Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
Hong Kong SARChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Hong Kong's privacy law contains a cross-border transfer ban that has never been switched on. It was written in 1995 and, thirty years later, still has no start date. So under the general law you can send personal data anywhere with no paperwork at all. The privacy regulator is busy and prosecutes people, but it cannot fine you directly.
- The catch
- The free-for-all stops at three doors. Licensed securities and futures firms need written permission from the markets regulator before their records live only on servers outside Hong Kong. Government departments are told not to put sensitive or personal information on public cloud at all. And data coming the other way, from mainland China into Hong Kong, is tightly controlled by mainland law, not by Hong Kong law - that is the wall most companies actually hit.
- Does this apply to me?
- Yes, it can reach you with no office in Hong Kong. The privacy law bites on whoever controls the collection, holding, use or processing of personal data in or from Hong Kong, so a foreign company running a Hong Kong-facing service is caught. There is no revenue or headcount threshold to fall below, no register to join, and no requirement to appoint a local representative. The anti-doxxing powers go further still: the regulator can order an overseas platform to take material down.High confidence
- Can the data leave the country?
- Under the general privacy law, yes - freely, with nothing to sign. The one section that would have restricted transfers abroad was written into the law in 1995 and has never been brought into operation, so today there is no legal control on personal data leaving Hong Kong. Industry rules are where the real limits sit, and there are fewer of them than people expect: the securities regulator is the main one, and government departments have their own restriction.High confidence
- What do I have to do to send it abroad?
- Nothing. There is no approval to seek, no standard contract to sign and no government list to check before personal data leaves Hong Kong. The model on paper is an allowlist - the regulator would publish a list of approved destinations - but because the section was never switched on, that list has never been issued and is empty. The regulator does publish a voluntary guide and encourages firms to build the safeguards now, but that is advice, not law.High confidence
- Who enforces this — and are they actually working?
- The Privacy Commissioner for Personal Data, and it is genuinely busy. By the end of December 2025 it had issued 2,104 orders to 57 online platforms to take down 33,743 doxxing messages, opened 519 criminal investigations and arrested 81 people. But there is a catch that changes the risk picture completely: the Commissioner cannot impose a fine for breaking the privacy principles. It serves a notice telling you to fix the problem, and only ignoring that notice is a crime.High confidence
- How long must I keep it, and when must I delete it?
- There is a hard ceiling and almost no floor in the privacy law itself. You must erase personal data once it is no longer needed for the purpose you collected it for, and failing to do so is a criminal offence carrying a fine of up to HK$10,000 (about $1,300). The privacy law sets no minimum keeping periods; those come from tax, company and anti-money-laundering law instead. Where the two pull against each other, the specific keeping duty in the other law wins, and you delete once it expires.Medium confidence
- What happens when something goes wrong?
- For a normal data breach there is no deadline, because there is no duty. Telling the Privacy Commissioner about a breach is voluntary in Hong Kong - the regulator asks you to do it as good practice and gives you a form, but no law compels it. That is unusual and it is changing: since 1 January 2026 operators of designated critical infrastructure must report computer-system security incidents, so those firms now have a real clock while everyone else has none.High confidence
- What's the trap?
- Five things that catch people out. First, marketing mistakes are crimes here, not fines - using someone's data for direct marketing without the right consent can mean five years in prison. Second, the regulator cannot fine you, so people assume the risk is low and miss the criminal exposure entirely. Third, Hong Kong sets no age at which a child can consent, so there is no simple number to code into a sign-up flow. Fourth, licensed securities firms need written permission before their records live only on overseas servers, and two named people who live in Hong Kong must be able to unlock them. Fifth, the dormant transfer section, if ever switched on, would also catch data moving between two foreign countries when a Hong Kong company controls it.Medium confidence
- What's about to change?
- Nothing is scheduled to land in the next twelve months that we could confirm. The critical infrastructure security law already started on 1 January 2026, and the government's guideline for generative artificial intelligence was revised in December 2025. The thing to watch is not a new bill. It is a switch the government has held for thirty years: the cross-border transfer section can be brought into force by a simple commencement notice, with no consultation and no new vote.Medium confidence
- Hardest industry wall
- None found.
United KingdomChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Data can leave the United Kingdom, but you need the right paperwork first. Sending it to Europe or to about fifteen other approved places needs nothing extra. Anywhere else needs a government-published contract and a risk check. No general law forces data to stay in Britain. The privacy regulator is busy and its fines are getting bigger.
- The catch
- The easy headline stops being true in three places. Telecoms operators must keep backup copies of key network information inside the United Kingdom. National Health Service patient records may only be sent to countries the United Kingdom has formally approved, which rules out the standard contract route. And government material classified SECRET or above cannot sit in public cloud at all. Everyone else can store data abroad with the right contract in place.
- Does this apply to me?
- Yes. British privacy law reaches a company anywhere in the world if it deliberately offers goods or services to people in the United Kingdom, or watches what they do online. There is no size or revenue floor to hide under. If you are caught and have no British office, you generally have to name a representative in the United Kingdom, unless you are a public body or your processing is rare and low risk.High confidence
- Can the data leave the country?
- Yes, with paperwork. The United Kingdom has no general law forcing data to stay in the country. Send it to the European Economic Area or another approved country and you need nothing extra; send it anywhere else and you need an approved contract plus a written risk assessment. Three industries are stricter: telecoms, the health service and classified government work. Banking, payments, insurance, securities, education, online gambling and mapping have no location rule that we could find.High confidence
- What do I have to do to send it abroad?
- The model is an approved-list one. If the destination is on the government's approved list you may send data with no extra paperwork. If it is not, you must sign the government's own contract template and run a risk assessment first. The list is well populated: the whole European Economic Area plus Andorra, Argentina, the Faroe Islands, Gibraltar, Guernsey, the Isle of Man, Israel, Jersey, New Zealand, South Korea, Switzerland and Uruguay, with partial cover for Canada, Japan and the United States.High confidence
- Who enforces this — and are they actually working?
- The Information Commissioner's Office, and it is very much working. It fined Capita fourteen million pounds (about $18 million) in October 2025, Reddit £14.47 million (about $18.5 million) in February 2026, and the owner of Imgur in the same month, and it issues smaller marketing fines almost monthly. Watch a quirk: a replacement body called the Information Commission legally exists but had no staff and did no work in its first financial year, so the old office is still the one that acts.High confidence
- How long must I keep it, and when must I delete it?
- There is no single deletion deadline. The rule is that you keep personal data only as long as you actually need it, and you must be able to explain the period you chose. Pulling the other way are minimum keeping periods: company and tax records for six years, telecoms connection records for up to twelve months if the government serves a notice, and telecoms security data for thirteen months. Where a minimum and a maximum clash, the legal duty to keep wins and you keep the data.High confidence
- What happens when something goes wrong?
- Count at least three clocks. Any organisation has 72 hours to tell the privacy regulator about a personal data breach, and must tell the affected people if the risk to them is high. Telecoms and internet providers also have 72 hours under the electronic communications rules — that used to be 24 hours and quietly changed on 20 August 2025. Operators of essential services such as water, energy and transport have their own 72-hour clock to their own regulator.High confidence
- What's the trap?
- Five. (1) A child can consent at 13 here, not 16 — but the children's design code covers everyone under 18, and the regulator fined Reddit £14.47 million (about $18.5 million) for weak age checks. (2) Telecoms firms must keep some backup data physically in Britain. (3) Health service data can only go to approved countries, so the standard contract does not help you. (4) Misusing personal data can be a crime, not just a fine. (5) The government can secretly order a company to weaken its security, and Apple is fighting one of those orders right now.Medium confidence
- What's about to change?
- Two things to watch in the next twelve months. A cyber security bill is going through Parliament and will widen incident reporting to data centres and managed service suppliers — it is not law yet, so do not plan as if it were. And the privacy regulator is due to be replaced by a new body called the Information Commission, but only once ministers lay the paperwork, which had not happened by mid-2026. The regulator is also writing a statutory code on artificial intelligence.High confidence
- Hardest industry wall
- Telecoms — The Electronic Communications (Security Measures) Regulations 2022, with the Telecommunications Security Code of Practice 2026 (version 1.1)