Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
CambodiaChecked 18 August 2026
Depends on your industryWork: LowEnforcement: Dormant
In one paragraph
Cambodia has no general privacy law. A bill exists and went to a public review meeting in August 2026, but it is not law and there is no privacy regulator to complain to. For most businesses data can leave the country freely, with no paperwork. Banks and other lenders are the big exception: their main data centre must sit inside Cambodia.
The catch
The relaxed headline stops at the door of the financial sector. Any bank or lender supervised by Cambodia's central bank must keep at least one main data centre inside the country, and must get the central bank's permission in advance before customer personal data is moved to or hosted on servers abroad. Telecoms are also watched closely by an active regulator, and a suspended 2021 order that would push all internet traffic through a single government-controlled gateway can be switched back on at any time.
Does this apply to me?
There is no general data protection law in Cambodia, so there is nothing for a foreign company to be caught by. No size threshold, no revenue threshold, no registration, and no requirement to appoint someone in Cambodia to answer for your data. That changes the moment you need a local licence: banks, lenders and telecoms operators are licensed here and their licence conditions do reach their overseas systems. A draft privacy law was put to a validation workshop on 5 August 2026 and will proceed through the formal law-making process, so this answer has a shelf life.High confidence
Can the data leave the country?
In general, yes, and with nothing to sign. Cambodia has no rule that stops ordinary personal data leaving the country. Finance is the one hard wall we could verify: a bank or lender supervised by the central bank must have at least one main data centre in Cambodia, may only use a foreign data centre as a backup, and needs the central bank's approval before customer personal data is hosted abroad. Telecoms is the sector to watch, because a 2021 order that would route all internet traffic through a single national gateway was never switched on but was never cancelled either.Medium confidence
What do I have to do to send it abroad?
For most organisations, nothing at all. There is no approved-countries list, no banned-countries list, no standard contract to sign and no government form to file. The lists are not just empty, they do not exist, because there is no law that creates them. In finance the model is completely different: each move of customer personal data out of Cambodia needs its own approval from the central bank, decided case by case, and there is no published application process or timetable.Medium confidence
Who enforces this — and are they actually working?
For privacy, nobody. Cambodia has no data protection authority. The Ministry of Post and Telecommunications is writing the law and, in November 2025, ran a training workshop with Singapore's privacy regulator on how to build such an authority, which tells you plainly that one does not yet exist. Sector regulators are a different story and are genuinely working: the central bank supervises financial firms against its 2026 technology guidelines, and the telecoms regulator publicly named an operator in June 2026 for selling SIM cards without properly checking customers' identity documents.High confidence
How long must I keep it, and when must I delete it?
There is a floor and almost no ceiling. Tax and accounting law forces businesses to keep books and supporting documents for years, and financial firms must keep system logs and agree retention periods with their cloud providers. In the other direction there is no general rule telling anyone to delete personal data, because there is no privacy law. The only deletion duty we could verify applies to banks and lenders, who must keep customer personal data only as long as it is needed.Medium confidence
What happens when something goes wrong?
There is no breach reporting clock in Cambodia. No law requires you to tell a regulator or the affected people when personal data leaks, and there is no national cyber incident hotline with a deadline in hours. The nearest thing is in banking: the central bank tells supervised firms to report incidents as it requires, either on a regular cycle or one-off, with no fixed number of hours. Two draft laws would change this, so treat today's silence as temporary.Medium confidence
What's the trap?
Five things that are not in the summary. First, the e-commerce law reportedly bans encryption that would stop evidence being used in a criminal case, which cuts across normal end-to-end encryption promises. Second, a cloud-only bank cannot operate here: the main data centre must physically be in Cambodia. Third, moving customer banking data abroad needs the central bank's permission in advance, and there is no published process or timetable, so it must be planned months ahead. Fourth, telecoms operators must check identity documents before activating a SIM card, and the regulator names offenders in public. Fifth, no privacy law does not mean no risk, because your foreign customers will impose their own rules by contract.Medium confidence
What's about to change?
Four drafts are moving and none of them is law yet. The Personal Data Protection Law reached a validation workshop on 5 August 2026 and now heads into the formal law-making process. The Cybersecurity Law was still being argued over with the Ministry of Justice in July 2026. A Data Governance Policy for 2026 to 2035 was in consultation in March 2026 and is expected to cover where data may be stored and how it may cross borders. A Digital Government Law went to consultation in July 2025. No commencement date has been announced for any of them.High confidence
Hardest industry wall
  • Finance Technology and Cyber Risk Management Guidelines (TCRMG)
MaltaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
In one paragraph
Malta runs on the European rulebook. Data may go abroad once the right paperwork is in place, and there is no general rule that it must stay on the island. Two things break that. Online gaming companies must keep their core systems inside Europe. And any Maltese company that keeps its books abroad must still keep a copy of its accounts in Malta.
The catch
The easy answer stops being true in three places. First, online gaming, which is Malta's biggest regulated industry: a licensed operator's 'key technical setup' — including the player database, the financial database and the control system — must sit in Malta or another European Economic Area country, unless the Malta Gaming Authority approves another location one case at a time. The same operator must also run a live mirror of its essential regulatory data that the Authority can reach at any moment, including physically. Second, company law: if a company keeps its accounting records outside Malta, it must still send to Malta, and keep in Malta, accounts and returns good enough to show the financial position at least every six months. Third, government: the public administration's own cloud policy says cloud services should as a rule be inside the European Union or European Economic Area, and anything classified must go on the government's own cloud. Banking, payments, insurance, securities, health, education and mapping have no storage-location rule that we could find, checked 18 August 2026.
Does this apply to me?
Yes. Malta's Data Protection Act reaches a company with no office in Malta if it offers goods or services to people in Malta, or watches their behaviour in Malta. There is no size or revenue threshold. There is no extra Maltese representative to appoint beyond the one the European rules already require of companies based outside Europe.High confidence
Can the data leave the country?
In general, yes. Malta has no law saying personal data must be stored on the island. It follows the European Union rules: send data outside Europe once you have an approved destination or the right contract. Three areas override that. Online gaming is the big one, and it is Malta's flagship industry.High confidence
What do I have to do to send it abroad?
Use the European toolkit. Send data to a country the European Commission has approved, or sign the European standard contract, or use approved group-wide rules. Malta adds nothing on top. Malta's own minister has a power to restrict transfers of named categories of data, but has never used it, so the list of Maltese restrictions is empty today.High confidence
Who enforces this — and are they actually working?
The Information and Data Protection Commissioner. It is real, staffed and issuing decisions: its public register shows around nineteen decisions published in 2026 and thirty-eight in 2025. The fines are small by European standards — most sit between about 2,000 and 20,000 euros (roughly $2,300 to $23,000). The gaming regulator is the harder one, and it cancels licences.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling. The floor: company accounting records for ten years, tax and value-added-tax records for at least six years, and anti-money-laundering records for five years. The ceiling: the European rule that you delete personal data once you no longer need it. Where they clash, the specific Maltese law that orders you to keep something wins, because keeping it is then a legal duty.High confidence
What happens when something goes wrong?
Count three clocks, and they do not line up. Seventy-two hours to tell the privacy regulator about a personal data breach. Twenty-four hours to send a first warning about a serious cyber incident, then seventy-two hours for the full report and one month for the final one. Phone and internet companies have their own separate duty to report straight away.High confidence
What's the trap?
Five things that are not in the summary. A child in Malta is thirteen, not sixteen. Health and biometric research needs the regulator's written permission before you start, not just a risk assessment. Copying someone's identity card is restricted. Leaking a client secret can be a crime, not a fine. And the gaming regulator can keep personal data forever, in a law that says so out loud.High confidence
What's about to change?
Three dated changes. On 1 January 2027 a new law stops insurers, banks and employers asking about a cancer diagnosis once enough time has passed since treatment. On 12 January 2027 European rules make cloud switching and data export fees free. And Malta's artificial intelligence rules started phasing in on 2 August 2026, with the privacy regulator now policing the market.High confidence
Hardest industry wall
  • All industries Att dwar il-Kumpaniji (Kap. 386), artikolu 163