Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
IsraelChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
In one paragraph
Israeli data can go abroad, but never by default. Either the destination country protects data as well as Israel does, or you fit one of eight listed exceptions — usually a contract in which the receiver promises to follow Israeli rules. A big reform started on 14 August 2025 and the regulator now issues real fines. No industry bans exports outright, but several add heavy conditions.
The catch
The general answer is 'yes, with paperwork'. It stops being true in four places. Banks may not put sensitive customer data on a cloud outside Israel unless they have checked the provider meets European-level protection. Insurers and pension bodies must report every offshore outsourcing arrangement to their regulator each year. Identifiable patient data used for research must generally stay inside the hospital or health fund that holds it, not merely inside Israel. And central government has moved its own cloud into Israeli data-centre regions on purpose, so selling cloud to the state effectively requires an Israeli region.
Does this apply to me?
Yes, it can reach a foreign company with no office in Israel — but the law never says so in words. Israeli privacy law simply applies to anyone who collects, uses or processes personal data, with no size or revenue threshold to fall under. There is no general requirement to appoint a local representative. Some organisations must appoint a privacy officer, and that person is allowed to be an outside contractor rather than a staff member.Medium confidence
Can the data leave the country?
Yes, with paperwork — and you must be able to name the route you are using. The default rule is that data may only go to a country whose law protects it at least as well as Israeli law does. If the destination fails that test, you have to fit one of eight listed exceptions, and whichever route you take you also need a written promise from the receiver. No Israeli industry has a flat 'the data stays here' rule, but four sectors bolt extra conditions on top.High confidence
What do I have to do to send it abroad?
The model is closest to an allowlist: you may not send data out unless the destination qualifies, and the qualifying list is already populated. It counts if the country signed the Council of Europe data protection convention, or if it receives data from European Union countries on the same terms — so Europe's approved-country list does much of the work. If your destination does not qualify, the usual fallback is a contract in which the receiver promises to meet Israeli standards. Either way you also need a separate written promise from the receiver that it will protect the data and pass it to nobody else.High confidence
Who enforces this — and are they actually working?
The Privacy Protection Authority, part of the Ministry of Justice, and it is fully operational. It has a serving commissioner, an administrative enforcement department, and it publishes its decisions with names and amounts. In 2026 it fined a national health fund about 256,000 shekels (roughly $72,000) for taking two months to report a security incident, and a small leisure company about 12,000 shekels (roughly $3,400) for a defective privacy notice. Industry regulators — the Bank of Israel, the insurance regulator and the Ministry of Health — enforce their own rules separately.High confidence
How long must I keep it, and when must I delete it?
There is a clear floor and a clear ceiling, and they sit close together. The floor: security and access-monitoring records must be kept for at least 24 months, and organisations with medium or high security databases must keep a restorable backup of them. The ceiling: if a database contains anything that came from Europe, you must run a mechanism that finds data you no longer need and delete it, and you must delete data on request. Where another law says you must keep something, that wins over the duty to delete.High confidence
What happens when something goes wrong?
There is one main clock and it has no hours attached to it: a severe security incident must be reported to the Privacy Protection Authority immediately, along with what you did about it. 'Immediately' is taken literally — a health fund was fined for a two-month delay. Telling the affected people is not automatic; the Authority decides, after consulting the national cyber agency, and can order you to notify them. Israel has no general law forcing every company to report cyber incidents to the state, so your second clock, if you have one, comes from your industry regulator.High confidence
What's the trap?
Five things that are not in the summary. One: a single record that arrived from Europe drags the whole database into the stricter European rules — since 1 January 2025 those rules apply to any other data sitting in the same database. Two: 'immediately' really means immediately, and there is no safe 72-hour habit to fall back on. Three: fines are calculated per person, not as a flat cap, so a large database turns a small breach into a very large bill. Four: privacy breaches are criminal offences, not just regulatory ones, with prison terms attached. Five: 'data security officer' and 'data protection officer' are two different Israeli roles with different triggers, and having one does not satisfy the other.High confidence
What's about to change?
The big change already happened on 14 August 2025. What is landing now is the detail underneath it. In April 2026 the regulator finalised its binding rules on the contract you must sign before sending data abroad, and separate regulations came into force giving a short grace period — a warning instead of a fine — for brand-new obligations. A guideline applying privacy law to artificial intelligence, including a requirement of consent before scraping the web to train models, is also in play. Watch three switches the government can flip without warning.Medium confidence
Hardest industry wall
  • Health and social care חוזרי מנכ"ל משרד הבריאות 1/2018 ו-2/2018 - שימושים משניים במידע בריאות
  • Government פרויקט נימבוס - מדיניות הענן הממשלתית
UkraineChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
In one paragraph
Ukraine still runs its 2010 privacy law, not a European-style one. Personal data may leave the country only to a country the law treats as safe — that means Europe and the 50-odd countries that signed a Council of Europe data treaty. The United States is not on that list. Fines are tiny, but the human rights Commissioner really does inspect, and misusing data can be a crime.
The catch
The general picture changes completely once government is involved. If a Ukrainian state body is the organisation deciding how personal data is used, only a Ukrainian state-owned or municipal company may process that data for it — a private or foreign supplier cannot. State systems, defence data and critical infrastructure also carry hard location rules, and several of the current permissions exist only because the country is under martial law.
Does this apply to me?
Probably not, if you have nothing in Ukraine. The 2010 law simply says it covers the processing of personal data by automated means or in structured paper files. It contains no clause reaching foreign companies that only sell into Ukraine from abroad, and it does not make you appoint a local representative. There is no size or revenue threshold either — a corner shop and a bank are treated the same.Medium confidence
Can the data leave the country?
Yes, but only to countries Ukraine already treats as safe. Those are the European Economic Area countries plus every country that has signed the Council of Europe's data protection treaty — roughly 55 states. The United States has signed neither, so routine transfers to American servers do not fit the safe-country route and need one of the narrow exceptions instead. Whole sectors then override this: government, defence and critical infrastructure are far tighter, and securities firms are unusually looser.High confidence
What do I have to do to send it abroad?
There is no form to file and no government permission to obtain. You either send the data to a country the law already treats as safe, or you rely on one of five narrow exceptions. Those are: the person's clear consent, necessity for a contract made for that person's benefit, protecting someone's life, an important public interest or a legal claim, and the sender giving guarantees that private and family life will not be interfered with. That last one is a catch-all that a lot of Ukrainian practice leans on.High confidence
Who enforces this — and are they actually working?
The Ukrainian Parliament Commissioner for Human Rights — the national ombudsman — is the data protection regulator, and it is genuinely working. It publishes a fresh inspection programme every three months; the one for July to September 2026 went up on 2 July 2026. It also publishes what it found, including a run of checks on the national electronic health system. The catch is the money: the regulator cannot fine anyone itself, it writes up a case and sends it to a court, and the maximum penalty is about $800.High confidence
How long must I keep it, and when must I delete it?
The floor comes from tax law. Companies must keep primary accounting documents and financial statements for 1,825 days — five years. Papers needed for transfer pricing checks run to 2,555 days, which is seven years. Everything else the tax authority may ask for runs 1,095 days, three years. The ceiling comes from the privacy law: you must delete personal data when the agreed storage period runs out, or when your relationship with the person ends, unless another law tells you to keep it.High confidence
What happens when something goes wrong?
This is the biggest surprise in Ukrainian law: if you lose personal data, there is no duty to tell the regulator and no duty to tell the people affected. The 2010 privacy law simply has no breach reporting clause. The only mandatory clocks sit in the cyber security regime, and they only bite if you run a state system or a piece of critical information infrastructure. Even there the law does not set the hours — it leaves the deadline to an order of the cyber agency.Medium confidence
What's the trap?
Five. (1) If a Ukrainian government body is the one deciding how personal data is used, only a Ukrainian state-owned or municipal company may handle that data for it — a private or foreign supplier is not allowed at all. (2) Misusing personal data is a crime, not just a fine, and repeat offences carry up to five years in prison. (3) The fines are aimed at named individuals and sole traders, not at companies. (4) Posting anything that shows where Ukrainian troops are carries five to eight years in prison. (5) Martial law lets the government limit the constitutional right to privacy that the whole system rests on.High confidence
What's about to change?
The date to watch is not a new law — it is the end of the war. Martial law was extended again on 13 July 2026 and now runs from 2 August 2026 for 90 days, so to about 31 October 2026. Several of today's permissions exist only while it lasts, and they die six months after it ends. A European-style replacement privacy law has been discussed for years and has still not been passed, so nothing about the current regime should be planned around its arrival.High confidence
Hardest industry wall
  • Government Закон України "Про захист персональних даних", частина третя статті 4
  • Government Закон України "Про захист інформації в інформаційно-комунікаційних системах"
  • Defence Закон України "Про хмарні послуги"
  • Mapping and location Кримінальний кодекс України, стаття 114-2