Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
IsraelChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Israeli data can go abroad, but never by default. Either the destination country protects data as well as Israel does, or you fit one of eight listed exceptions — usually a contract in which the receiver promises to follow Israeli rules. A big reform started on 14 August 2025 and the regulator now issues real fines. No industry bans exports outright, but several add heavy conditions.
- The catch
- The general answer is 'yes, with paperwork'. It stops being true in four places. Banks may not put sensitive customer data on a cloud outside Israel unless they have checked the provider meets European-level protection. Insurers and pension bodies must report every offshore outsourcing arrangement to their regulator each year. Identifiable patient data used for research must generally stay inside the hospital or health fund that holds it, not merely inside Israel. And central government has moved its own cloud into Israeli data-centre regions on purpose, so selling cloud to the state effectively requires an Israeli region.
- Does this apply to me?
- Yes, it can reach a foreign company with no office in Israel — but the law never says so in words. Israeli privacy law simply applies to anyone who collects, uses or processes personal data, with no size or revenue threshold to fall under. There is no general requirement to appoint a local representative. Some organisations must appoint a privacy officer, and that person is allowed to be an outside contractor rather than a staff member.Medium confidence
- Can the data leave the country?
- Yes, with paperwork — and you must be able to name the route you are using. The default rule is that data may only go to a country whose law protects it at least as well as Israeli law does. If the destination fails that test, you have to fit one of eight listed exceptions, and whichever route you take you also need a written promise from the receiver. No Israeli industry has a flat 'the data stays here' rule, but four sectors bolt extra conditions on top.High confidence
- What do I have to do to send it abroad?
- The model is closest to an allowlist: you may not send data out unless the destination qualifies, and the qualifying list is already populated. It counts if the country signed the Council of Europe data protection convention, or if it receives data from European Union countries on the same terms — so Europe's approved-country list does much of the work. If your destination does not qualify, the usual fallback is a contract in which the receiver promises to meet Israeli standards. Either way you also need a separate written promise from the receiver that it will protect the data and pass it to nobody else.High confidence
- Who enforces this — and are they actually working?
- The Privacy Protection Authority, part of the Ministry of Justice, and it is fully operational. It has a serving commissioner, an administrative enforcement department, and it publishes its decisions with names and amounts. In 2026 it fined a national health fund about 256,000 shekels (roughly $72,000) for taking two months to report a security incident, and a small leisure company about 12,000 shekels (roughly $3,400) for a defective privacy notice. Industry regulators — the Bank of Israel, the insurance regulator and the Ministry of Health — enforce their own rules separately.High confidence
- How long must I keep it, and when must I delete it?
- There is a clear floor and a clear ceiling, and they sit close together. The floor: security and access-monitoring records must be kept for at least 24 months, and organisations with medium or high security databases must keep a restorable backup of them. The ceiling: if a database contains anything that came from Europe, you must run a mechanism that finds data you no longer need and delete it, and you must delete data on request. Where another law says you must keep something, that wins over the duty to delete.High confidence
- What happens when something goes wrong?
- There is one main clock and it has no hours attached to it: a severe security incident must be reported to the Privacy Protection Authority immediately, along with what you did about it. 'Immediately' is taken literally — a health fund was fined for a two-month delay. Telling the affected people is not automatic; the Authority decides, after consulting the national cyber agency, and can order you to notify them. Israel has no general law forcing every company to report cyber incidents to the state, so your second clock, if you have one, comes from your industry regulator.High confidence
- What's the trap?
- Five things that are not in the summary. One: a single record that arrived from Europe drags the whole database into the stricter European rules — since 1 January 2025 those rules apply to any other data sitting in the same database. Two: 'immediately' really means immediately, and there is no safe 72-hour habit to fall back on. Three: fines are calculated per person, not as a flat cap, so a large database turns a small breach into a very large bill. Four: privacy breaches are criminal offences, not just regulatory ones, with prison terms attached. Five: 'data security officer' and 'data protection officer' are two different Israeli roles with different triggers, and having one does not satisfy the other.High confidence
- What's about to change?
- The big change already happened on 14 August 2025. What is landing now is the detail underneath it. In April 2026 the regulator finalised its binding rules on the contract you must sign before sending data abroad, and separate regulations came into force giving a short grace period — a warning instead of a fine — for brand-new obligations. A guideline applying privacy law to artificial intelligence, including a requirement of consent before scraping the web to train models, is also in play. Watch three switches the government can flip without warning.Medium confidence
- Hardest industry wall
- Health and social care — חוזרי מנכ"ל משרד הבריאות 1/2018 ו-2/2018 - שימושים משניים במידע בריאות
- Government — פרויקט נימבוס - מדיניות הענן הממשלתית
IndonesiaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Waking up
- In one paragraph
- Indonesia's general privacy law lets data leave if the destination protects it about as well as Indonesia does, or you use strong safeguards, or the person agrees. Money and health are walled off. Banks, payment firms, insurers and non-bank lenders must run their systems on Indonesian soil unless the financial regulator says otherwise, and medical records must sit with a local storage provider.
- The catch
- The relaxed headline is true only until you touch banking, payments, insurance and other non-bank finance, electronic medical records, or public-sector systems. In those areas the servers themselves must be in Indonesia, and moving them out needs a written permission that the banking regulator may take three months to grant. The general privacy watchdog looks quiet; the financial regulators are not.
- Does this apply to me?
- Yes. The privacy law follows the data, not the office. It covers any organisation, inside or outside Indonesia, whose handling of personal data has legal effects in Indonesia or affects people in Indonesia. There is no size or revenue cut-off to fall below. An organisation with no presence in the country is expected to name a representative in Indonesia, and any online service used by Indonesians is also expected to register with the digital ministry, which can order internet providers to block services that do not.Medium confidence
- Can the data leave the country?
- In general yes, with homework. You must be able to show the destination protects personal data at a level at least equal to Indonesia's, or put binding safeguards in place, or get the person's clear agreement. That general answer stops at the door of finance, health and government. Banks, payment providers, insurers and other non-bank financial firms must keep their systems in Indonesian data centres and back-up centres, and can only go offshore with written regulator permission. Electronic medical records must be stored with a provider that has storage facilities inside Indonesia.High confidence
- What do I have to do to send it abroad?
- There is no published list of approved countries and no official standard contract to sign. Under the general law you assess the destination yourself, write down why it is safe enough, and keep that evidence. In finance the model is completely different: you need a real permission from the regulator before the systems move, and the banking regulator allows itself up to three months to answer once your paperwork is complete.Medium confidence
- Who enforces this — and are they actually working?
- It depends which rule you break. The privacy law's own watchdog is the weak spot: the law says a supervisory body must be set up by the President, and we found no government source showing it is staffed and issuing decisions as of 18 August 2026. Day to day the digital ministry handles complaints, registration and blocking. The financial regulators are a different story — the Financial Services Authority and the central bank are plainly working, and the Authority issued new binding rules as recently as July 2026.Medium confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling and they collide. The hardest floor is health: a hospital or clinic must keep an electronic medical record for at least 25 years after the patient's last visit. Company and tax paperwork must also be kept for years. The ceiling comes from the privacy law, which says personal data must be erased once the purpose is finished, the retention period ends, or the person withdraws consent. Where they clash, the specific keeping rule wins, so a patient asking for deletion does not defeat the 25-year rule.High confidence
- What happens when something goes wrong?
- Count at least three clocks, and the privacy one is not the fastest. Under the privacy law you have 72 hours to tell the affected people and the regulator about a personal data breach. If you are a bank, you must send the financial regulator a first alert within 24 hours of learning about a serious technology incident, and a full incident report within five working days. Other financial firms, such as insurers and lenders, have five working days. Miss the 24-hour one and the fact that you met the 72-hour one will not help you.High confidence
- What's the trap?
- Five things that ruin weekends. (1) In finance the wall is a permission, not a contract — moving systems abroad needs a regulator licence and the banking regulator gives itself up to three months to decide, so cloud migrations must be planned around that. (2) In health your cloud provider must have storage facilities in Indonesia, and the Ministry of Health can demand access to the whole medical record. (3) The 25-year medical record rule beats a patient's deletion request. (4) The privacy law carries prison sentences, not just fines, so directors are personally exposed. (5) A foreign company with no office still needs a named representative in Indonesia, and a consumer service that is not registered with the digital ministry can be blocked at the internet level.Medium confidence
- What's about to change?
- One dated change is certain: from 1 September 2026 trading in digital financial assets, including crypto, runs under the financial regulator's new rulebook, so anyone in that business should re-check where its servers and records must sit. Two things are still pending as far as we could verify: the detailed implementing regulation under the privacy law, and the presidential decision setting up the privacy watchdog itself. Both could land without warning.Medium confidence
- Hardest industry wall
- Banking — Peraturan Otoritas Jasa Keuangan Nomor 11/POJK.03/2022 tentang Penyelenggaraan Teknologi Informasi oleh Bank Umum
- Payments — Peraturan Bank Indonesia Nomor 23/6/PBI/2021 tentang Penyedia Jasa Pembayaran
- Insurance — Peraturan Otoritas Jasa Keuangan Nomor 4/POJK.05/2021 tentang Penerapan Manajemen Risiko dalam Penggunaan Teknologi Informasi oleh Lembaga Jasa Keuangan Nonbank
- Health and social care — Peraturan Menteri Kesehatan Nomor 24 Tahun 2022 tentang Rekam Medis
- Government — Peraturan Pemerintah Nomor 71 Tahun 2019 tentang Penyelenggaraan Sistem dan Transaksi Elektronik
- Mapping and location — Undang-Undang Nomor 4 Tahun 2011 tentang Informasi Geospasial