Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
CambodiaChecked 18 August 2026
Depends on your industryWork: LowEnforcement: Dormant
- In one paragraph
- Cambodia has no general privacy law. A bill exists and went to a public review meeting in August 2026, but it is not law and there is no privacy regulator to complain to. For most businesses data can leave the country freely, with no paperwork. Banks and other lenders are the big exception: their main data centre must sit inside Cambodia.
- The catch
- The relaxed headline stops at the door of the financial sector. Any bank or lender supervised by Cambodia's central bank must keep at least one main data centre inside the country, and must get the central bank's permission in advance before customer personal data is moved to or hosted on servers abroad. Telecoms are also watched closely by an active regulator, and a suspended 2021 order that would push all internet traffic through a single government-controlled gateway can be switched back on at any time.
- Does this apply to me?
- There is no general data protection law in Cambodia, so there is nothing for a foreign company to be caught by. No size threshold, no revenue threshold, no registration, and no requirement to appoint someone in Cambodia to answer for your data. That changes the moment you need a local licence: banks, lenders and telecoms operators are licensed here and their licence conditions do reach their overseas systems. A draft privacy law was put to a validation workshop on 5 August 2026 and will proceed through the formal law-making process, so this answer has a shelf life.High confidence
- Can the data leave the country?
- In general, yes, and with nothing to sign. Cambodia has no rule that stops ordinary personal data leaving the country. Finance is the one hard wall we could verify: a bank or lender supervised by the central bank must have at least one main data centre in Cambodia, may only use a foreign data centre as a backup, and needs the central bank's approval before customer personal data is hosted abroad. Telecoms is the sector to watch, because a 2021 order that would route all internet traffic through a single national gateway was never switched on but was never cancelled either.Medium confidence
- What do I have to do to send it abroad?
- For most organisations, nothing at all. There is no approved-countries list, no banned-countries list, no standard contract to sign and no government form to file. The lists are not just empty, they do not exist, because there is no law that creates them. In finance the model is completely different: each move of customer personal data out of Cambodia needs its own approval from the central bank, decided case by case, and there is no published application process or timetable.Medium confidence
- Who enforces this — and are they actually working?
- For privacy, nobody. Cambodia has no data protection authority. The Ministry of Post and Telecommunications is writing the law and, in November 2025, ran a training workshop with Singapore's privacy regulator on how to build such an authority, which tells you plainly that one does not yet exist. Sector regulators are a different story and are genuinely working: the central bank supervises financial firms against its 2026 technology guidelines, and the telecoms regulator publicly named an operator in June 2026 for selling SIM cards without properly checking customers' identity documents.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and almost no ceiling. Tax and accounting law forces businesses to keep books and supporting documents for years, and financial firms must keep system logs and agree retention periods with their cloud providers. In the other direction there is no general rule telling anyone to delete personal data, because there is no privacy law. The only deletion duty we could verify applies to banks and lenders, who must keep customer personal data only as long as it is needed.Medium confidence
- What happens when something goes wrong?
- There is no breach reporting clock in Cambodia. No law requires you to tell a regulator or the affected people when personal data leaks, and there is no national cyber incident hotline with a deadline in hours. The nearest thing is in banking: the central bank tells supervised firms to report incidents as it requires, either on a regular cycle or one-off, with no fixed number of hours. Two draft laws would change this, so treat today's silence as temporary.Medium confidence
- What's the trap?
- Five things that are not in the summary. First, the e-commerce law reportedly bans encryption that would stop evidence being used in a criminal case, which cuts across normal end-to-end encryption promises. Second, a cloud-only bank cannot operate here: the main data centre must physically be in Cambodia. Third, moving customer banking data abroad needs the central bank's permission in advance, and there is no published process or timetable, so it must be planned months ahead. Fourth, telecoms operators must check identity documents before activating a SIM card, and the regulator names offenders in public. Fifth, no privacy law does not mean no risk, because your foreign customers will impose their own rules by contract.Medium confidence
- What's about to change?
- Four drafts are moving and none of them is law yet. The Personal Data Protection Law reached a validation workshop on 5 August 2026 and now heads into the formal law-making process. The Cybersecurity Law was still being argued over with the Ministry of Justice in July 2026. A Data Governance Policy for 2026 to 2035 was in consultation in March 2026 and is expected to cover where data may be stored and how it may cross borders. A Digital Government Law went to consultation in July 2025. No commencement date has been announced for any of them.High confidence
- Hardest industry wall
- Finance — Technology and Cyber Risk Management Guidelines (TCRMG)
ChinaChecked 18 August 2026
Yes, with paperworkWork: Very highEnforcement: Active
- In one paragraph
- Data can leave China, but only through one of three official gates: a government security review, a government-written contract you file with the regulator, or a certificate from an approved body. Which gate you need depends on how many people's data you move, not on where you send it. Small exporters are exempt. Several industries are walled off entirely.
- The catch
- The 'paperwork, then it can go' answer is only true for ordinary companies. Payment firms, credit bureaus, hospitals, genetic labs, online map services, telecom and industrial operators, and anything the government labels critical national infrastructure must keep the data in China. In those areas a copy staying behind is not optional.
- Does this apply to me?
- Yes. China's privacy law reaches a company with no office and no staff in China if it offers goods or services to people in China, or analyses their behaviour. There is no revenue or headcount threshold that lets you out. If you are caught this way, you must set up a dedicated office in China or name a representative there, and give the regulator their details.High confidence
- Can the data leave the country?
- In general yes, once you clear the right gate — but the gate is set by volume, not by destination. China has no list of banned or approved countries. Below 100,000 people a year you can usually send data abroad with no filing at all. Above that you need a contract filed with the regulator or a certificate; above a million people, or if you hold data the state calls 'important', you need a full government security review. Then come the industry walls, which override all of this.High confidence
- What do I have to do to send it abroad?
- Three routes, and you do not get to pick freely — your volume picks for you. Route one is a government security review, run by the national internet regulator through your provincial office; an approval lasts three years and only covers the exact purpose, scope and method you declared. Route two is China's own standard contract, which you sign with the overseas recipient and file with the provincial regulator along with a risk assessment. Route three is a certificate from an accredited body, which since 1 March 2026 has a national standard behind it. You also need each person's separate, specific consent before their data goes abroad.High confidence
- Who enforces this — and are they actually working?
- The Cyberspace Administration of China leads, and it is fully staffed and busy. It runs a nationwide enforcement campaign every year, tests apps itself and publishes the names of the ones that fail, and puts out batches of worked enforcement cases. Police, the industry ministry and the market regulator enforce alongside it, and finance, health, mapping and securities regulators run their own rules. Fines are usually modest and paired with an order to fix things; the eye-watering penalties in the statute are rarely used.High confidence
- How long must I keep it, and when must I delete it?
- Both directions apply, and they pull against each other. The floor: network logs must be kept for at least six months, and accounting records have their own long minimum periods set by a national schedule. The ceiling: personal data may only be kept for the shortest time needed for the purpose you collected it for, and must be deleted once that purpose is met, the service ends, or consent is withdrawn. Where a law sets a minimum, that minimum wins over the delete duty — you keep the record and stop using it for anything else.High confidence
- What happens when something goes wrong?
- Three clocks, and they overlap. If you run critical national infrastructure you have ONE HOUR to report a serious incident to your supervising department and the police. Everyone else has four hours to tell the provincial internet office. On top of that, a network data incident that could harm national security or the public interest must be reported within 24 hours. You must also tell affected people immediately, by phone, text, message, email or public notice.High confidence
- What's the trap?
- Five things that ruin weekends. (1) Sending data abroad needs each person's separate, specific consent — a line buried in a global privacy notice will not do. (2) A child is anyone under 14, and their data is treated as sensitive, so you need a parent's consent and a separate set of processing rules. (3) You may not hand data stored in China to a foreign court, police force or regulator without Chinese government approval — this catches routine legal discovery and overseas audit requests. (4) You have to work out for yourself whether you hold 'important data' and report it, because the official catalogues are incomplete. (5) The widely repeated claim that all personal financial data must be stored in China does not appear where people think it does.High confidence
- What's about to change?
- The next twelve months are about size-based rules. A draft published on 7 August 2026 would create a heavy new tier for any company holding data on ten million people or more: store it in China, appoint a chief privacy officer, set up an outside supervision committee, publish an annual report and honour data portability requests within 30 working days. Comments closed on 7 September 2026 and it is not law yet. A companion draft going the other way would simplify life for small processors. Watch the dormant switches — several can flip with no consultation at all.High confidence
- Hardest industry wall
- All industries — 中华人民共和国网络安全法(2025年修正)
- Payments — 非银行支付机构监督管理条例
- Finance — 征信业务管理办法
- Banking — 中国人民银行业务领域数据安全管理办法
- Securities — 关于加强境内企业境外发行证券和上市相关保密和档案管理工作的规定
- Health and social care — 国家健康医疗大数据标准、安全和服务管理办法(试行)
- Mapping and location — 地图管理条例
- Telecoms — 工业和信息化领域数据安全管理办法(试行)