Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
KenyaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Kenya has a real privacy law and a regulator that genuinely works. Data may leave the country, but only if you can show the destination protects it about as well as Kenya does, or the person has clearly agreed. Some data must stay: anything used for identity records, elections, public money, basic schooling or front-line health care needs at least one live copy on a server inside Kenya.
The catch
The relaxed answer stops at the edge of six activities: birth and identity records, running elections, public finance systems, computer systems the government has formally declared protected, early-years and basic education, and primary and secondary health care. In those six, a working copy of the data must sit on a server inside Kenya. The privacy regulator also reads the 'protected computer systems' category as covering most telephone and internet providers, which drags ordinary private companies into a rule that was written for the state.
Does this apply to me?
Yes. The law reaches a company with no office and no staff in Kenya, as long as it handles the data of people who are in Kenya. There is no revenue or headcount level that gets you out of the law itself. Size only decides whether you must also put your name on the regulator's public register: you can skip registering if you turn over less than five million Kenyan shillings a year (roughly 38,000 US dollars) and employ fewer than ten people. That let-off disappears if you work in one of twelve listed activities, which include gambling, financial services, telephone and internet services, health, education, transport, direct marketing and anything involving genetic data. Kenya does not make you appoint a local representative.High confidence
Can the data leave the country?
Mostly yes, with homework — and then six hard exceptions. In general you may send personal data abroad if you can show the recipient is bound to protect it about as well as Kenya does, or the person has said yes after being told the risks. Sensitive data, such as health or biometric records, needs that explicit yes. But if you process data for identity and civil registration, elections, public finance systems, systems the government has declared protected, early-years and basic schooling, or primary and secondary health care, then a working copy has to live on a server inside Kenya. You can still hold a second copy abroad. Kenya's telephone and internet regulator sector is pulled in through the 'protected systems' door.High confidence
What do I have to do to send it abroad?
There are four ways to make a transfer lawful, and you pick one yourself. First, appropriate safeguards: a binding legal document that gives the data protection essentially equal to Kenya's. Second, a decision by the Data Commissioner that the destination country is safe enough — no such decision has been published that we could find. Third, necessity, for a short list of purposes. Fourth, the person's explicit consent after being warned of the risks. Sensitive data can only go on consent. There is no government-issued contract template to copy, no approval to apply for, and no filing to make — but you must write the transfer down and hand the paperwork to the regulator if asked.High confidence
Who enforces this — and are they actually working?
The Office of the Data Protection Commissioner, and yes, it really works. This is not a paper regulator. In 2026 alone it has published twenty-two decisions naming the companies involved, covering hospitals, schools, lenders, insurance brokers, a water utility and a savings cooperative. In one April 2026 decision it found a microfinance bank liable, ordered the data deleted within fourteen days, and recommended that the company's directors be prosecuted for obstructing the Commissioner. The office also runs a public register of registered organisations with hundreds of entries and took an international quality certification in July 2026. Money penalties are capped low, so orders and criminal referrals do more of the work than fines.High confidence
How long must I keep it, and when must I delete it?
Kenya sets a firm ceiling and almost no floor. The ceiling: you may keep personal data only for as long as it is genuinely needed, and once the purpose is finished you must delete it, or strip out the names, or scramble the identifiers. The regulator expects you to have a written retention timetable, review it regularly, and be able to justify every period you have chosen — keeping something 'just in case' is specifically called out as not good enough. The privacy law itself sets no minimum keeping periods. Those come from tax, company and sector rules outside this law, and we could not verify them from a government source in this run, so treat any minimum you rely on as unchecked.Medium confidence
What happens when something goes wrong?
Three clocks, and the shortest one is easy to miss. If you are the organisation that decided how the data is used, you must tell the Data Commissioner without delay and in any case within seventy-two hours of becoming aware of the breach. If you are a supplier processing data for someone else, you have only forty-eight hours to tell your customer — so a supplier who waits for the customer's process has already blown the deadline. You must also tell the affected people, within a reasonably practical period rather than a fixed number of hours. Separately, the national cyber crime body runs an online incident reporting portal; we found no published deadline attached to it.High confidence
What's the trap?
Five things that are not in the summary. One: a child is anyone under eighteen, you need a parent's verifiable consent, and profiling a child for marketing is banned outright — plus you must build age checks. Two: this is criminal law, not just fines. The regulator has recommended prosecuting company directors, and offences carry up to ten years in prison. Three: registration is a licence in disguise — a certificate lasting twenty-four months, with fees, and twelve listed activities that lose the small-business exemption. Four: for sensitive data such as health or biometrics, a good contract is not enough to send it abroad; you need the person's explicit consent. Five: the localisation rule was written for the state but the regulator reads it as catching most telephone and internet companies.High confidence
What's about to change?
One thing is landing now and three switches could flip at any time. Landing: the regulator put out three draft guidance notes in July 2026, on artificial intelligence, on emerging technologies, and on privacy-enhancing technologies. Comments closed on the seventeenth of August 2026, so final versions are due imminently. The artificial intelligence draft would require organisations to register, to run risk assessments before high-risk uses, to keep humans in the loop on serious automated decisions, and to document how well any country they send data to protects it. The three switches are described below and none of them needs a new law.High confidence
Hardest industry wall
  • Government The Data Protection (General) Regulations, 2021, regulation 26 — requirement for specified processing to be done in Kenya
  • Health and social care ODPC Guidance Note on the Processing of Health Data, read with regulation 26 of the Data Protection (General) Regulations, 2021
  • Telecoms ODPC Guidance Note for the Communication Sector, applying regulation 26 through the 'protected computer system' definition in the Computer Misuse and Cybercrimes Act, 2018
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
The catch
The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
Does this apply to me?
Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
Can the data leave the country?
Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
What do I have to do to send it abroad?
The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
Who enforces this — and are they actually working?
The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
What happens when something goes wrong?
There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
What's the trap?
Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
What's about to change?
Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
Hardest industry wall
  • Telecoms Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
  • E-commerce Loi n° 18-05 relative au commerce electronique
  • Government Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees