Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
IrelandChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
In one paragraph
Ireland follows Europe's rules, so personal data can leave the country once you have the right paperwork in place. But a handful of Irish laws force certain records to be kept physically in Ireland, and breaking those is a crime rather than a fine. Ireland's privacy regulator is one of the toughest in Europe: in 2025 it fined TikTok 530 million euro and ordered it to stop sending data to China.
The catch
The relaxed headline stops being true in four places. Trust and company service providers, and cheque-cashing firms, must keep their anti-money-laundering records at premises inside Ireland for six years, and failing to do so is a criminal offence carrying up to five years in prison. Every Irish company must keep accounting information and returns at a place in Ireland even when the books themselves sit on a foreign server. Health records and telephone and internet connection records each have their own separate rules on top.
Does this apply to me?
Yes. Ireland's data protection law reaches a company with no office in Ireland whenever it offers goods or services to people in Europe or watches what they do online. There is no revenue or headcount threshold to duck under. A company based outside Europe normally has to name a representative inside Europe who regulators and members of the public can write to.High confidence
Can the data leave the country?
In general, yes, with paperwork. Ireland does not have a general rule saying personal data must stay in the country. Sending it outside Europe is allowed once you use one of the approved legal routes. But several Irish laws quietly demand that particular records sit on Irish soil, and those override the friendly headline.High confidence
What do I have to do to send it abroad?
Ireland uses the European model. A destination outside Europe is off limits unless it is on the European Commission's approved list, or you put an approved safeguard in place first. The approved list is real and populated: it currently covers seventeen destinations, including the United Kingdom, Japan, South Korea, Switzerland and Brazil. The United States counts only for companies that have signed up to the European Union to United States Data Privacy Framework.High confidence
Who enforces this — and are they actually working?
The Data Protection Commission, and it is very much awake. It has three commissioners in post — Des Hogan as chairperson, Dale Sunderland and Niamh Sweeney — and it published its 2025 annual report on 30 June 2026. In 2025 it finished four large inquiries and imposed fines of just over 530 million euro (about 580 million US dollars), almost all of it on TikTok, which it also ordered to stop sending European user data to China.High confidence
How long must I keep it, and when must I delete it?
Both directions apply, and Ireland's floors are longer than most people expect. Anti-money-laundering customer records must be kept for at least five years. Company accounting records and returns must be kept for at least six years. Trust and company service providers and cheque-cashing firms must keep their records for six years and keep them in Ireland. Telephone and internet providers must keep subscriber details for one year.High confidence
What happens when something goes wrong?
Count three clocks, not one. You have 72 hours to tell the Data Protection Commission about a personal data breach that puts people at risk, and you must tell the affected people without delay if the risk is high. Telephone and internet providers report through a separate channel under separate rules. And if the police send you an order to take down terrorist content, you have one hour.High confidence
What's the trap?
Five things that cost people their weekend. First, Ireland's famous ban on advertising to children has never actually switched on. Second, the official copy of the law on the government's own statute website can be out of date and misleading. Third, a child in Ireland is anyone under 16 for consent purposes, not 13. Fourth, some record-keeping failures are crimes, not fines. Fifth, the regulator can only fine a public body up to 1 million euro (about 1.1 million US dollars), so it uses stop orders instead.High confidence
What's about to change?
Three things land in the next year. Ireland's new health records law is switching on in stages, and the parts that let doctors share your file and that allow sharing with countries outside Europe are still switched off. Europe's cloud switching rules make all data exit fees zero on 12 January 2027. And Ireland still has not written the European cybersecurity directive into Irish law, almost two years past the deadline.High confidence
Hardest industry wall
  • Finance Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 106
  • Payments Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 108I
  • All industries Companies Act 2014, sections 283 and 285
CambodiaChecked 18 August 2026
Depends on your industryWork: LowEnforcement: Dormant
In one paragraph
Cambodia has no general privacy law. A bill exists and went to a public review meeting in August 2026, but it is not law and there is no privacy regulator to complain to. For most businesses data can leave the country freely, with no paperwork. Banks and other lenders are the big exception: their main data centre must sit inside Cambodia.
The catch
The relaxed headline stops at the door of the financial sector. Any bank or lender supervised by Cambodia's central bank must keep at least one main data centre inside the country, and must get the central bank's permission in advance before customer personal data is moved to or hosted on servers abroad. Telecoms are also watched closely by an active regulator, and a suspended 2021 order that would push all internet traffic through a single government-controlled gateway can be switched back on at any time.
Does this apply to me?
There is no general data protection law in Cambodia, so there is nothing for a foreign company to be caught by. No size threshold, no revenue threshold, no registration, and no requirement to appoint someone in Cambodia to answer for your data. That changes the moment you need a local licence: banks, lenders and telecoms operators are licensed here and their licence conditions do reach their overseas systems. A draft privacy law was put to a validation workshop on 5 August 2026 and will proceed through the formal law-making process, so this answer has a shelf life.High confidence
Can the data leave the country?
In general, yes, and with nothing to sign. Cambodia has no rule that stops ordinary personal data leaving the country. Finance is the one hard wall we could verify: a bank or lender supervised by the central bank must have at least one main data centre in Cambodia, may only use a foreign data centre as a backup, and needs the central bank's approval before customer personal data is hosted abroad. Telecoms is the sector to watch, because a 2021 order that would route all internet traffic through a single national gateway was never switched on but was never cancelled either.Medium confidence
What do I have to do to send it abroad?
For most organisations, nothing at all. There is no approved-countries list, no banned-countries list, no standard contract to sign and no government form to file. The lists are not just empty, they do not exist, because there is no law that creates them. In finance the model is completely different: each move of customer personal data out of Cambodia needs its own approval from the central bank, decided case by case, and there is no published application process or timetable.Medium confidence
Who enforces this — and are they actually working?
For privacy, nobody. Cambodia has no data protection authority. The Ministry of Post and Telecommunications is writing the law and, in November 2025, ran a training workshop with Singapore's privacy regulator on how to build such an authority, which tells you plainly that one does not yet exist. Sector regulators are a different story and are genuinely working: the central bank supervises financial firms against its 2026 technology guidelines, and the telecoms regulator publicly named an operator in June 2026 for selling SIM cards without properly checking customers' identity documents.High confidence
How long must I keep it, and when must I delete it?
There is a floor and almost no ceiling. Tax and accounting law forces businesses to keep books and supporting documents for years, and financial firms must keep system logs and agree retention periods with their cloud providers. In the other direction there is no general rule telling anyone to delete personal data, because there is no privacy law. The only deletion duty we could verify applies to banks and lenders, who must keep customer personal data only as long as it is needed.Medium confidence
What happens when something goes wrong?
There is no breach reporting clock in Cambodia. No law requires you to tell a regulator or the affected people when personal data leaks, and there is no national cyber incident hotline with a deadline in hours. The nearest thing is in banking: the central bank tells supervised firms to report incidents as it requires, either on a regular cycle or one-off, with no fixed number of hours. Two draft laws would change this, so treat today's silence as temporary.Medium confidence
What's the trap?
Five things that are not in the summary. First, the e-commerce law reportedly bans encryption that would stop evidence being used in a criminal case, which cuts across normal end-to-end encryption promises. Second, a cloud-only bank cannot operate here: the main data centre must physically be in Cambodia. Third, moving customer banking data abroad needs the central bank's permission in advance, and there is no published process or timetable, so it must be planned months ahead. Fourth, telecoms operators must check identity documents before activating a SIM card, and the regulator names offenders in public. Fifth, no privacy law does not mean no risk, because your foreign customers will impose their own rules by contract.Medium confidence
What's about to change?
Four drafts are moving and none of them is law yet. The Personal Data Protection Law reached a validation workshop on 5 August 2026 and now heads into the formal law-making process. The Cybersecurity Law was still being argued over with the Ministry of Justice in July 2026. A Data Governance Policy for 2026 to 2035 was in consultation in March 2026 and is expected to cover where data may be stored and how it may cross borders. A Digital Government Law went to consultation in July 2025. No commencement date has been announced for any of them.High confidence
Hardest industry wall
  • Finance Technology and Cyber Risk Management Guidelines (TCRMG)