Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
IcelandChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Iceland follows Europe's privacy rulebook, so personal data can leave the country once the right paperwork is in place. Two local rules surprise people: a company's accounting records must physically be kept in Iceland, and health record systems can only be hosted by a certified provider. The privacy regulator is small but genuinely busy, and it fines public bodies too.
The catch
The relaxed answer is true for personal data only. Iceland's bookkeeping law says a company's books, invoices and receipts must be kept in Iceland for seven years, and only lets you hold them abroad for up to six months — and breaking the bookkeeping law is a crime, not a fine from the privacy regulator. Health record hosting has its own certification wall. Separately, three European laws that people assume apply here — the Data Act, the cybersecurity law known as NIS2, and the Artificial Intelligence Act — have NOT yet been brought into Icelandic law, so the rights and deadlines they create do not exist in Iceland today.
Does this apply to me?
Yes, it reaches you with no office in Iceland. Iceland applies Europe's General Data Protection Regulation through the European Economic Area agreement, so the rules cover any organisation anywhere in the world that offers goods or services to people in Iceland, or that watches what they do. There is no size or revenue threshold to duck under. If your organisation has no establishment anywhere in Europe, you normally have to name a representative inside Europe who people and the regulator can contact.High confidence
Can the data leave the country?
For personal data, yes — it can leave once you have the right paperwork. Two Icelandic rules cut across that headline. First, your company's accounting books, invoices and receipts must be kept in Iceland for seven years; the law only lets you hold them abroad for up to six months. Second, a health record system can sit with an outside host only if that host holds a recognised security certificate and the normal rules for sending data out of Europe are met.Medium confidence
What do I have to do to send it abroad?
You use one of the standard European routes. Send the data to a country Europe has officially approved, or sign the European Commission's standard contract with the recipient, or use group-wide rules a regulator has approved. Narrow one-off exceptions exist, such as the person's explicit consent, but they are not for routine or bulk transfers. One Icelandic wrinkle catches people out: an approval of a foreign country only takes effect in Iceland once the Icelandic minister confirms it and publishes a notice in the official gazette.Medium confidence
Who enforces this — and are they actually working?
Persónuvernd, the Icelandic Data Protection Authority. It is genuinely operational, not a name on paper: it registered 2,124 new cases in 2025 and closed 2,232, it opens its own investigations without waiting for a complaint, and it fines public bodies as well as private companies. It is also small — about 17 staff and a budget of roughly 379 million krónur (about $2.8 million) — and it says in its own annual report that it cannot cover every task the law gives it.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and they point in opposite directions. The floor: accounting books, invoices and receipts must be kept for seven years — and kept in Iceland. The ceiling: under the European rules you must delete personal data once you no longer need it for the purpose you collected it for. When the two clash, the keeping duty wins; a person cannot force you to delete records the bookkeeping and tax law requires you to hold.High confidence
What happens when something goes wrong?
Count at least two clocks, and three if you are a financial firm. You have 72 hours to report a personal data breach to Persónuvernd, and you must tell the people affected without delay where the risk to them is high. Separately, operators of critical services — banks, hospitals, energy, water, transport and digital infrastructure — must alert Iceland's national cyber security team as soon as possible under a 2019 law, and serious breaches of that law can lead to prosecution. Financial firms have a further, tighter reporting duty to the Central Bank under the European operational resilience rules.Medium confidence
What's the trap?
Five things that are not in the summary. (1) A child in Iceland is anyone under 13 for online consent, not 16 as in much of Europe — so a design built for a 16-year-old threshold is wrong here. (2) Your accounting records must sit in Iceland, and bookkeeping offences are criminal: fines, and up to six years in prison for serious cases, investigated by the district prosecutor and the tax investigators, not by the privacy regulator. (3) Public bodies can be fined in Iceland — the law says so expressly, unlike several European countries. (4) Some processing needs a licence from Persónuvernd before you start, which is unusual under the European regime. (5) Three European laws you may assume apply here do not yet: the Data Act, the cybersecurity law known as NIS2, and the Artificial Intelligence Act have not been brought into the European Economic Area agreement.High confidence
What's about to change?
The main thing to watch is not an Icelandic bill but the queue of European laws waiting to be pulled into Icelandic law. The Data Act, the cybersecurity law known as NIS2 and the Artificial Intelligence Act are all still outside the European Economic Area agreement as of 18 August 2026, and each will land when a joint committee decides — with no Icelandic public consultation and often at short notice. The financial resilience regulation already landed this way on 1 July 2025, more than five months after it started applying in the European Union.High confidence
Hardest industry wall
  • All industries Lög um bókhald
UkraineChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
In one paragraph
Ukraine still runs its 2010 privacy law, not a European-style one. Personal data may leave the country only to a country the law treats as safe — that means Europe and the 50-odd countries that signed a Council of Europe data treaty. The United States is not on that list. Fines are tiny, but the human rights Commissioner really does inspect, and misusing data can be a crime.
The catch
The general picture changes completely once government is involved. If a Ukrainian state body is the organisation deciding how personal data is used, only a Ukrainian state-owned or municipal company may process that data for it — a private or foreign supplier cannot. State systems, defence data and critical infrastructure also carry hard location rules, and several of the current permissions exist only because the country is under martial law.
Does this apply to me?
Probably not, if you have nothing in Ukraine. The 2010 law simply says it covers the processing of personal data by automated means or in structured paper files. It contains no clause reaching foreign companies that only sell into Ukraine from abroad, and it does not make you appoint a local representative. There is no size or revenue threshold either — a corner shop and a bank are treated the same.Medium confidence
Can the data leave the country?
Yes, but only to countries Ukraine already treats as safe. Those are the European Economic Area countries plus every country that has signed the Council of Europe's data protection treaty — roughly 55 states. The United States has signed neither, so routine transfers to American servers do not fit the safe-country route and need one of the narrow exceptions instead. Whole sectors then override this: government, defence and critical infrastructure are far tighter, and securities firms are unusually looser.High confidence
What do I have to do to send it abroad?
There is no form to file and no government permission to obtain. You either send the data to a country the law already treats as safe, or you rely on one of five narrow exceptions. Those are: the person's clear consent, necessity for a contract made for that person's benefit, protecting someone's life, an important public interest or a legal claim, and the sender giving guarantees that private and family life will not be interfered with. That last one is a catch-all that a lot of Ukrainian practice leans on.High confidence
Who enforces this — and are they actually working?
The Ukrainian Parliament Commissioner for Human Rights — the national ombudsman — is the data protection regulator, and it is genuinely working. It publishes a fresh inspection programme every three months; the one for July to September 2026 went up on 2 July 2026. It also publishes what it found, including a run of checks on the national electronic health system. The catch is the money: the regulator cannot fine anyone itself, it writes up a case and sends it to a court, and the maximum penalty is about $800.High confidence
How long must I keep it, and when must I delete it?
The floor comes from tax law. Companies must keep primary accounting documents and financial statements for 1,825 days — five years. Papers needed for transfer pricing checks run to 2,555 days, which is seven years. Everything else the tax authority may ask for runs 1,095 days, three years. The ceiling comes from the privacy law: you must delete personal data when the agreed storage period runs out, or when your relationship with the person ends, unless another law tells you to keep it.High confidence
What happens when something goes wrong?
This is the biggest surprise in Ukrainian law: if you lose personal data, there is no duty to tell the regulator and no duty to tell the people affected. The 2010 privacy law simply has no breach reporting clause. The only mandatory clocks sit in the cyber security regime, and they only bite if you run a state system or a piece of critical information infrastructure. Even there the law does not set the hours — it leaves the deadline to an order of the cyber agency.Medium confidence
What's the trap?
Five. (1) If a Ukrainian government body is the one deciding how personal data is used, only a Ukrainian state-owned or municipal company may handle that data for it — a private or foreign supplier is not allowed at all. (2) Misusing personal data is a crime, not just a fine, and repeat offences carry up to five years in prison. (3) The fines are aimed at named individuals and sole traders, not at companies. (4) Posting anything that shows where Ukrainian troops are carries five to eight years in prison. (5) Martial law lets the government limit the constitutional right to privacy that the whole system rests on.High confidence
What's about to change?
The date to watch is not a new law — it is the end of the war. Martial law was extended again on 13 July 2026 and now runs from 2 August 2026 for 90 days, so to about 31 October 2026. Several of today's permissions exist only while it lasts, and they die six months after it ends. A European-style replacement privacy law has been discussed for years and has still not been passed, so nothing about the current regime should be planned around its arrival.High confidence
Hardest industry wall
  • Government Закон України "Про захист персональних даних", частина третя статті 4
  • Government Закон України "Про захист інформації в інформаційно-комунікаційних системах"
  • Defence Закон України "Про хмарні послуги"
  • Mapping and location Кримінальний кодекс України, стаття 114-2