Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
IsraelChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Israeli data can go abroad, but never by default. Either the destination country protects data as well as Israel does, or you fit one of eight listed exceptions — usually a contract in which the receiver promises to follow Israeli rules. A big reform started on 14 August 2025 and the regulator now issues real fines. No industry bans exports outright, but several add heavy conditions.
- The catch
- The general answer is 'yes, with paperwork'. It stops being true in four places. Banks may not put sensitive customer data on a cloud outside Israel unless they have checked the provider meets European-level protection. Insurers and pension bodies must report every offshore outsourcing arrangement to their regulator each year. Identifiable patient data used for research must generally stay inside the hospital or health fund that holds it, not merely inside Israel. And central government has moved its own cloud into Israeli data-centre regions on purpose, so selling cloud to the state effectively requires an Israeli region.
- Does this apply to me?
- Yes, it can reach a foreign company with no office in Israel — but the law never says so in words. Israeli privacy law simply applies to anyone who collects, uses or processes personal data, with no size or revenue threshold to fall under. There is no general requirement to appoint a local representative. Some organisations must appoint a privacy officer, and that person is allowed to be an outside contractor rather than a staff member.Medium confidence
- Can the data leave the country?
- Yes, with paperwork — and you must be able to name the route you are using. The default rule is that data may only go to a country whose law protects it at least as well as Israeli law does. If the destination fails that test, you have to fit one of eight listed exceptions, and whichever route you take you also need a written promise from the receiver. No Israeli industry has a flat 'the data stays here' rule, but four sectors bolt extra conditions on top.High confidence
- What do I have to do to send it abroad?
- The model is closest to an allowlist: you may not send data out unless the destination qualifies, and the qualifying list is already populated. It counts if the country signed the Council of Europe data protection convention, or if it receives data from European Union countries on the same terms — so Europe's approved-country list does much of the work. If your destination does not qualify, the usual fallback is a contract in which the receiver promises to meet Israeli standards. Either way you also need a separate written promise from the receiver that it will protect the data and pass it to nobody else.High confidence
- Who enforces this — and are they actually working?
- The Privacy Protection Authority, part of the Ministry of Justice, and it is fully operational. It has a serving commissioner, an administrative enforcement department, and it publishes its decisions with names and amounts. In 2026 it fined a national health fund about 256,000 shekels (roughly $72,000) for taking two months to report a security incident, and a small leisure company about 12,000 shekels (roughly $3,400) for a defective privacy notice. Industry regulators — the Bank of Israel, the insurance regulator and the Ministry of Health — enforce their own rules separately.High confidence
- How long must I keep it, and when must I delete it?
- There is a clear floor and a clear ceiling, and they sit close together. The floor: security and access-monitoring records must be kept for at least 24 months, and organisations with medium or high security databases must keep a restorable backup of them. The ceiling: if a database contains anything that came from Europe, you must run a mechanism that finds data you no longer need and delete it, and you must delete data on request. Where another law says you must keep something, that wins over the duty to delete.High confidence
- What happens when something goes wrong?
- There is one main clock and it has no hours attached to it: a severe security incident must be reported to the Privacy Protection Authority immediately, along with what you did about it. 'Immediately' is taken literally — a health fund was fined for a two-month delay. Telling the affected people is not automatic; the Authority decides, after consulting the national cyber agency, and can order you to notify them. Israel has no general law forcing every company to report cyber incidents to the state, so your second clock, if you have one, comes from your industry regulator.High confidence
- What's the trap?
- Five things that are not in the summary. One: a single record that arrived from Europe drags the whole database into the stricter European rules — since 1 January 2025 those rules apply to any other data sitting in the same database. Two: 'immediately' really means immediately, and there is no safe 72-hour habit to fall back on. Three: fines are calculated per person, not as a flat cap, so a large database turns a small breach into a very large bill. Four: privacy breaches are criminal offences, not just regulatory ones, with prison terms attached. Five: 'data security officer' and 'data protection officer' are two different Israeli roles with different triggers, and having one does not satisfy the other.High confidence
- What's about to change?
- The big change already happened on 14 August 2025. What is landing now is the detail underneath it. In April 2026 the regulator finalised its binding rules on the contract you must sign before sending data abroad, and separate regulations came into force giving a short grace period — a warning instead of a fine — for brand-new obligations. A guideline applying privacy law to artificial intelligence, including a requirement of consent before scraping the web to train models, is also in play. Watch three switches the government can flip without warning.Medium confidence
- Hardest industry wall
- Health and social care — חוזרי מנכ"ל משרד הבריאות 1/2018 ו-2/2018 - שימושים משניים במידע בריאות
- Government — פרויקט נימבוס - מדיניות הענן הממשלתית
ArgentinaChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Active
- In one paragraph
- Argentina lets personal data leave the country, but only on paper terms it sets. You either send it to a country the regulator has approved, or you sign the regulator's own model contract with the receiver. No industry has to keep data inside Argentina. Fines are tiny in dollars, but the regulator can order a database shut down, and some misuse is a crime.
- The catch
- There is no data-residency wall in Argentina, but four sector rules still catch people out. Banks and payment firms must run their technology and security management from inside Argentina, must tell the banking supervisor before they outsource, and must report a cyber incident within one hour. Government bodies must have a working backup data centre by late 2026. And nobody may publish a map showing Argentine territory without the national mapping agency's prior approval.
- Does this apply to me?
- The main privacy law is Ley 25.326, passed in 2000. It covers personal data held in any file or database in Argentina, public or private. There is no size threshold, no revenue threshold, and no duty to appoint a local representative. The law does not clearly say it reaches a foreign company with no presence in Argentina, and in practice the regulator has acted against local subsidiaries of global firms rather than against foreign entities directly.High confidence
- Can the data leave the country?
- Yes, with paperwork. The rule is that personal data may not go to a country that does not protect it well enough. The regulator publishes a list of countries it accepts, and for everywhere else you sign its model contract with the receiver. We looked for industries that must keep data inside Argentina - banking, payments, insurance, securities, health, telecoms, government cloud and mapping - and found none as of 18 August 2026.High confidence
- What do I have to do to send it abroad?
- The model is an approved-destinations list, and it is populated today with about a dozen places, including the whole European Union. If your destination is not on it, use the regulator's published model contract - two versions, one for handing data to another company that decides how to use it and one for a supplier processing it for you. Using the published wording needs no permission. If you change the wording, you must file the contract with the regulator within 30 days of signing.High confidence
- Who enforces this — and are they actually working?
- The Agency for Access to Public Information, known by its Spanish initials AAIP, enforces both privacy and freedom of information. It is real and working: it has a named head, it publishes a register of final penalties that was updated on 3 July 2026, it opened a public investigation into debt-collection calls in April 2026, and it chaired an international data-protection committee in July 2026. Its 244 final penalties are mostly small, and more than half are for calling people on the do-not-call list.High confidence
- How long must I keep it, and when must I delete it?
- Argentina has strong floors and one hard ceiling. Anti-money-laundering rules make banks, insurers, crypto firms, accountants and estate agents keep transaction records and customer files for at least ten years. Clinical records must be kept ten years from the last entry. Banks must keep audit and accounting support data six years and produce it immediately on demand. The ceiling: credit-reporting data may only show the last five years, dropping to two years once the debt is paid.High confidence
- What happens when something goes wrong?
- There is no general duty to report a data breach in Argentina, checked on 18 August 2026 - the privacy law has no deadline and the regulator's security rules are recommendations, not commands. Finance is the exception and the clock is brutal: banks and registered payment firms must tell the banking supervisor within one hour of an incident happening or being spotted, keep sending updates, and file a closing report within five days.High confidence
- What's the trap?
- Five things bite people. Answer times are very short: ten days for an access request and five working days to correct or delete. The maximum fine is one hundred thousand pesos, about seventy US dollars, so the real risk is a shutdown order or a criminal case, not the fine. Databases still have to be registered. Publishing a map of Argentina needs government approval first. And a bank cannot run its technology and security management from abroad.High confidence
- What's about to change?
- Nothing is scheduled to replace the privacy law. A reform bill went to Congress in 2023 and never became law; the regulator is still campaigning for a new one. The dated thing to watch is government cybersecurity: public bodies have about 180 days from 13 May 2026 to have contingency plans and a working alternative data centre, which lands around November 2026, and a new national cybersecurity centre started issuing rules in 2026.Medium confidence
- Hardest industry wall
- None found.