Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
GeorgiaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Georgia copied the European model in 2023: data can leave the country, but only to a destination the supervisor has approved, or with a permit, or under a narrow exception. There is no general rule forcing data to stay. The big change is who is in charge — on 2 March 2026 the independent privacy watchdog was replaced by the State Audit Office, and we could not verify that it has issued a single decision since.
The catch
Two things break the calm headline. Telephone and internet connection records are copied into a state-held database inside Georgia, so telecoms cannot treat that data as ordinary business data. And the same State Audit Office that now polices privacy also runs the public register of foreign-funded organisations.
Does this apply to me?
Yes. The law catches a company with no office in Georgia if it uses technical means located in Georgia to handle people's data. There is no revenue or headcount threshold to duck under. Worse, a foreign company in that position must appoint a representative in Georgia and register that person with the supervisor BEFORE it starts processing — the only escape is being based in the European Union or in a country the European Union has already approved.High confidence
Can the data leave the country?
Yes, with paperwork. Data may go abroad if the destination country has been judged to give good enough protection, or if the supervisor grants a permit for the contract you have signed, or under a short list of narrow exceptions such as the person's written consent after being told the risks. Nothing in the general law forces data to stay in Georgia. The one place data really does stay is telecoms: a copy of who called whom, and when, sits in a state-run database inside the country.High confidence
What do I have to do to send it abroad?
The model is an approved-destinations list, with a permit as the back-up. The supervisor decides which countries offer good enough protection and publishes that decision as a formal act; if your destination is not on it, you need a permit for your contract, or you fall back on a narrow exception such as written consent. We could not find the current published list, so we cannot tell you today which countries are on it — treat that as the single biggest open question in this record.Medium confidence
Who enforces this — and are they actually working?
This is where Georgia surprises people. Until 1 March 2026 the job belonged to the Personal Data Protection Service, an independent watchdog. From 2 March 2026 the law hands the same job to the State Audit Office — the body that audits government spending — and its head, the Auditor General, now signs the privacy rules. We can prove the handover happened, because the Auditor General reissued two of the privacy rulebooks at the end of March 2026. We could not find a single enforcement decision published since the handover.Medium confidence
How long must I keep it, and when must I delete it?
The ceiling is clear: keep personal data only as long as you need it for the purpose you collected it for, then erase, destroy or strip out the identifying parts, unless another law tells you to keep it. The floors are scattered across tax, accounting and sector laws that we could not open on an official site today. In telecoms the direction is reversed — the content of a call or message must be destroyed at once, while the record of who contacted whom can be copied into a state database and kept for a period set by a separate law.Medium confidence
What happens when something goes wrong?
Two clocks. If personal data is lost, leaked or wrongly handled, you have 72 hours from spotting it to tell the supervisor, and you must keep your own record of the incident and what you did about it. If you run a system the government has listed as critical to the country, you must tell the national computer emergency response team immediately — no fixed number of hours, which in practice means the same day. If both apply to you, both run at once.High confidence
What's the trap?
Five. First, the regulator changed identity on 2 March 2026, so a privacy notice or contract naming the Personal Data Protection Service now points at a body the law no longer mentions. Second, a foreign company must register a representative in Georgia before it starts, not after. Third, a child is anyone under 16, so a European sign-up flow tuned to 13 will be wrong here. Fourth, direct marketing always needs consent, even if you bought the list lawfully. Fifth, the same State Audit Office that now polices privacy also runs the public register of foreign-funded organisations, which must publish detailed information about themselves.Medium confidence
What's about to change?
Nothing new is scheduled to start in the privacy law itself — we checked the current text on 18 August 2026 and found no provisions waiting on a future date. The live story is the handover: the Auditor General is reissuing the four rulebooks inherited from the old watchdog, and two of the four were reissued in March 2026. The rest of the risk sits in switches the government can already flip without a new law.Medium confidence
Hardest industry wall
  • Telecoms საქართველოს კანონი ელექტრონული კომუნიკაციების შესახებ
FranceChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
In one paragraph
France follows the European rule: data may leave, but only once the right paperwork is in place. France then adds hard walls of its own. Health records must be stored inside Europe. Online gambling records must sit on a machine in mainland France. From 1 September 2026 the invoicing platform every French business must use has to run entirely from inside Europe.
The catch
"France has no local storage rule" is true for an ordinary business and false the moment you touch health data, online gambling, electronic invoicing or a government contract involving sensitive state data. In those four areas France is among the strictest countries in Europe. Since March 2026 the health rule sits in a decree, not just a certification standard, so it now binds the customer as well as the supplier.
Does this apply to me?
Yes. France reaches a company with no office in the country. European law already applies to anyone offering goods or services to people in Europe. On top of that, France's own privacy law says its national rules apply as soon as the person concerned lives in France, even when the company is based somewhere else. There is no size or revenue threshold that lets you escape.High confidence
Can the data leave the country?
For an ordinary business, yes, with paperwork: the European transfer rules apply and nothing extra is added. But four French sectors override that. Health records must be stored inside Europe and nowhere else. Online gambling records must be archived in real time on hardware in mainland France. Electronic invoicing platforms must run their whole system from inside Europe. And sensitive state data must sit on a cloud that the French cyber agency has certified as beyond the reach of foreign authorities.High confidence
What do I have to do to send it abroad?
The model is an approved-list one, run from Brussels rather than Paris. Data may go to a country the European Commission has formally approved, or anywhere else if you sign the official standard contract and write down why you think the data will still be safe. The list of approved countries is full, not empty: it includes the United Kingdom, Japan, South Korea, Canada, Switzerland, Brazil and about a dozen others, plus American companies that have signed up to the transatlantic framework. France adds no separate national approval step.High confidence
Who enforces this — and are they actually working?
The privacy regulator is the CNIL, and it is one of the busiest in Europe. In 2025 alone it issued 83 penalties totalling about 487 million euros (roughly 530 million dollars), plus 143 formal warnings. It is still fining in 2026: 5 million euros against the national employment agency in January and 5 million against a health data company in May. Separate regulators run the sector walls, and all of them are staffed and working.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling and they pull in opposite directions. You must keep accounting books and supporting documents for ten years, tax records for six, employment contracts and pay records for five, and telephone and internet subscriber identity data for five. In the other direction, European law says you must delete personal data once you no longer need it. France resolves the clash the same way most of Europe does: the legal minimum wins, but only for the specific documents the law names, and only for as long as it names.High confidence
What happens when something goes wrong?
Count the clocks, because France has at least four and they run at different speeds. Every organisation has 72 hours to tell the CNIL about a personal data breach. Telephone and internet providers have only 24 hours. Hospitals and clinics must report a serious computer security incident to their regional health agency immediately. Banks, insurers and investment firms have their own European deadlines: an initial report within 4 hours of classifying a major incident and no later than 24 hours after they notice it.High confidence
What's the trap?
Five things that are not in the summary. (1) Breaking the privacy law in France is a crime, not just a fine: sending data out of Europe unlawfully carries up to five years in prison and a 300,000 euro fine (about 330,000 dollars), and it attaches to people, not only companies. (2) A child is anyone under 15 for consent, not 13 or 16. (3) A 2023 law setting a social media age of 15 is printed in the statute book but has never come into force and cannot be enforced. (4) Handing documents to a foreign court or regulator can itself be a criminal offence in France. (5) Cookies are policed separately from the rest of privacy law, so a foreign company cannot hide behind its lead European regulator.High confidence
What's about to change?
Four dates in the next twelve months. 1 September 2026: every French business must be able to send and receive invoices through an approved platform, and those platforms must run entirely from inside Europe. Around 27 September 2026: the second phase of the health data hosting decree starts. 21 October 2026: the order forcing telephone and internet companies to keep everyone's connection records for a year expires unless the Prime Minister renews it. 12 January 2027: cloud providers across Europe must drop switching and data export fees to zero.Medium confidence
Hardest industry wall
  • Health and social care Decret n° 2026-209 du 24 mars 2026 portant modification de certaines dispositions du code de la sante publique relatives a l'hebergement de donnees de sante a caractere personnel
  • Government Decret n° 2026-272 du 14 avril 2026 relatif a la protection des donnees d'une sensibilite particuliere des administrations, operateurs et groupements d'interet public de l'Etat traitees par un service d'informatique en nuage fourni par un prestataire prive
  • All industries Immatriculation des plateformes agreees (ex plateformes de dematerialisation partenaires) - facturation electronique
  • Online gaming Article 31 de la loi n° 2010-476 du 12 mai 2010 relative a l'ouverture a la concurrence et a la regulation du secteur des jeux d'argent et de hasard en ligne