Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
Hong Kong SARChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
In one paragraph
Hong Kong's privacy law contains a cross-border transfer ban that has never been switched on. It was written in 1995 and, thirty years later, still has no start date. So under the general law you can send personal data anywhere with no paperwork at all. The privacy regulator is busy and prosecutes people, but it cannot fine you directly.
The catch
The free-for-all stops at three doors. Licensed securities and futures firms need written permission from the markets regulator before their records live only on servers outside Hong Kong. Government departments are told not to put sensitive or personal information on public cloud at all. And data coming the other way, from mainland China into Hong Kong, is tightly controlled by mainland law, not by Hong Kong law - that is the wall most companies actually hit.
Does this apply to me?
Yes, it can reach you with no office in Hong Kong. The privacy law bites on whoever controls the collection, holding, use or processing of personal data in or from Hong Kong, so a foreign company running a Hong Kong-facing service is caught. There is no revenue or headcount threshold to fall below, no register to join, and no requirement to appoint a local representative. The anti-doxxing powers go further still: the regulator can order an overseas platform to take material down.High confidence
Can the data leave the country?
Under the general privacy law, yes - freely, with nothing to sign. The one section that would have restricted transfers abroad was written into the law in 1995 and has never been brought into operation, so today there is no legal control on personal data leaving Hong Kong. Industry rules are where the real limits sit, and there are fewer of them than people expect: the securities regulator is the main one, and government departments have their own restriction.High confidence
What do I have to do to send it abroad?
Nothing. There is no approval to seek, no standard contract to sign and no government list to check before personal data leaves Hong Kong. The model on paper is an allowlist - the regulator would publish a list of approved destinations - but because the section was never switched on, that list has never been issued and is empty. The regulator does publish a voluntary guide and encourages firms to build the safeguards now, but that is advice, not law.High confidence
Who enforces this — and are they actually working?
The Privacy Commissioner for Personal Data, and it is genuinely busy. By the end of December 2025 it had issued 2,104 orders to 57 online platforms to take down 33,743 doxxing messages, opened 519 criminal investigations and arrested 81 people. But there is a catch that changes the risk picture completely: the Commissioner cannot impose a fine for breaking the privacy principles. It serves a notice telling you to fix the problem, and only ignoring that notice is a crime.High confidence
How long must I keep it, and when must I delete it?
There is a hard ceiling and almost no floor in the privacy law itself. You must erase personal data once it is no longer needed for the purpose you collected it for, and failing to do so is a criminal offence carrying a fine of up to HK$10,000 (about $1,300). The privacy law sets no minimum keeping periods; those come from tax, company and anti-money-laundering law instead. Where the two pull against each other, the specific keeping duty in the other law wins, and you delete once it expires.Medium confidence
What happens when something goes wrong?
For a normal data breach there is no deadline, because there is no duty. Telling the Privacy Commissioner about a breach is voluntary in Hong Kong - the regulator asks you to do it as good practice and gives you a form, but no law compels it. That is unusual and it is changing: since 1 January 2026 operators of designated critical infrastructure must report computer-system security incidents, so those firms now have a real clock while everyone else has none.High confidence
What's the trap?
Five things that catch people out. First, marketing mistakes are crimes here, not fines - using someone's data for direct marketing without the right consent can mean five years in prison. Second, the regulator cannot fine you, so people assume the risk is low and miss the criminal exposure entirely. Third, Hong Kong sets no age at which a child can consent, so there is no simple number to code into a sign-up flow. Fourth, licensed securities firms need written permission before their records live only on overseas servers, and two named people who live in Hong Kong must be able to unlock them. Fifth, the dormant transfer section, if ever switched on, would also catch data moving between two foreign countries when a Hong Kong company controls it.Medium confidence
What's about to change?
Nothing is scheduled to land in the next twelve months that we could confirm. The critical infrastructure security law already started on 1 January 2026, and the government's guideline for generative artificial intelligence was revised in December 2025. The thing to watch is not a new bill. It is a switch the government has held for thirty years: the cross-border transfer section can be brought into force by a simple commencement notice, with no consultation and no new vote.Medium confidence
Hardest industry wall
None found.
FranceChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
In one paragraph
France follows the European rule: data may leave, but only once the right paperwork is in place. France then adds hard walls of its own. Health records must be stored inside Europe. Online gambling records must sit on a machine in mainland France. From 1 September 2026 the invoicing platform every French business must use has to run entirely from inside Europe.
The catch
"France has no local storage rule" is true for an ordinary business and false the moment you touch health data, online gambling, electronic invoicing or a government contract involving sensitive state data. In those four areas France is among the strictest countries in Europe. Since March 2026 the health rule sits in a decree, not just a certification standard, so it now binds the customer as well as the supplier.
Does this apply to me?
Yes. France reaches a company with no office in the country. European law already applies to anyone offering goods or services to people in Europe. On top of that, France's own privacy law says its national rules apply as soon as the person concerned lives in France, even when the company is based somewhere else. There is no size or revenue threshold that lets you escape.High confidence
Can the data leave the country?
For an ordinary business, yes, with paperwork: the European transfer rules apply and nothing extra is added. But four French sectors override that. Health records must be stored inside Europe and nowhere else. Online gambling records must be archived in real time on hardware in mainland France. Electronic invoicing platforms must run their whole system from inside Europe. And sensitive state data must sit on a cloud that the French cyber agency has certified as beyond the reach of foreign authorities.High confidence
What do I have to do to send it abroad?
The model is an approved-list one, run from Brussels rather than Paris. Data may go to a country the European Commission has formally approved, or anywhere else if you sign the official standard contract and write down why you think the data will still be safe. The list of approved countries is full, not empty: it includes the United Kingdom, Japan, South Korea, Canada, Switzerland, Brazil and about a dozen others, plus American companies that have signed up to the transatlantic framework. France adds no separate national approval step.High confidence
Who enforces this — and are they actually working?
The privacy regulator is the CNIL, and it is one of the busiest in Europe. In 2025 alone it issued 83 penalties totalling about 487 million euros (roughly 530 million dollars), plus 143 formal warnings. It is still fining in 2026: 5 million euros against the national employment agency in January and 5 million against a health data company in May. Separate regulators run the sector walls, and all of them are staffed and working.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling and they pull in opposite directions. You must keep accounting books and supporting documents for ten years, tax records for six, employment contracts and pay records for five, and telephone and internet subscriber identity data for five. In the other direction, European law says you must delete personal data once you no longer need it. France resolves the clash the same way most of Europe does: the legal minimum wins, but only for the specific documents the law names, and only for as long as it names.High confidence
What happens when something goes wrong?
Count the clocks, because France has at least four and they run at different speeds. Every organisation has 72 hours to tell the CNIL about a personal data breach. Telephone and internet providers have only 24 hours. Hospitals and clinics must report a serious computer security incident to their regional health agency immediately. Banks, insurers and investment firms have their own European deadlines: an initial report within 4 hours of classifying a major incident and no later than 24 hours after they notice it.High confidence
What's the trap?
Five things that are not in the summary. (1) Breaking the privacy law in France is a crime, not just a fine: sending data out of Europe unlawfully carries up to five years in prison and a 300,000 euro fine (about 330,000 dollars), and it attaches to people, not only companies. (2) A child is anyone under 15 for consent, not 13 or 16. (3) A 2023 law setting a social media age of 15 is printed in the statute book but has never come into force and cannot be enforced. (4) Handing documents to a foreign court or regulator can itself be a criminal offence in France. (5) Cookies are policed separately from the rest of privacy law, so a foreign company cannot hide behind its lead European regulator.High confidence
What's about to change?
Four dates in the next twelve months. 1 September 2026: every French business must be able to send and receive invoices through an approved platform, and those platforms must run entirely from inside Europe. Around 27 September 2026: the second phase of the health data hosting decree starts. 21 October 2026: the order forcing telephone and internet companies to keep everyone's connection records for a year expires unless the Prime Minister renews it. 12 January 2027: cloud providers across Europe must drop switching and data export fees to zero.Medium confidence
Hardest industry wall
  • Health and social care Decret n° 2026-209 du 24 mars 2026 portant modification de certaines dispositions du code de la sante publique relatives a l'hebergement de donnees de sante a caractere personnel
  • Government Decret n° 2026-272 du 14 avril 2026 relatif a la protection des donnees d'une sensibilite particuliere des administrations, operateurs et groupements d'interet public de l'Etat traitees par un service d'informatique en nuage fourni par un prestataire prive
  • All industries Immatriculation des plateformes agreees (ex plateformes de dematerialisation partenaires) - facturation electronique
  • Online gaming Article 31 de la loi n° 2010-476 du 12 mai 2010 relative a l'ouverture a la concurrence et a la regulation du secteur des jeux d'argent et de hasard en ligne