Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
GeorgiaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Georgia copied the European model in 2023: data can leave the country, but only to a destination the supervisor has approved, or with a permit, or under a narrow exception. There is no general rule forcing data to stay. The big change is who is in charge — on 2 March 2026 the independent privacy watchdog was replaced by the State Audit Office, and we could not verify that it has issued a single decision since.
The catch
Two things break the calm headline. Telephone and internet connection records are copied into a state-held database inside Georgia, so telecoms cannot treat that data as ordinary business data. And the same State Audit Office that now polices privacy also runs the public register of foreign-funded organisations.
Does this apply to me?
Yes. The law catches a company with no office in Georgia if it uses technical means located in Georgia to handle people's data. There is no revenue or headcount threshold to duck under. Worse, a foreign company in that position must appoint a representative in Georgia and register that person with the supervisor BEFORE it starts processing — the only escape is being based in the European Union or in a country the European Union has already approved.High confidence
Can the data leave the country?
Yes, with paperwork. Data may go abroad if the destination country has been judged to give good enough protection, or if the supervisor grants a permit for the contract you have signed, or under a short list of narrow exceptions such as the person's written consent after being told the risks. Nothing in the general law forces data to stay in Georgia. The one place data really does stay is telecoms: a copy of who called whom, and when, sits in a state-run database inside the country.High confidence
What do I have to do to send it abroad?
The model is an approved-destinations list, with a permit as the back-up. The supervisor decides which countries offer good enough protection and publishes that decision as a formal act; if your destination is not on it, you need a permit for your contract, or you fall back on a narrow exception such as written consent. We could not find the current published list, so we cannot tell you today which countries are on it — treat that as the single biggest open question in this record.Medium confidence
Who enforces this — and are they actually working?
This is where Georgia surprises people. Until 1 March 2026 the job belonged to the Personal Data Protection Service, an independent watchdog. From 2 March 2026 the law hands the same job to the State Audit Office — the body that audits government spending — and its head, the Auditor General, now signs the privacy rules. We can prove the handover happened, because the Auditor General reissued two of the privacy rulebooks at the end of March 2026. We could not find a single enforcement decision published since the handover.Medium confidence
How long must I keep it, and when must I delete it?
The ceiling is clear: keep personal data only as long as you need it for the purpose you collected it for, then erase, destroy or strip out the identifying parts, unless another law tells you to keep it. The floors are scattered across tax, accounting and sector laws that we could not open on an official site today. In telecoms the direction is reversed — the content of a call or message must be destroyed at once, while the record of who contacted whom can be copied into a state database and kept for a period set by a separate law.Medium confidence
What happens when something goes wrong?
Two clocks. If personal data is lost, leaked or wrongly handled, you have 72 hours from spotting it to tell the supervisor, and you must keep your own record of the incident and what you did about it. If you run a system the government has listed as critical to the country, you must tell the national computer emergency response team immediately — no fixed number of hours, which in practice means the same day. If both apply to you, both run at once.High confidence
What's the trap?
Five. First, the regulator changed identity on 2 March 2026, so a privacy notice or contract naming the Personal Data Protection Service now points at a body the law no longer mentions. Second, a foreign company must register a representative in Georgia before it starts, not after. Third, a child is anyone under 16, so a European sign-up flow tuned to 13 will be wrong here. Fourth, direct marketing always needs consent, even if you bought the list lawfully. Fifth, the same State Audit Office that now polices privacy also runs the public register of foreign-funded organisations, which must publish detailed information about themselves.Medium confidence
What's about to change?
Nothing new is scheduled to start in the privacy law itself — we checked the current text on 18 August 2026 and found no provisions waiting on a future date. The live story is the handover: the Auditor General is reissuing the four rulebooks inherited from the old watchdog, and two of the four were reissued in March 2026. The rest of the risk sits in switches the government can already flip without a new law.Medium confidence
Hardest industry wall
  • Telecoms საქართველოს კანონი ელექტრონული კომუნიკაციების შესახებ
ItalyChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
In one paragraph
Italy does not make ordinary business data stay in Italy. European rules decide when data may leave Europe, and Italy layers its own rules on top. But the moment you sell to the Italian state — a ministry, a town hall, a hospital, a school — the picture changes completely. The most sensitive government data has to sit on machines inside Italy, run from Italy.
The catch
"Italy has no data localisation" holds right up until your customer is a public body. Italian government data is sorted into ordinary, critical and strategic. Strategic data belongs on Italian soil under Italian operational control; critical data may not go on a public cloud outside Europe. On top of that, a cloud provider needs a licence from the national cyber agency before any public body is allowed to buy from it at all. Separately, telecoms companies must keep call and connection records for years, and the government can attach storage-location conditions to fifth-generation mobile and cloud contracts case by case.
Does this apply to me?
Yes, it reaches you with no office in Italy. European law applies to any organisation anywhere that offers goods or services to people in Italy, or that monitors what they do online. There is no size or revenue threshold to duck under. If you have no branch anywhere in Europe, you must appoint a written representative based in Europe, and people and regulators can go to that representative instead of chasing you abroad.High confidence
Can the data leave the country?
For a normal private company, yes — with paperwork, exactly as anywhere else in Europe. Italy has no general law saying personal data must be stored in Italy. The real walls are in one place: anything sold to or run by the Italian public sector. Government data is graded ordinary, critical or strategic, and the top two grades cannot sit on a public cloud outside Europe, with strategic data confined to infrastructure inside Italy and operated from Italy.High confidence
What do I have to do to send it abroad?
Three routes, and they are European rather than Italian. Best case, the destination is on Europe's official approved list and you need nothing extra. Otherwise you sign Europe's standard contract with the recipient, or get group-wide internal rules approved by a regulator. With the last two you must also write down an assessment of whether the destination country's surveillance laws would undermine the protection. Italy adds no extra permission step, but it does add a criminal offence for getting it badly wrong.High confidence
Who enforces this — and are they actually working?
The Italian data protection authority, known as the Garante, and it is one of the busiest and boldest regulators in Europe. In 2025 alone it took 807 decisions, of which 506 were corrective or punitive, ran 130 inspections and collected more than 37 million euros (about 41 million dollars) in fines. It was the first regulator in the world to order a temporary halt to a major chatbot service, and it has since blocked or restricted several artificial intelligence products. Cybersecurity is enforced by a separate agency.High confidence
How long must I keep it, and when must I delete it?
Both directions, and they pull hard against each other. The floors: telephone records must be kept 24 months, internet connection records 12 months, unanswered calls 30 days, and a separate six-year rule applies for terrorism and serious crime. Health records in the national system are erased 30 years after the patient dies. The ceiling is much tighter than people expect: the regulator says the technical logs behind staff email may normally be kept for no more than 21 days.High confidence
What happens when something goes wrong?
Count at least three clocks, and they run at the same time. A personal data breach goes to the Garante within 72 hours, and to the people affected without delay where the risk to them is high. If you are in scope of Italy's network security regime, a first warning goes to the national cyber agency within 24 hours, a fuller notification within 72 hours, and a final report within a month. Organisations inside the national cyber perimeter have a much shorter fuse, reported as six hours.Medium confidence
What's the trap?
Five. One: staff email logs may normally be kept only 21 days, and a regional government was punished in 2025 for keeping 90. Two: before you install any tool that could monitor employees, you need a union agreement or a labour inspectorate permit, and skipping it is a criminal matter, not a fine. Three: some data offences in Italy carry prison, not just penalties. Four: children can consent at 14 in Italy, not 16. Five: the widely reported rule forcing public-sector artificial intelligence onto Italian servers was deleted before the law passed, so citing it is wrong.High confidence
What's about to change?
Two firm dates and one open wound. By 31 October 2026 organisations in Italy's network security regime must have their basic security measures in place and evidenced. From 12 January 2027 every cloud provider must charge nothing for switching away or pulling data out. The open wound is the Italian regulator itself: one of four board seats has been empty since January 2026 and Parliament has not filled it.Medium confidence
Hardest industry wall
  • Government Regolamento unico per le infrastrutture e i servizi cloud per la PA — Determinazione ACN n. 21007/24