Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
CroatiaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- Croatia looks like an ordinary European Union country for privacy: data may leave once you have the right paperwork. But its accounting law is stricter than most people expect. A Croatian company's books and receipts may only be kept in Croatia or another European Union country. Public bodies must keep personal-data registers in Croatian data centres. The privacy regulator fines hard.
- The catch
- The relaxed European headline stops being true in four places. First, accounting: the books and supporting documents of any Croatian company may be kept outside Croatia only in another European Union member state, so a United States or United Kingdom cloud archive of your ledger is not lawful, and no contract or consent fixes it. Second, the public sector: since May 2025 state registers containing personal data must sit in data centres on Croatian soil, and state bodies must use the government's own Shared Services Centre. Third, health: health data must be processed inside Croatia's national health information infrastructure and exchanged through the central health system. Fourth, aerial imagery: you need one permission to photograph Croatia from the air and a second permission to use the pictures, and the Ministry of Defence screens them first.
- Does this apply to me?
- Yes. Croatia's rules reach a company with no office in the country. The European Union privacy rulebook applies to anyone who offers goods or services to people in Europe, or who watches what they do online. There is no revenue or headcount threshold. Croatia does not demand its own local representative on top of the Europe-wide one, which you may place in any European country.High confidence
- Can the data leave the country?
- Mostly yes, but with one nasty exception that catches everybody. Ordinary personal data can go abroad using the standard European transfer tools. Your accounting records cannot: Croatian law allows them to be kept outside Croatia only in another European Union country. Health data, public-sector registers and aerial photographs each have their own separate walls.High confidence
- What do I have to do to send it abroad?
- For personal data, Croatia uses the European model. Some countries are pre-approved, and everywhere else you need a standard contract or a similar tool plus a risk check. The approved list is real and populated, and includes the United Kingdom, Japan, South Korea and Switzerland. For accounting records the model is different and much blunter: only European Union countries are allowed, and no paperwork buys you more.High confidence
- Who enforces this — and are they actually working?
- The main regulator is the Personal Data Protection Agency, known as AZOP. It is fully staffed, it hires more people, and it is one of the busiest fining bodies in central Europe for its size. It issued 13 fines totalling about 6.7 million euros (roughly 7.3 million dollars) in 2025, and 38 fines the year before. The cyber regulator, the National Cyber Security Centre, is also up and running.High confidence
- How long must I keep it, and when must I delete it?
- Croatia has strong minimum keeping periods and a few hard maximums. Ledgers and the documents behind them must be kept at least eleven years; payroll lists six years; the detailed wage and contribution records forever. Medical records run to ten years after the patient dies. Going the other way, camera footage must normally be deleted after six months.High confidence
- What happens when something goes wrong?
- There are at least two clocks and they run at different speeds. A personal data breach goes to the privacy regulator within 72 hours. A significant cyber incident goes to the cyber authority within 24 hours as an early warning, with a fuller report at 72 hours and a final report within 30 days. One incident can easily trigger both, and the 24-hour clock is the one that catches people out.High confidence
- What's the trap?
- Five things that are not in the summary. Your ledger cannot live on an American cloud. Children count as adults for online consent at 16, not 13. Using someone's personal data unlawfully is a crime, not just a fine. Genetic test results may never be used to price life insurance. And camera footage in an apartment building needs two thirds of the owners to agree.High confidence
- What's about to change?
- Two Croatian dates matter. Fines under the state information infrastructure law switch on 1 January 2027. Mandatory eInvoicing widens to smaller traders on the same day. Across Europe, cloud switching fees must fall to zero by 12 January 2027. The thing to watch is the challenge to the Europe-United States data deal, which is still valid but under real pressure.Medium confidence
- Hardest industry wall
- All industries — Zakon o računovodstvu
- Government — Zakon o državnoj informacijskoj infrastrukturi
- Health and social care — Zakon o podacima i informacijama u zdravstvu
EstoniaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Estonia has no general rule forcing data to stay in the country, and it adds very little on top of the European privacy rules. Two industries are the exception. Phone and internet companies must keep connection records inside the European Union, with some records physically in Estonia. Online gambling firms may only run their game server from a short list of approved countries. The regulator works, but its fines are small.
- The catch
- The relaxed headline stops being true the moment you are a telecoms operator, an online gambling operator, a health care provider or a public body. Telecoms connection records may not leave the European Union at all and certain police-request records must sit on Estonian soil. Gambling servers are limited to an approved list of countries. Health records carry a 30-year minimum keep-time. Public bodies must run the Estonian national security standard and exchange data through the state's own data layer.
- Does this apply to me?
- Yes, it reaches you even with no office in Estonia. Estonia does not write its own reach test — it uses the European Union's. If you offer goods or services to people in Estonia, or track what they do online, the European privacy rules apply and Estonia's regulator can act against you. There is no size or revenue threshold to fall below. A company with no branch anywhere in Europe normally has to name a written representative inside Europe.High confidence
- Can the data leave the country?
- In general, yes. Estonia has no law telling companies to keep personal data in Estonia, and European law actually forbids member states from imposing one on non-personal data. Two industries break that headline. Phone and internet companies must keep their call and connection records inside the European Union, and certain police-request records must stay physically in Estonia. Online gambling companies may only place their game server in Estonia, in a country that has signed the cybercrime treaty, or in a country whose regulator has a cooperation deal with the Estonian Tax and Customs Board.High confidence
- What do I have to do to send it abroad?
- For the normal routes you file nothing with the Estonian regulator. If the destination country has been officially approved by the European Commission, you simply send the data. If it has not, you sign the European Commission's standard contract with the recipient and run a risk check on the destination first. Only two routes need Estonia's regulator to sign off: group-wide internal rules where the parent company is in Estonia, and a one-off contract you wrote yourself.High confidence
- Who enforces this — and are they actually working?
- The Data Protection Inspectorate, and it is genuinely working. It has 34 posts, a director general in her second term since May 2024, and it publishes its orders. In 2025 it took in 1,568 complaints, issued 13 orders and imposed 5 penalties. But note the shape of the risk: Estonian data protection penalties are handled like minor criminal charges, so they are slow and small, and no Estonian fine has ever approached the European ceilings. Cyber rules are enforced separately by the Information System Authority, which also publishes orders — the most recent on 5 June 2026.High confidence
- How long must I keep it, and when must I delete it?
- Estonia has some of the longest minimum keep-times in Europe. Health records must be kept for 30 years. Anti-money-laundering paperwork for 5 years after the customer leaves. Phone and internet connection records for 1 year, and the police request logs behind them for 5 years. Gambling records for 5 years. Going the other way, a dead person's data stays protected for 10 years after death, or 20 years if they died as a child, and a missed payment may only be reported to credit agencies between 30 days and 5 years after it happened.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. If personal data leaks, you have 72 hours to tell the Data Protection Inspectorate, and you must tell the affected people without delay if the risk to them is high. If you run an important or essential service, you have only 24 HOURS to send a first cyber-incident warning to the Information System Authority, then 72 hours for a fuller report, then one month for a final report. Trust service providers such as e-signature and certificate companies must send the fuller report inside 24 hours too. Missing the cyber deadline is punished separately from missing the privacy one.High confidence
- What's the trap?
- Six things that are not in the summary. (1) A child in Estonia is anyone under 13 for online services, not 16 as in much of Europe, so a consent flow tuned to Germany will over-block Estonian teenagers. (2) A dead person's data stays protected for 10 years after death, 20 if they died as a child, and the heirs control it. (3) Research on Estonians must be stripped of names BEFORE the data are handed over, an ethics committee must sign off sensitive projects, and you must name the individual who holds the key. (4) Data protection fines are handled like minor criminal charges, which makes them small but also drags a named human being into the process. (5) Since 1 January 2025 the regulator itself can sue you in court on behalf of a whole group of affected people. (6) Under the cyber law a named board member is personally responsible for security and must attend training.High confidence
- What's about to change?
- One near-term date stands out. Estonia's official gazette marks its own current texts of the privacy, public information, cybersecurity, telecoms, emergency, health services, health insurance and social welfare acts as valid only until 30 September 2026, so a further change starts on 1 October 2026. We could not identify the amending law, so treat that date as a hard diary entry. Beyond it, the cyber rules phase in: registration was due by 1 April 2026 and full compliance is due by 1 January 2029. From 12 January 2027 European rules make cloud switching and data export charges free.Medium confidence
- Hardest industry wall
- Telecoms — Elektroonilise side seadus (ESS), § 111-1