?
- The main clock is 72 hours. If personal data is breached, lost or accessed unlawfully and that could harm the people involved, you must tell the privacy regulator within 72 hours of finding out, through the government's data platform — and you have to be registered on that platform before you can use the service. You must also tell the affected people without undue delay, in plain language. A second, separate clock runs for government bodies and critical national infrastructure, which owe cyber incident reports to the national cybersecurity authority under its own rules. Suppliers owe you notice without undue delay so you can meet your own deadline.High confidence
- What's the trap?
- Five things that are not in the summary. One: sending data abroad is not only about protecting the individual — you must also assess whether the transfer could harm the Kingdom's own vital interests, and there is a government guide telling you how. Two: the standard contract must be copied word for word, and changing it is itself a breach of the law, while the overseas recipient has to accept Saudi courts. Three: leaking or publishing sensitive data to hurt someone or to profit can put a person in prison for up to two years — this is a criminal charge, not a fine. Four: your supplier contract must go beyond a normal data processing agreement and say whether the supplier is subject to foreign laws and how that affects its compliance. Five: the widely quoted rule that all government and critical infrastructure data must be hosted inside Saudi Arabia was deleted in 2024, and quoting it today is wrong.High confidence
- What's about to change?
- Nothing is scheduled to commence on a fixed date in the next twelve months — the law and all its main regulations are already fully in force. The risk is the opposite kind: several switches the government already holds and can flip with no consultation. The biggest is the approved-country list, which the regulator is legally required to publish and has not; the day it appears, every transfer plan in the country needs rechecking. The second biggest is the missing localisation rule for government and critical infrastructure, which one office was handed in 2024 and has not yet written.Medium confidence
- Hardest industry wall
- None found.