Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
IndonesiaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Waking up
- In one paragraph
- Indonesia's general privacy law lets data leave if the destination protects it about as well as Indonesia does, or you use strong safeguards, or the person agrees. Money and health are walled off. Banks, payment firms, insurers and non-bank lenders must run their systems on Indonesian soil unless the financial regulator says otherwise, and medical records must sit with a local storage provider.
- The catch
- The relaxed headline is true only until you touch banking, payments, insurance and other non-bank finance, electronic medical records, or public-sector systems. In those areas the servers themselves must be in Indonesia, and moving them out needs a written permission that the banking regulator may take three months to grant. The general privacy watchdog looks quiet; the financial regulators are not.
- Does this apply to me?
- Yes. The privacy law follows the data, not the office. It covers any organisation, inside or outside Indonesia, whose handling of personal data has legal effects in Indonesia or affects people in Indonesia. There is no size or revenue cut-off to fall below. An organisation with no presence in the country is expected to name a representative in Indonesia, and any online service used by Indonesians is also expected to register with the digital ministry, which can order internet providers to block services that do not.Medium confidence
- Can the data leave the country?
- In general yes, with homework. You must be able to show the destination protects personal data at a level at least equal to Indonesia's, or put binding safeguards in place, or get the person's clear agreement. That general answer stops at the door of finance, health and government. Banks, payment providers, insurers and other non-bank financial firms must keep their systems in Indonesian data centres and back-up centres, and can only go offshore with written regulator permission. Electronic medical records must be stored with a provider that has storage facilities inside Indonesia.High confidence
- What do I have to do to send it abroad?
- There is no published list of approved countries and no official standard contract to sign. Under the general law you assess the destination yourself, write down why it is safe enough, and keep that evidence. In finance the model is completely different: you need a real permission from the regulator before the systems move, and the banking regulator allows itself up to three months to answer once your paperwork is complete.Medium confidence
- Who enforces this — and are they actually working?
- It depends which rule you break. The privacy law's own watchdog is the weak spot: the law says a supervisory body must be set up by the President, and we found no government source showing it is staffed and issuing decisions as of 18 August 2026. Day to day the digital ministry handles complaints, registration and blocking. The financial regulators are a different story — the Financial Services Authority and the central bank are plainly working, and the Authority issued new binding rules as recently as July 2026.Medium confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling and they collide. The hardest floor is health: a hospital or clinic must keep an electronic medical record for at least 25 years after the patient's last visit. Company and tax paperwork must also be kept for years. The ceiling comes from the privacy law, which says personal data must be erased once the purpose is finished, the retention period ends, or the person withdraws consent. Where they clash, the specific keeping rule wins, so a patient asking for deletion does not defeat the 25-year rule.High confidence
- What happens when something goes wrong?
- Count at least three clocks, and the privacy one is not the fastest. Under the privacy law you have 72 hours to tell the affected people and the regulator about a personal data breach. If you are a bank, you must send the financial regulator a first alert within 24 hours of learning about a serious technology incident, and a full incident report within five working days. Other financial firms, such as insurers and lenders, have five working days. Miss the 24-hour one and the fact that you met the 72-hour one will not help you.High confidence
- What's the trap?
- Five things that ruin weekends. (1) In finance the wall is a permission, not a contract — moving systems abroad needs a regulator licence and the banking regulator gives itself up to three months to decide, so cloud migrations must be planned around that. (2) In health your cloud provider must have storage facilities in Indonesia, and the Ministry of Health can demand access to the whole medical record. (3) The 25-year medical record rule beats a patient's deletion request. (4) The privacy law carries prison sentences, not just fines, so directors are personally exposed. (5) A foreign company with no office still needs a named representative in Indonesia, and a consumer service that is not registered with the digital ministry can be blocked at the internet level.Medium confidence
- What's about to change?
- One dated change is certain: from 1 September 2026 trading in digital financial assets, including crypto, runs under the financial regulator's new rulebook, so anyone in that business should re-check where its servers and records must sit. Two things are still pending as far as we could verify: the detailed implementing regulation under the privacy law, and the presidential decision setting up the privacy watchdog itself. Both could land without warning.Medium confidence
- Hardest industry wall
- Banking — Peraturan Otoritas Jasa Keuangan Nomor 11/POJK.03/2022 tentang Penyelenggaraan Teknologi Informasi oleh Bank Umum
- Payments — Peraturan Bank Indonesia Nomor 23/6/PBI/2021 tentang Penyedia Jasa Pembayaran
- Insurance — Peraturan Otoritas Jasa Keuangan Nomor 4/POJK.05/2021 tentang Penerapan Manajemen Risiko dalam Penggunaan Teknologi Informasi oleh Lembaga Jasa Keuangan Nonbank
- Health and social care — Peraturan Menteri Kesehatan Nomor 24 Tahun 2022 tentang Rekam Medis
- Government — Peraturan Pemerintah Nomor 71 Tahun 2019 tentang Penyelenggaraan Sistem dan Transaksi Elektronik
- Mapping and location — Undang-Undang Nomor 4 Tahun 2011 tentang Informasi Geospasial
EstoniaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Estonia has no general rule forcing data to stay in the country, and it adds very little on top of the European privacy rules. Two industries are the exception. Phone and internet companies must keep connection records inside the European Union, with some records physically in Estonia. Online gambling firms may only run their game server from a short list of approved countries. The regulator works, but its fines are small.
- The catch
- The relaxed headline stops being true the moment you are a telecoms operator, an online gambling operator, a health care provider or a public body. Telecoms connection records may not leave the European Union at all and certain police-request records must sit on Estonian soil. Gambling servers are limited to an approved list of countries. Health records carry a 30-year minimum keep-time. Public bodies must run the Estonian national security standard and exchange data through the state's own data layer.
- Does this apply to me?
- Yes, it reaches you even with no office in Estonia. Estonia does not write its own reach test — it uses the European Union's. If you offer goods or services to people in Estonia, or track what they do online, the European privacy rules apply and Estonia's regulator can act against you. There is no size or revenue threshold to fall below. A company with no branch anywhere in Europe normally has to name a written representative inside Europe.High confidence
- Can the data leave the country?
- In general, yes. Estonia has no law telling companies to keep personal data in Estonia, and European law actually forbids member states from imposing one on non-personal data. Two industries break that headline. Phone and internet companies must keep their call and connection records inside the European Union, and certain police-request records must stay physically in Estonia. Online gambling companies may only place their game server in Estonia, in a country that has signed the cybercrime treaty, or in a country whose regulator has a cooperation deal with the Estonian Tax and Customs Board.High confidence
- What do I have to do to send it abroad?
- For the normal routes you file nothing with the Estonian regulator. If the destination country has been officially approved by the European Commission, you simply send the data. If it has not, you sign the European Commission's standard contract with the recipient and run a risk check on the destination first. Only two routes need Estonia's regulator to sign off: group-wide internal rules where the parent company is in Estonia, and a one-off contract you wrote yourself.High confidence
- Who enforces this — and are they actually working?
- The Data Protection Inspectorate, and it is genuinely working. It has 34 posts, a director general in her second term since May 2024, and it publishes its orders. In 2025 it took in 1,568 complaints, issued 13 orders and imposed 5 penalties. But note the shape of the risk: Estonian data protection penalties are handled like minor criminal charges, so they are slow and small, and no Estonian fine has ever approached the European ceilings. Cyber rules are enforced separately by the Information System Authority, which also publishes orders — the most recent on 5 June 2026.High confidence
- How long must I keep it, and when must I delete it?
- Estonia has some of the longest minimum keep-times in Europe. Health records must be kept for 30 years. Anti-money-laundering paperwork for 5 years after the customer leaves. Phone and internet connection records for 1 year, and the police request logs behind them for 5 years. Gambling records for 5 years. Going the other way, a dead person's data stays protected for 10 years after death, or 20 years if they died as a child, and a missed payment may only be reported to credit agencies between 30 days and 5 years after it happened.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. If personal data leaks, you have 72 hours to tell the Data Protection Inspectorate, and you must tell the affected people without delay if the risk to them is high. If you run an important or essential service, you have only 24 HOURS to send a first cyber-incident warning to the Information System Authority, then 72 hours for a fuller report, then one month for a final report. Trust service providers such as e-signature and certificate companies must send the fuller report inside 24 hours too. Missing the cyber deadline is punished separately from missing the privacy one.High confidence
- What's the trap?
- Six things that are not in the summary. (1) A child in Estonia is anyone under 13 for online services, not 16 as in much of Europe, so a consent flow tuned to Germany will over-block Estonian teenagers. (2) A dead person's data stays protected for 10 years after death, 20 if they died as a child, and the heirs control it. (3) Research on Estonians must be stripped of names BEFORE the data are handed over, an ethics committee must sign off sensitive projects, and you must name the individual who holds the key. (4) Data protection fines are handled like minor criminal charges, which makes them small but also drags a named human being into the process. (5) Since 1 January 2025 the regulator itself can sue you in court on behalf of a whole group of affected people. (6) Under the cyber law a named board member is personally responsible for security and must attend training.High confidence
- What's about to change?
- One near-term date stands out. Estonia's official gazette marks its own current texts of the privacy, public information, cybersecurity, telecoms, emergency, health services, health insurance and social welfare acts as valid only until 30 September 2026, so a further change starts on 1 October 2026. We could not identify the amending law, so treat that date as a hard diary entry. Beyond it, the cyber rules phase in: registration was due by 1 April 2026 and full compliance is due by 1 January 2029. From 12 January 2027 European rules make cloud switching and data export charges free.Medium confidence
- Hardest industry wall
- Telecoms — Elektroonilise side seadus (ESS), § 111-1