Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
JapanChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Active
In one paragraph
Japan lets personal data leave the country, but you need paperwork. Only Europe and the United Kingdom are pre-approved. For anywhere else you either sign a contract that binds the recipient to Japanese-standard protection, or you get the person's consent after telling them which country the data goes to. There is no general rule forcing data to stay in Japan.
The catch
Two things break the calm headline. If you sell to the Japanese government, the data must physically sit in Japanese data centres. And if you run a website, an app or any online service used from Japan, the telecoms law reaches you even with no office here, requires a representative in Japan, and makes leaking a communication a criminal offence rather than a fine.
Does this apply to me?
Yes. Japan's privacy law reaches a foreign company with no office and no staff in Japan, as long as it handles the personal information of people in Japan while supplying them goods or services. There is no size, revenue or headcount threshold to fall below. Unlike Europe, the privacy law does not make you appoint a representative in Japan — but the telecoms law does, if your service counts as a telecommunications service.High confidence
Can the data leave the country?
Yes, with paperwork. Japan's general rating is conditional: personal data may go abroad once you have one of three things in place. There is no across-the-board law keeping data in Japan, and no financial, insurance, securities or health localisation rule of the kind India or China have — we searched for one and did not find it. The real wall is government work: anything running on the national Government Cloud must sit in data centres inside Japan.High confidence
What do I have to do to send it abroad?
The model is an allowlist, and the list has exactly two entries: the European Union and the United Kingdom. Send data there and it is treated almost like a domestic transfer. For every other destination you need one of two things instead. Either the recipient is contractually bound to protect the data to Japanese standards and you keep checking that it does, or you get the person's consent after first telling them the destination country, what its privacy law is like, and what the recipient will do to protect the data.High confidence
Who enforces this — and are they actually working?
The Personal Information Protection Commission, and it is genuinely working. It has a chair, eight commissioners and a staff ceiling of 231 people. In the year to March 2025 it handled just over 19,000 breach reports, gave 395 pieces of formal guidance and made one recommendation. In the first six months of the following year it sharpened up: two recommendations and its first emergency order, against a company misusing personal information. What it cannot do yet is fine you — Japan has no administrative money penalty for privacy breaches until the 2026 amendment starts.High confidence
How long must I keep it, and when must I delete it?
The floor is firm and the ceiling is soft. Tax law makes you keep books and records for seven years, stretching to ten if you carry a loss forward. Company accounting books run ten years. Against that, the privacy law only asks you to try to delete personal data once you no longer need it — it is a best-efforts duty, not a hard deadline. So when the two collide, the keep-it rule wins in practice.Medium confidence
What happens when something goes wrong?
Count three clocks. For a personal data breach you file a first report to the privacy regulator within three to five days of finding out, and a full report within 30 days — 60 days if someone did it on purpose. You must also tell the people affected. Critical infrastructure operators have a separate cyber incident duty with a report to the government within 30 days. Telecoms operators report leaks of communications to the communications ministry on their own timetable.High confidence
What's the trap?
Five. (1) Putting data on a foreign server is often not a 'transfer' at all — if the provider is contractually barred from touching it — but you then have to work out that country's privacy law and publish the country's name to your users. Most people miss this. (2) The privacy law has no fines: the sanctions are criminal, and a company can be fined about $650,000 for a staff member stealing a customer database. (3) Leaking a communication is a crime punishable with prison, and telecoms staff face a longer term than outsiders. (4) The telecoms rules catch ordinary websites and apps, not just phone companies, and reach foreign operators with no office in Japan. (5) Consent to send data 'overseas' is not valid — you have to name the country.High confidence
What's about to change?
The big one has already passed. On 17 July 2026 Japan published a large amendment to its privacy law. It introduces the country's first money penalty for privacy breaches, sets 16 as the age below which a guardian must be involved, adds rules for face and other biometric data, and raises the criminal penalties. It is not in force yet: the government has up to two years to switch it on by order, and no date has been announced. The other thing to watch is the new cyber defence law, which is being switched on in stages through 2027.High confidence
Hardest industry wall
  • Government デジタル庁におけるガバメントクラウド等の整備のためのクラウドサービスの提供 — 令和8年度募集 調達仕様書
SlovakiaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Slovakia has no general rule that data must stay in the country. It runs on the European rulebook: send data abroad once you have the right paperwork. Three areas break that rule. Online gambling servers must sit on Slovak soil. The most sensitive government data must stay in a Slovak data centre. And anyone who takes aerial survey pictures of Slovakia must hand a copy to a defence ministry archive.
The catch
The easy answer stops being true in three places. First, online gambling: the operator's server must be physically in Slovakia, with no European Economic Area alternative. Second, government cloud: a public body handling the top security category of data may only use a service that stores and processes it inside Slovakia, in a data centre within reach of the Slovak state. Third, mapping: primary aerial survey imagery and published maps must be deposited with Slovak state archives, including one run by the Ministry of Defence. Banking, payments, insurance, securities, health and telecoms have no storage-location rule that we could find.
Does this apply to me?
Yes. A company with no office in Slovakia is still caught if it offers goods or services to people in Slovakia, or watches what they do online. There is no minimum size, headcount or revenue below which you are safe. If you have no office anywhere in the European Union, you must name a written representative inside the Union, and you can put that person in any member state where your customers are — it does not have to be Slovakia.High confidence
Can the data leave the country?
In general, yes — with the standard European paperwork. Nothing in Slovak law says personal data must be kept in Slovakia, and the law says so almost in as many words: it applies to a Slovak company whether it processes data inside or outside the country. But three specific activities do force data to stay. Online gambling operators must put their server in Slovakia. The top security tier of government data must stay in a Slovak data centre. And aerial survey imagery of Slovakia must be handed to a state archive.High confidence
What do I have to do to send it abroad?
Slovakia uses the European model, and it is an allowlist. Data may go to a country the European Commission has approved, or to anywhere else if you sign the Commission's standard contract, use approved group-wide rules, or fit one of a few narrow exceptions. The approved list is real and populated — it includes the United Kingdom, Switzerland, Japan, South Korea, Canada for commercial bodies, and the United States only for companies signed up to the transatlantic framework. Slovakia adds nothing of its own on top.High confidence
Who enforces this — and are they actually working?
The Office for Personal Data Protection of the Slovak Republic. It is real, staffed and busy. In 2025 it issued 542 final fines totalling about 468,000 euros (roughly $510,000) and actually collected about 411,000 euros of that — a very high number of fines but a very small average, about 860 euros each. It has around 60 staff and got 20 extra posts in 2025. Cybersecurity incidents go to a separate body, the National Security Authority.High confidence
How long must I keep it, and when must I delete it?
There is no single retention rule. The general privacy rule is to delete when you no longer need the data. Against that sit long minimum-keeping duties: ten years for accounts and financial statements, and up to one hundred years after death for entries in the national health registers. Telecom companies keep far less than most people assume — Slovakia scrapped blanket call-record retention after its Constitutional Court struck it down, so operators only retain what a court order covers.High confidence
What happens when something goes wrong?
There are two clocks and they are different. A personal data breach goes to the privacy authority within 72 hours of you becoming aware of it, and to the affected people without undue delay if the risk to them is high. A cybersecurity incident at a regulated organisation goes to the National Security Authority twice: a first warning within 24 hours, then a fuller report within 72 hours. If you are both, you file both, to two different bodies.High confidence
What's the trap?
Five things that are not in the summary. Public bodies can be fined the full amount, with no discount. Mishandling personal data you got through your job is a crime, not just a fine. The age of consent for online services is 16, not 13. The rule on dead people's data changed today. And the gambling server rule has no European workaround.High confidence
What's about to change?
The whole national privacy law is being replaced by two new laws — one general, one for police and courts — but they are still bills and have no legal effect. Act 18/2018 was amended today, 18 August 2026, mostly to remove dead people from its scope. Public bodies face a bigger data-registration duty from 1 January 2027, and all cloud switching and data export fees across Europe must drop to zero by 12 January 2027.High confidence
Hardest industry wall
  • Online gaming Zákon č. 30/2019 Z. z. o hazardných hrách a o zmene a doplnení niektorých zákonov, § 14 ods. 21 a 22
  • Government Metodické usmernenie č. 020775/2025/oSBATA z 11. 4. 2025 pre proces zaradenia cloudovej služby do katalógu vládnych cloudových služieb, vydané podľa § 24a zákona č. 95/2019 Z. z.
  • Mapping and location Zákon Národnej rady Slovenskej republiky č. 215/1995 Z. z. o geodézii a kartografii