Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
CroatiaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Croatia looks like an ordinary European Union country for privacy: data may leave once you have the right paperwork. But its accounting law is stricter than most people expect. A Croatian company's books and receipts may only be kept in Croatia or another European Union country. Public bodies must keep personal-data registers in Croatian data centres. The privacy regulator fines hard.
The catch
The relaxed European headline stops being true in four places. First, accounting: the books and supporting documents of any Croatian company may be kept outside Croatia only in another European Union member state, so a United States or United Kingdom cloud archive of your ledger is not lawful, and no contract or consent fixes it. Second, the public sector: since May 2025 state registers containing personal data must sit in data centres on Croatian soil, and state bodies must use the government's own Shared Services Centre. Third, health: health data must be processed inside Croatia's national health information infrastructure and exchanged through the central health system. Fourth, aerial imagery: you need one permission to photograph Croatia from the air and a second permission to use the pictures, and the Ministry of Defence screens them first.
Does this apply to me?
Yes. Croatia's rules reach a company with no office in the country. The European Union privacy rulebook applies to anyone who offers goods or services to people in Europe, or who watches what they do online. There is no revenue or headcount threshold. Croatia does not demand its own local representative on top of the Europe-wide one, which you may place in any European country.High confidence
Can the data leave the country?
Mostly yes, but with one nasty exception that catches everybody. Ordinary personal data can go abroad using the standard European transfer tools. Your accounting records cannot: Croatian law allows them to be kept outside Croatia only in another European Union country. Health data, public-sector registers and aerial photographs each have their own separate walls.High confidence
What do I have to do to send it abroad?
For personal data, Croatia uses the European model. Some countries are pre-approved, and everywhere else you need a standard contract or a similar tool plus a risk check. The approved list is real and populated, and includes the United Kingdom, Japan, South Korea and Switzerland. For accounting records the model is different and much blunter: only European Union countries are allowed, and no paperwork buys you more.High confidence
Who enforces this — and are they actually working?
The main regulator is the Personal Data Protection Agency, known as AZOP. It is fully staffed, it hires more people, and it is one of the busiest fining bodies in central Europe for its size. It issued 13 fines totalling about 6.7 million euros (roughly 7.3 million dollars) in 2025, and 38 fines the year before. The cyber regulator, the National Cyber Security Centre, is also up and running.High confidence
How long must I keep it, and when must I delete it?
Croatia has strong minimum keeping periods and a few hard maximums. Ledgers and the documents behind them must be kept at least eleven years; payroll lists six years; the detailed wage and contribution records forever. Medical records run to ten years after the patient dies. Going the other way, camera footage must normally be deleted after six months.High confidence
What happens when something goes wrong?
There are at least two clocks and they run at different speeds. A personal data breach goes to the privacy regulator within 72 hours. A significant cyber incident goes to the cyber authority within 24 hours as an early warning, with a fuller report at 72 hours and a final report within 30 days. One incident can easily trigger both, and the 24-hour clock is the one that catches people out.High confidence
What's the trap?
Five things that are not in the summary. Your ledger cannot live on an American cloud. Children count as adults for online consent at 16, not 13. Using someone's personal data unlawfully is a crime, not just a fine. Genetic test results may never be used to price life insurance. And camera footage in an apartment building needs two thirds of the owners to agree.High confidence
What's about to change?
Two Croatian dates matter. Fines under the state information infrastructure law switch on 1 January 2027. Mandatory eInvoicing widens to smaller traders on the same day. Across Europe, cloud switching fees must fall to zero by 12 January 2027. The thing to watch is the challenge to the Europe-United States data deal, which is still valid but under real pressure.Medium confidence
Hardest industry wall
  • All industries Zakon o računovodstvu
  • Government Zakon o državnoj informacijskoj infrastrukturi
  • Health and social care Zakon o podacima i informacijama u zdravstvu
ChinaChecked 18 August 2026
Yes, with paperworkWork: Very highEnforcement: Active
In one paragraph
Data can leave China, but only through one of three official gates: a government security review, a government-written contract you file with the regulator, or a certificate from an approved body. Which gate you need depends on how many people's data you move, not on where you send it. Small exporters are exempt. Several industries are walled off entirely.
The catch
The 'paperwork, then it can go' answer is only true for ordinary companies. Payment firms, credit bureaus, hospitals, genetic labs, online map services, telecom and industrial operators, and anything the government labels critical national infrastructure must keep the data in China. In those areas a copy staying behind is not optional.
Does this apply to me?
Yes. China's privacy law reaches a company with no office and no staff in China if it offers goods or services to people in China, or analyses their behaviour. There is no revenue or headcount threshold that lets you out. If you are caught this way, you must set up a dedicated office in China or name a representative there, and give the regulator their details.High confidence
Can the data leave the country?
In general yes, once you clear the right gate — but the gate is set by volume, not by destination. China has no list of banned or approved countries. Below 100,000 people a year you can usually send data abroad with no filing at all. Above that you need a contract filed with the regulator or a certificate; above a million people, or if you hold data the state calls 'important', you need a full government security review. Then come the industry walls, which override all of this.High confidence
What do I have to do to send it abroad?
Three routes, and you do not get to pick freely — your volume picks for you. Route one is a government security review, run by the national internet regulator through your provincial office; an approval lasts three years and only covers the exact purpose, scope and method you declared. Route two is China's own standard contract, which you sign with the overseas recipient and file with the provincial regulator along with a risk assessment. Route three is a certificate from an accredited body, which since 1 March 2026 has a national standard behind it. You also need each person's separate, specific consent before their data goes abroad.High confidence
Who enforces this — and are they actually working?
The Cyberspace Administration of China leads, and it is fully staffed and busy. It runs a nationwide enforcement campaign every year, tests apps itself and publishes the names of the ones that fail, and puts out batches of worked enforcement cases. Police, the industry ministry and the market regulator enforce alongside it, and finance, health, mapping and securities regulators run their own rules. Fines are usually modest and paired with an order to fix things; the eye-watering penalties in the statute are rarely used.High confidence
How long must I keep it, and when must I delete it?
Both directions apply, and they pull against each other. The floor: network logs must be kept for at least six months, and accounting records have their own long minimum periods set by a national schedule. The ceiling: personal data may only be kept for the shortest time needed for the purpose you collected it for, and must be deleted once that purpose is met, the service ends, or consent is withdrawn. Where a law sets a minimum, that minimum wins over the delete duty — you keep the record and stop using it for anything else.High confidence
What happens when something goes wrong?
Three clocks, and they overlap. If you run critical national infrastructure you have ONE HOUR to report a serious incident to your supervising department and the police. Everyone else has four hours to tell the provincial internet office. On top of that, a network data incident that could harm national security or the public interest must be reported within 24 hours. You must also tell affected people immediately, by phone, text, message, email or public notice.High confidence
What's the trap?
Five things that ruin weekends. (1) Sending data abroad needs each person's separate, specific consent — a line buried in a global privacy notice will not do. (2) A child is anyone under 14, and their data is treated as sensitive, so you need a parent's consent and a separate set of processing rules. (3) You may not hand data stored in China to a foreign court, police force or regulator without Chinese government approval — this catches routine legal discovery and overseas audit requests. (4) You have to work out for yourself whether you hold 'important data' and report it, because the official catalogues are incomplete. (5) The widely repeated claim that all personal financial data must be stored in China does not appear where people think it does.High confidence
What's about to change?
The next twelve months are about size-based rules. A draft published on 7 August 2026 would create a heavy new tier for any company holding data on ten million people or more: store it in China, appoint a chief privacy officer, set up an outside supervision committee, publish an annual report and honour data portability requests within 30 working days. Comments closed on 7 September 2026 and it is not law yet. A companion draft going the other way would simplify life for small processors. Watch the dormant switches — several can flip with no consultation at all.High confidence
Hardest industry wall
  • All industries 中华人民共和国网络安全法(2025年修正)
  • Payments 非银行支付机构监督管理条例
  • Finance 征信业务管理办法
  • Banking 中国人民银行业务领域数据安全管理办法
  • Securities 关于加强境内企业境外发行证券和上市相关保密和档案管理工作的规定
  • Health and social care 国家健康医疗大数据标准、安全和服务管理办法(试行)
  • Mapping and location 地图管理条例
  • Telecoms 工业和信息化领域数据安全管理办法(试行)