Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
IrelandChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
In one paragraph
Ireland follows Europe's rules, so personal data can leave the country once you have the right paperwork in place. But a handful of Irish laws force certain records to be kept physically in Ireland, and breaking those is a crime rather than a fine. Ireland's privacy regulator is one of the toughest in Europe: in 2025 it fined TikTok 530 million euro and ordered it to stop sending data to China.
The catch
The relaxed headline stops being true in four places. Trust and company service providers, and cheque-cashing firms, must keep their anti-money-laundering records at premises inside Ireland for six years, and failing to do so is a criminal offence carrying up to five years in prison. Every Irish company must keep accounting information and returns at a place in Ireland even when the books themselves sit on a foreign server. Health records and telephone and internet connection records each have their own separate rules on top.
Does this apply to me?
Yes. Ireland's data protection law reaches a company with no office in Ireland whenever it offers goods or services to people in Europe or watches what they do online. There is no revenue or headcount threshold to duck under. A company based outside Europe normally has to name a representative inside Europe who regulators and members of the public can write to.High confidence
Can the data leave the country?
In general, yes, with paperwork. Ireland does not have a general rule saying personal data must stay in the country. Sending it outside Europe is allowed once you use one of the approved legal routes. But several Irish laws quietly demand that particular records sit on Irish soil, and those override the friendly headline.High confidence
What do I have to do to send it abroad?
Ireland uses the European model. A destination outside Europe is off limits unless it is on the European Commission's approved list, or you put an approved safeguard in place first. The approved list is real and populated: it currently covers seventeen destinations, including the United Kingdom, Japan, South Korea, Switzerland and Brazil. The United States counts only for companies that have signed up to the European Union to United States Data Privacy Framework.High confidence
Who enforces this — and are they actually working?
The Data Protection Commission, and it is very much awake. It has three commissioners in post — Des Hogan as chairperson, Dale Sunderland and Niamh Sweeney — and it published its 2025 annual report on 30 June 2026. In 2025 it finished four large inquiries and imposed fines of just over 530 million euro (about 580 million US dollars), almost all of it on TikTok, which it also ordered to stop sending European user data to China.High confidence
How long must I keep it, and when must I delete it?
Both directions apply, and Ireland's floors are longer than most people expect. Anti-money-laundering customer records must be kept for at least five years. Company accounting records and returns must be kept for at least six years. Trust and company service providers and cheque-cashing firms must keep their records for six years and keep them in Ireland. Telephone and internet providers must keep subscriber details for one year.High confidence
What happens when something goes wrong?
Count three clocks, not one. You have 72 hours to tell the Data Protection Commission about a personal data breach that puts people at risk, and you must tell the affected people without delay if the risk is high. Telephone and internet providers report through a separate channel under separate rules. And if the police send you an order to take down terrorist content, you have one hour.High confidence
What's the trap?
Five things that cost people their weekend. First, Ireland's famous ban on advertising to children has never actually switched on. Second, the official copy of the law on the government's own statute website can be out of date and misleading. Third, a child in Ireland is anyone under 16 for consent purposes, not 13. Fourth, some record-keeping failures are crimes, not fines. Fifth, the regulator can only fine a public body up to 1 million euro (about 1.1 million US dollars), so it uses stop orders instead.High confidence
What's about to change?
Three things land in the next year. Ireland's new health records law is switching on in stages, and the parts that let doctors share your file and that allow sharing with countries outside Europe are still switched off. Europe's cloud switching rules make all data exit fees zero on 12 January 2027. And Ireland still has not written the European cybersecurity directive into Irish law, almost two years past the deadline.High confidence
Hardest industry wall
  • Finance Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 106
  • Payments Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 108I
  • All industries Companies Act 2014, sections 283 and 285
Saudi ArabiaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Data can leave Saudi Arabia, but never for free. You need a purpose the law allows, a written safeguard such as the government's own standard contract, and a written risk assessment that asks whether the transfer could harm the Kingdom itself. Banks need the central bank's written permission before anything goes abroad. The privacy regulator is fully set up but publishes no fines.
The catch
The 'paperwork and you can send it' answer is true for an ordinary business. It is false for banks and finance companies, where the central bank must give written no-objection first and cloud is expected to sit inside the country. It is also unsettled for government bodies and critical national infrastructure: the old rule forcing them to host inside Saudi Arabia was deleted in 2024 and replaced by a duty to ask a government office for a decision, and that office has published no replacement rule.
Does this apply to me?
Yes. The law reaches a company anywhere in the world with no office in Saudi Arabia, as long as it handles the data of people living in the Kingdom. There is no size, revenue or headcount threshold to fall below. There is no general duty to appoint a local representative, but many organisations must register on the government's data platform and some must name a data protection officer.High confidence
Can the data leave the country?
Yes, with real paperwork. First the reason for sending it has to be on the government's short list of allowed purposes. Then you need a safeguard: the government's own standard contract, approved group-wide rules, or a certificate from a licensed body. Then you must write a risk assessment that includes whether the transfer could damage the Kingdom's vital interests. Two industries are much harder. Banks and finance companies must get the central bank's written no-objection before any data goes to an overseas supplier, and the central bank's rules say cloud services should sit inside Saudi Arabia unless it approves otherwise. For government bodies and critical national infrastructure the picture changed in 2024 and is now genuinely unclear.High confidence
What do I have to do to send it abroad?
The model is an approved-destination list, and the list is empty. The law says data may go to a country the regulator has judged good enough, but no such list has been published, so in practice nobody uses that route. Instead almost everyone relies on the escape hatches: sign the government's word-for-word standard contract, or get approved group-wide rules for a multinational, or send to a body holding a certificate from a licensed Saudi accreditation body. On top of that you must run a written risk assessment before the data moves.High confidence
Who enforces this — and are they actually working?
The Saudi Data and Artificial Intelligence Authority is the privacy regulator, and it is genuinely up and running. Its National Data Governance Platform is live and takes registrations, self-assessments, breach reports and complaints, and it has published the rulebook for the panels that hear violations and issue fines. What we could not find is a single published fine or named decision, so how hard it bites is still unknown. The financial regulator and the cybersecurity authority, by contrast, have supervised their sectors for years.Medium confidence
How long must I keep it, and when must I delete it?
Both directions apply, and the floor wins when they clash. The ceiling: you must destroy personal data without undue delay once the reason you collected it has gone, and also when someone asks, when they withdraw the only consent you relied on, or when you learn you processed it unlawfully. Destruction must reach backups too. The floor: your written record of processing activities must be kept for five years after the activity ends. If another law sets a keeping period, the law says keep the data until whichever is longer.High confidence
What happens when something goes wrong?
The main clock is 72 hours. If personal data is breached, lost or accessed unlawfully and that could harm the people involved, you must tell the privacy regulator within 72 hours of finding out, through the government's data platform — and you have to be registered on that platform before you can use the service. You must also tell the affected people without undue delay, in plain language. A second, separate clock runs for government bodies and critical national infrastructure, which owe cyber incident reports to the national cybersecurity authority under its own rules. Suppliers owe you notice without undue delay so you can meet your own deadline.High confidence
What's the trap?
Five things that are not in the summary. One: sending data abroad is not only about protecting the individual — you must also assess whether the transfer could harm the Kingdom's own vital interests, and there is a government guide telling you how. Two: the standard contract must be copied word for word, and changing it is itself a breach of the law, while the overseas recipient has to accept Saudi courts. Three: leaking or publishing sensitive data to hurt someone or to profit can put a person in prison for up to two years — this is a criminal charge, not a fine. Four: your supplier contract must go beyond a normal data processing agreement and say whether the supplier is subject to foreign laws and how that affects its compliance. Five: the widely quoted rule that all government and critical infrastructure data must be hosted inside Saudi Arabia was deleted in 2024, and quoting it today is wrong.High confidence
What's about to change?
Nothing is scheduled to commence on a fixed date in the next twelve months — the law and all its main regulations are already fully in force. The risk is the opposite kind: several switches the government already holds and can flip with no consultation. The biggest is the approved-country list, which the regulator is legally required to publish and has not; the day it appears, every transfer plan in the country needs rechecking. The second biggest is the missing localisation rule for government and critical infrastructure, which one office was handed in 2024 and has not yet written.Medium confidence
Hardest industry wall
None found.