Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
CroatiaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Croatia looks like an ordinary European Union country for privacy: data may leave once you have the right paperwork. But its accounting law is stricter than most people expect. A Croatian company's books and receipts may only be kept in Croatia or another European Union country. Public bodies must keep personal-data registers in Croatian data centres. The privacy regulator fines hard.
The catch
The relaxed European headline stops being true in four places. First, accounting: the books and supporting documents of any Croatian company may be kept outside Croatia only in another European Union member state, so a United States or United Kingdom cloud archive of your ledger is not lawful, and no contract or consent fixes it. Second, the public sector: since May 2025 state registers containing personal data must sit in data centres on Croatian soil, and state bodies must use the government's own Shared Services Centre. Third, health: health data must be processed inside Croatia's national health information infrastructure and exchanged through the central health system. Fourth, aerial imagery: you need one permission to photograph Croatia from the air and a second permission to use the pictures, and the Ministry of Defence screens them first.
Does this apply to me?
Yes. Croatia's rules reach a company with no office in the country. The European Union privacy rulebook applies to anyone who offers goods or services to people in Europe, or who watches what they do online. There is no revenue or headcount threshold. Croatia does not demand its own local representative on top of the Europe-wide one, which you may place in any European country.High confidence
Can the data leave the country?
Mostly yes, but with one nasty exception that catches everybody. Ordinary personal data can go abroad using the standard European transfer tools. Your accounting records cannot: Croatian law allows them to be kept outside Croatia only in another European Union country. Health data, public-sector registers and aerial photographs each have their own separate walls.High confidence
What do I have to do to send it abroad?
For personal data, Croatia uses the European model. Some countries are pre-approved, and everywhere else you need a standard contract or a similar tool plus a risk check. The approved list is real and populated, and includes the United Kingdom, Japan, South Korea and Switzerland. For accounting records the model is different and much blunter: only European Union countries are allowed, and no paperwork buys you more.High confidence
Who enforces this — and are they actually working?
The main regulator is the Personal Data Protection Agency, known as AZOP. It is fully staffed, it hires more people, and it is one of the busiest fining bodies in central Europe for its size. It issued 13 fines totalling about 6.7 million euros (roughly 7.3 million dollars) in 2025, and 38 fines the year before. The cyber regulator, the National Cyber Security Centre, is also up and running.High confidence
How long must I keep it, and when must I delete it?
Croatia has strong minimum keeping periods and a few hard maximums. Ledgers and the documents behind them must be kept at least eleven years; payroll lists six years; the detailed wage and contribution records forever. Medical records run to ten years after the patient dies. Going the other way, camera footage must normally be deleted after six months.High confidence
What happens when something goes wrong?
There are at least two clocks and they run at different speeds. A personal data breach goes to the privacy regulator within 72 hours. A significant cyber incident goes to the cyber authority within 24 hours as an early warning, with a fuller report at 72 hours and a final report within 30 days. One incident can easily trigger both, and the 24-hour clock is the one that catches people out.High confidence
What's the trap?
Five things that are not in the summary. Your ledger cannot live on an American cloud. Children count as adults for online consent at 16, not 13. Using someone's personal data unlawfully is a crime, not just a fine. Genetic test results may never be used to price life insurance. And camera footage in an apartment building needs two thirds of the owners to agree.High confidence
What's about to change?
Two Croatian dates matter. Fines under the state information infrastructure law switch on 1 January 2027. Mandatory eInvoicing widens to smaller traders on the same day. Across Europe, cloud switching fees must fall to zero by 12 January 2027. The thing to watch is the challenge to the Europe-United States data deal, which is still valid but under real pressure.Medium confidence
Hardest industry wall
  • All industries Zakon o računovodstvu
  • Government Zakon o državnoj informacijskoj infrastrukturi
  • Health and social care Zakon o podacima i informacijama u zdravstvu
United KingdomChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
In one paragraph
Data can leave the United Kingdom, but you need the right paperwork first. Sending it to Europe or to about fifteen other approved places needs nothing extra. Anywhere else needs a government-published contract and a risk check. No general law forces data to stay in Britain. The privacy regulator is busy and its fines are getting bigger.
The catch
The easy headline stops being true in three places. Telecoms operators must keep backup copies of key network information inside the United Kingdom. National Health Service patient records may only be sent to countries the United Kingdom has formally approved, which rules out the standard contract route. And government material classified SECRET or above cannot sit in public cloud at all. Everyone else can store data abroad with the right contract in place.
Does this apply to me?
Yes. British privacy law reaches a company anywhere in the world if it deliberately offers goods or services to people in the United Kingdom, or watches what they do online. There is no size or revenue floor to hide under. If you are caught and have no British office, you generally have to name a representative in the United Kingdom, unless you are a public body or your processing is rare and low risk.High confidence
Can the data leave the country?
Yes, with paperwork. The United Kingdom has no general law forcing data to stay in the country. Send it to the European Economic Area or another approved country and you need nothing extra; send it anywhere else and you need an approved contract plus a written risk assessment. Three industries are stricter: telecoms, the health service and classified government work. Banking, payments, insurance, securities, education, online gambling and mapping have no location rule that we could find.High confidence
What do I have to do to send it abroad?
The model is an approved-list one. If the destination is on the government's approved list you may send data with no extra paperwork. If it is not, you must sign the government's own contract template and run a risk assessment first. The list is well populated: the whole European Economic Area plus Andorra, Argentina, the Faroe Islands, Gibraltar, Guernsey, the Isle of Man, Israel, Jersey, New Zealand, South Korea, Switzerland and Uruguay, with partial cover for Canada, Japan and the United States.High confidence
Who enforces this — and are they actually working?
The Information Commissioner's Office, and it is very much working. It fined Capita fourteen million pounds (about $18 million) in October 2025, Reddit £14.47 million (about $18.5 million) in February 2026, and the owner of Imgur in the same month, and it issues smaller marketing fines almost monthly. Watch a quirk: a replacement body called the Information Commission legally exists but had no staff and did no work in its first financial year, so the old office is still the one that acts.High confidence
How long must I keep it, and when must I delete it?
There is no single deletion deadline. The rule is that you keep personal data only as long as you actually need it, and you must be able to explain the period you chose. Pulling the other way are minimum keeping periods: company and tax records for six years, telecoms connection records for up to twelve months if the government serves a notice, and telecoms security data for thirteen months. Where a minimum and a maximum clash, the legal duty to keep wins and you keep the data.High confidence
What happens when something goes wrong?
Count at least three clocks. Any organisation has 72 hours to tell the privacy regulator about a personal data breach, and must tell the affected people if the risk to them is high. Telecoms and internet providers also have 72 hours under the electronic communications rules — that used to be 24 hours and quietly changed on 20 August 2025. Operators of essential services such as water, energy and transport have their own 72-hour clock to their own regulator.High confidence
What's the trap?
Five. (1) A child can consent at 13 here, not 16 — but the children's design code covers everyone under 18, and the regulator fined Reddit £14.47 million (about $18.5 million) for weak age checks. (2) Telecoms firms must keep some backup data physically in Britain. (3) Health service data can only go to approved countries, so the standard contract does not help you. (4) Misusing personal data can be a crime, not just a fine. (5) The government can secretly order a company to weaken its security, and Apple is fighting one of those orders right now.Medium confidence
What's about to change?
Two things to watch in the next twelve months. A cyber security bill is going through Parliament and will widen incident reporting to data centres and managed service suppliers — it is not law yet, so do not plan as if it were. And the privacy regulator is due to be replaced by a new body called the Information Commission, but only once ministers lay the paperwork, which had not happened by mid-2026. The regulator is also writing a statutory code on artificial intelligence.High confidence
Hardest industry wall
  • Telecoms The Electronic Communications (Security Measures) Regulations 2022, with the Telecommunications Security Code of Practice 2026 (version 1.1)