Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
EthiopiaChecked 18 August 2026
A copy must stayWork: HighEnforcement: Dormant
In one paragraph
Ethiopia's privacy law says personal data collected in the country must be kept on a server or in a data centre inside Ethiopia. A copy may go abroad, but usually only if the regulator first accepts that the destination protects data well enough. The law has been in force since July 2024. Almost nothing is being enforced: the regulator has published no rules and runs no register.
The catch
This is a national rule, so no industry escapes it, and two industries are tighter still. Mobile operators must copy every subscriber's identity record to a national registry held on the regulator's own premises. Anyone hosting data commercially in Ethiopia needs a data centre or hosting licence from the same regulator. And sending personal data out of Ethiopia in breach of the law is a crime carrying five to ten years in prison, not a fine you can budget for.
Does this apply to me?
Only partly, and this is Ethiopia's oddest feature. The law covers any organisation set up in Ethiopia. A foreign company with no office is covered only if it uses equipment inside Ethiopia to process the data and has a representative based in Ethiopia. There is no size or revenue threshold. Read literally, a purely foreign online service with no kit and no representative in the country falls outside the law.High confidence
Can the data leave the country?
A copy must stay in the country. Every organisation must keep personal data collected or obtained in Ethiopia on a server or in a data centre located in Ethiopia. A copy may then go abroad, but only in the situations the law allows. Data the law treats as sensitive needs the regulator's permission before it goes anywhere, and that category is wide: health, biometrics, race, religion, political views, criminal records, and the content and details of people's messages.High confidence
What do I have to do to send it abroad?
You need the regulator to bless the destination first. Before personal data leaves Ethiopia you must give the regulator evidence that the receiving country protects data properly, and the regulator must decide that it does. If it does not, the transfer is banned unless you fall into a narrow exception: the person's explicit and informed consent, or the transfer is genuinely necessary for a contract, a legal claim, an important public interest or to save a life. Nothing you sign with the recipient replaces that.High confidence
Who enforces this — and are they actually working?
The Ethiopian Communications Authority, the telecoms regulator, was handed the job. On its own website it says it registers and supervises data controllers, investigates complaints and issues directives. In practice we could find none of that happening. Two years after the law started, it has published no data protection directive, offers no way to register, and has announced no decisions or fines. The telecoms side of the same regulator is busy and effective, so this is a choice about priorities rather than an empty building.High confidence
How long must I keep it, and when must I delete it?
The ceiling is clear, the floor mostly is not. Once the reason for holding personal data has gone, you must destroy it as soon as you reasonably can, and in a way that stops anyone rebuilding it. The clearest minimum we could confirm is in telecoms: when a mobile line is switched off, the operator keeps that subscriber's records for three months. Ethiopia is also unusual in that a person's privacy rights survive them, and last for ten years after death.Medium confidence
What happens when something goes wrong?
Count three clocks, soon to be four. Within 72 hours of learning of a personal data breach you must tell the regulator, and within 72 hours you must also tell the people affected — Ethiopia puts a hard deadline on telling individuals, where most countries only say 'promptly'. Banks have a separate two working day deadline to the central bank for serious technology incidents. From July 2027, organisations in twelve critical sectors get a 48 hour deadline to the national cyber emergency team. Failing to report a breach at all is a crime.High confidence
What's the trap?
Five things that will ruin someone's week. First, you must be registered with the regulator before you process any personal data at all — but the regulator offers no way to register, so the duty cannot be met. Second, a child here is anyone under sixteen, not thirteen. Third, breaking the export rules is a crime punishable by five to ten years in prison, and prison does not need the missing fine regulation to work. Fourth, the content and details of people's messages count as sensitive data, so exporting communications records needs prior permission. Fifth, the servers, firewalls and security modules you would need to store data locally are on a government control list and need a security clearance permit before you can import or use them.High confidence
What's about to change?
One dated change and several switches that could flip without warning. The dated one: the Critical Infrastructure Cybersecurity Proclamation was published on 21 July 2026 and takes effect on 21 July 2027, giving twelve sectors — including finance, health, energy, transport and government services — eighteen security duties, a 48 hour incident deadline, and a licensing regime for anyone selling cybersecurity products or services into Ethiopia. The switches: the government has not yet issued the regulation that sets privacy fines, the regulator has issued no directives, and it can at any time name categories of data that may never leave the country.High confidence
Hardest industry wall
  • All industries የግል ዳታ ጥበቃ አዋጅ ቁጥር ፩ሺ፫፻፳፩/፪ሺ፲፮ — Personal Data Protection Proclamation No. 1321/2024
  • Telecoms SIM Card Registration Directive No. 799/2021
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
The catch
The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
Does this apply to me?
Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
Can the data leave the country?
Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
What do I have to do to send it abroad?
The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
Who enforces this — and are they actually working?
The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
What happens when something goes wrong?
There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
What's the trap?
Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
What's about to change?
Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
Hardest industry wall
  • Telecoms Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
  • E-commerce Loi n° 18-05 relative au commerce electronique
  • Government Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees