Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
IrelandChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
In one paragraph
Ireland follows Europe's rules, so personal data can leave the country once you have the right paperwork in place. But a handful of Irish laws force certain records to be kept physically in Ireland, and breaking those is a crime rather than a fine. Ireland's privacy regulator is one of the toughest in Europe: in 2025 it fined TikTok 530 million euro and ordered it to stop sending data to China.
The catch
The relaxed headline stops being true in four places. Trust and company service providers, and cheque-cashing firms, must keep their anti-money-laundering records at premises inside Ireland for six years, and failing to do so is a criminal offence carrying up to five years in prison. Every Irish company must keep accounting information and returns at a place in Ireland even when the books themselves sit on a foreign server. Health records and telephone and internet connection records each have their own separate rules on top.
Does this apply to me?
Yes. Ireland's data protection law reaches a company with no office in Ireland whenever it offers goods or services to people in Europe or watches what they do online. There is no revenue or headcount threshold to duck under. A company based outside Europe normally has to name a representative inside Europe who regulators and members of the public can write to.High confidence
Can the data leave the country?
In general, yes, with paperwork. Ireland does not have a general rule saying personal data must stay in the country. Sending it outside Europe is allowed once you use one of the approved legal routes. But several Irish laws quietly demand that particular records sit on Irish soil, and those override the friendly headline.High confidence
What do I have to do to send it abroad?
Ireland uses the European model. A destination outside Europe is off limits unless it is on the European Commission's approved list, or you put an approved safeguard in place first. The approved list is real and populated: it currently covers seventeen destinations, including the United Kingdom, Japan, South Korea, Switzerland and Brazil. The United States counts only for companies that have signed up to the European Union to United States Data Privacy Framework.High confidence
Who enforces this — and are they actually working?
The Data Protection Commission, and it is very much awake. It has three commissioners in post — Des Hogan as chairperson, Dale Sunderland and Niamh Sweeney — and it published its 2025 annual report on 30 June 2026. In 2025 it finished four large inquiries and imposed fines of just over 530 million euro (about 580 million US dollars), almost all of it on TikTok, which it also ordered to stop sending European user data to China.High confidence
How long must I keep it, and when must I delete it?
Both directions apply, and Ireland's floors are longer than most people expect. Anti-money-laundering customer records must be kept for at least five years. Company accounting records and returns must be kept for at least six years. Trust and company service providers and cheque-cashing firms must keep their records for six years and keep them in Ireland. Telephone and internet providers must keep subscriber details for one year.High confidence
What happens when something goes wrong?
Count three clocks, not one. You have 72 hours to tell the Data Protection Commission about a personal data breach that puts people at risk, and you must tell the affected people without delay if the risk is high. Telephone and internet providers report through a separate channel under separate rules. And if the police send you an order to take down terrorist content, you have one hour.High confidence
What's the trap?
Five things that cost people their weekend. First, Ireland's famous ban on advertising to children has never actually switched on. Second, the official copy of the law on the government's own statute website can be out of date and misleading. Third, a child in Ireland is anyone under 16 for consent purposes, not 13. Fourth, some record-keeping failures are crimes, not fines. Fifth, the regulator can only fine a public body up to 1 million euro (about 1.1 million US dollars), so it uses stop orders instead.High confidence
What's about to change?
Three things land in the next year. Ireland's new health records law is switching on in stages, and the parts that let doctors share your file and that allow sharing with countries outside Europe are still switched off. Europe's cloud switching rules make all data exit fees zero on 12 January 2027. And Ireland still has not written the European cybersecurity directive into Irish law, almost two years past the deadline.High confidence
Hardest industry wall
  • Finance Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 106
  • Payments Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 108I
  • All industries Companies Act 2014, sections 283 and 285
ItalyChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
In one paragraph
Italy does not make ordinary business data stay in Italy. European rules decide when data may leave Europe, and Italy layers its own rules on top. But the moment you sell to the Italian state — a ministry, a town hall, a hospital, a school — the picture changes completely. The most sensitive government data has to sit on machines inside Italy, run from Italy.
The catch
"Italy has no data localisation" holds right up until your customer is a public body. Italian government data is sorted into ordinary, critical and strategic. Strategic data belongs on Italian soil under Italian operational control; critical data may not go on a public cloud outside Europe. On top of that, a cloud provider needs a licence from the national cyber agency before any public body is allowed to buy from it at all. Separately, telecoms companies must keep call and connection records for years, and the government can attach storage-location conditions to fifth-generation mobile and cloud contracts case by case.
Does this apply to me?
Yes, it reaches you with no office in Italy. European law applies to any organisation anywhere that offers goods or services to people in Italy, or that monitors what they do online. There is no size or revenue threshold to duck under. If you have no branch anywhere in Europe, you must appoint a written representative based in Europe, and people and regulators can go to that representative instead of chasing you abroad.High confidence
Can the data leave the country?
For a normal private company, yes — with paperwork, exactly as anywhere else in Europe. Italy has no general law saying personal data must be stored in Italy. The real walls are in one place: anything sold to or run by the Italian public sector. Government data is graded ordinary, critical or strategic, and the top two grades cannot sit on a public cloud outside Europe, with strategic data confined to infrastructure inside Italy and operated from Italy.High confidence
What do I have to do to send it abroad?
Three routes, and they are European rather than Italian. Best case, the destination is on Europe's official approved list and you need nothing extra. Otherwise you sign Europe's standard contract with the recipient, or get group-wide internal rules approved by a regulator. With the last two you must also write down an assessment of whether the destination country's surveillance laws would undermine the protection. Italy adds no extra permission step, but it does add a criminal offence for getting it badly wrong.High confidence
Who enforces this — and are they actually working?
The Italian data protection authority, known as the Garante, and it is one of the busiest and boldest regulators in Europe. In 2025 alone it took 807 decisions, of which 506 were corrective or punitive, ran 130 inspections and collected more than 37 million euros (about 41 million dollars) in fines. It was the first regulator in the world to order a temporary halt to a major chatbot service, and it has since blocked or restricted several artificial intelligence products. Cybersecurity is enforced by a separate agency.High confidence
How long must I keep it, and when must I delete it?
Both directions, and they pull hard against each other. The floors: telephone records must be kept 24 months, internet connection records 12 months, unanswered calls 30 days, and a separate six-year rule applies for terrorism and serious crime. Health records in the national system are erased 30 years after the patient dies. The ceiling is much tighter than people expect: the regulator says the technical logs behind staff email may normally be kept for no more than 21 days.High confidence
What happens when something goes wrong?
Count at least three clocks, and they run at the same time. A personal data breach goes to the Garante within 72 hours, and to the people affected without delay where the risk to them is high. If you are in scope of Italy's network security regime, a first warning goes to the national cyber agency within 24 hours, a fuller notification within 72 hours, and a final report within a month. Organisations inside the national cyber perimeter have a much shorter fuse, reported as six hours.Medium confidence
What's the trap?
Five. One: staff email logs may normally be kept only 21 days, and a regional government was punished in 2025 for keeping 90. Two: before you install any tool that could monitor employees, you need a union agreement or a labour inspectorate permit, and skipping it is a criminal matter, not a fine. Three: some data offences in Italy carry prison, not just penalties. Four: children can consent at 14 in Italy, not 16. Five: the widely reported rule forcing public-sector artificial intelligence onto Italian servers was deleted before the law passed, so citing it is wrong.High confidence
What's about to change?
Two firm dates and one open wound. By 31 October 2026 organisations in Italy's network security regime must have their basic security measures in place and evidenced. From 12 January 2027 every cloud provider must charge nothing for switching away or pulling data out. The open wound is the Italian regulator itself: one of four board seats has been empty since January 2026 and Parliament has not filled it.Medium confidence
Hardest industry wall
  • Government Regolamento unico per le infrastrutture e i servizi cloud per la PA — Determinazione ACN n. 21007/24