Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
South KoreaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
- In one paragraph
- South Korea's privacy law bans sending personal data abroad unless you have one of five grounds. The usual one is a separate consent, ticked apart from every other consent. Since September 2025 the 30 European countries need no extra paperwork. But banking, health records, government cloud and detailed maps have hard walls no consent can unlock, and the regulator fines foreign companies often.
- The catch
- The 'get consent and send it' headline stops being true the moment you touch six areas: bank and payment systems, financial customers' national ID numbers, hospital records, government cloud, detailed mapping data, and personal location services. In those areas the data or the machine holding it must physically sit in South Korea, and in the government cloud case so must the people who run it.
- Does this apply to me?
- Yes. The regulator fines companies with no Korean office. In July 2026 it fined TikTok's Singapore company and two Apple companies based in Ireland and Singapore for collecting Korean users' data and sending it abroad without a proper legal basis. If your worldwide revenue was 1 trillion won (about $720 million) or more last year, or you held data on an average of 1 million or more people in Korea per day over the last three months of last year, you must appoint a representative in Korea. Since April 2026, if you already own or control a Korean company, that Korean company has to be the representative.High confidence
- Can the data leave the country?
- In general yes, but only if you have one of five grounds, and the usual one is a separate consent that the person ticks apart from every other consent. Since September 2025 you can also send data to the 27 European Union countries plus Norway, Iceland and Liechtenstein with no extra step at all, because the regulator has formally accepted their protection as equal to Korea's. That is the only such list, and no other country is on it. Six industries override all of this and are covered below.High confidence
- What do I have to do to send it abroad?
- Korea does not police the destination. It polices your paperwork. There is no banned-country list and no approval application to file: you pick one of the five grounds, and for most companies that means asking each person for a separate transfer consent that lists what goes, where, to whom, for how long and how to refuse. The one destination list that exists is a positive one, and it holds exactly 30 countries: the European Union plus Norway, Iceland and Liechtenstein. Send data anywhere else and you also have to keep security measures, a complaints route and a dispute process in place, and write the transfer into your contract with the recipient.High confidence
- Who enforces this — and are they actually working?
- The Personal Information Protection Commission, chaired by Song Kyoung-hee, and it is one of the busiest privacy regulators in the world right now. In July 2026 alone it fined the telecoms company KT about 54 billion won (roughly $39 million) over a data breach, fined TikTok about 10.3 billion won (roughly $7.4 million) and Apple about 252 million won (roughly $180,000). It referred KT to prosecutors for obstructing the investigation and asked police to investigate LG U+ for destroying a server before the inquiry started. Finance is separately policed by the Financial Services Commission and the Financial Supervisory Service; health by the health ministry; maps by an inter-agency committee that includes the intelligence service.High confidence
- How long must I keep it, and when must I delete it?
- Two forces pull in opposite directions. The ceiling: you must destroy personal data without delay once you no longer need it, and destroy it so it cannot be recovered. The floor: other laws make you keep things. An online seller must keep advertising records for 6 months, complaint and dispute records for 3 years, and contract, cancellation, payment and delivery records for 5 years. Almost everyone must keep system access logs for at least 1 year, and 2 years if the system holds data on 50,000 or more people, holds national ID numbers or sensitive data, or belongs to a licensed telecoms carrier. When the two clash, the keeping rule wins, but you must store that data separately from everything else.High confidence
- What happens when something goes wrong?
- Count two clocks, and in telecoms and finance a third. Under the privacy law you have 72 hours to tell the affected people, and a separate 72 hours to report to the Commission or to the Korea Internet and Security Agency. The reporting clock starts if 1,000 or more people are affected, or if any sensitive data or national ID numbers leaked, or if the cause was someone breaking in from outside. Separately, an internet service provider must report a cyber incident to the science ministry or the same agency immediately. A hospital must also tell the health ministry about a medical-records incident.High confidence
- What's the trap?
- Five things that will cost you a weekend. One: the children's age line is 14, not 13 or 16, and processing an under-14's data without a parent's consent is a crime punishable by up to five years in prison, not just a fine. Two: hiding or destroying material during a regulator's inspection is itself a crime, and the regulator used it in July 2026. Three: stripping names out of a dataset does not free it. Four: a bank's Korean customers' national ID numbers may not leave the country at all, and any offshore processing of customers' financial transaction data needs a report to the supervisor 30 business days before work starts. Five: if you want to run a personal location service you must be a corporation and be registered, so you cannot serve Korea from abroad with no entity.High confidence
- What's about to change?
- The privacy regulator started rewriting the rulebook for artificial intelligence. It set up a reform task force on 30 July 2026, ran a public suggestion window from 6 to 31 August 2026, and plans to publish the direction of reform before the end of 2026. Consent-based rules and the block on sending pseudonymised data abroad for research are both explicitly on the table. Separately, Apple's request to export detailed Korean map data has been pending since its deadline was extended in December 2025, and Google's equivalent request was granted in February 2026 on strict conditions, so the mapping picture can move again at any time.High confidence
- Hardest industry wall
- Banking — 전자금융감독규정 (Regulation on Supervision of Electronic Financial Transactions)
- Finance — 금융회사의 정보처리 업무 위탁에 관한 규정 (Regulation on Outsourcing of Data Processing Business by Financial Companies)
- Health and social care — 전자의무기록의 관리·보존에 필요한 시설과 장비에 관한 기준 (Standards for the Facilities and Equipment Required to Manage and Preserve Electronic Medical Records)
- Government — 클라우드컴퓨팅서비스 보안인증에 관한 고시 (Notice on Security Certification of Cloud Computing Services)
- Mapping and location — 공간정보의 구축 및 관리 등에 관한 법률 (Act on the Establishment and Management of Spatial Data)
AzerbaijanChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Azerbaijan has had a personal data law since 2010. Data may leave the country, but only if you decide the destination protects it as well as Azerbaijan does, and you must declare those exports up front. The real cost is not the export rule. It is that you must register your database with the state before you collect a single record.
- The catch
- The easy-sounding export rule hides where the work actually is. Nothing may be collected until the system holding it sits on a state register, and the government's security rules are unusually specific, down to the encryption key length and where the archive building may stand. Banking and payments have no separate storage wall, but a new cybersecurity regime started in August 2026 and a social media law bites in 2027.
- Does this apply to me?
- The law is silent about foreign companies, and that silence is the answer. Unlike Europe's rules, Azerbaijan's personal data law has no clause reaching organisations abroad that sell to Azerbaijanis. What it does have is a duty on the 'owner' of a database to register it with the state before collecting anything, and that duty is enforced through the register in Baku. A foreign company with no Azerbaijani entity has no realistic way to register, and no regulator has said whether it must. From 2027 one narrow group of foreign firms is caught by name: social network providers offering services to users in Azerbaijan must set up a local branch or representative office.Medium confidence
- Can the data leave the country?
- Yes, with conditions, and the condition is a judgement call you make yourself. Azerbaijan bans sending personal data abroad in only two situations: where it would threaten national security, or where the destination country's law does not protect the data to the standard Azerbaijani law sets. Nobody publishes a list of good or bad countries, so you decide, and you carry the risk. If the person has consented, or if the transfer is needed to protect their life or health, the destination's standard stops mattering at all. We looked hard for industry walls in banking, payments, insurance, securities, telecoms and health and found none that force data to stay in the country.High confidence
- What do I have to do to send it abroad?
- There is no form to file and no approval to get. You need three things instead: a lawful basis for the processing in the first place, your own written assessment that the destination country protects the data well enough, and a declaration of the transfer in your entry on the state register. That last point is the one people miss. The registration form asks you to list the categories of personal data you send to other countries and to international organisations, so an undeclared export is also a registration failure.High confidence
- Who enforces this — and are they actually working?
- This changed three months ago. On 3 June 2026 the President abolished the Electronic Security Service and created the National Cybersecurity Agency in its place, under the Ministry of Digital Development and Transport, with express powers over personal data as well as cyber security. The agency is real and working: it runs the state register, takes complaints about data misuse through its website, publishes advisories most weeks, and signed a cooperation agreement with Latvia's data protection inspectorate in July 2026. It is not independent of government, and we found no published fines. The register itself is the strongest evidence it functions: 444 systems are listed and the most recent approval is dated 7 August 2026.High confidence
- How long must I keep it, and when must I delete it?
- The ceiling is strict and the floor is thin. Once you have achieved the purpose you collected the data for, and there is no longer a need to keep it, you must destroy it without delay. If your registration is cancelled, everything in that system must be blocked immediately and destroyed. Sensitive data must go as soon as the reason for holding it disappears, unless the person agrees to it staying or being archived. In the other direction, the personal data law itself sets no minimum keeping period. The clearest floor we could verify is new: from 2026, records of a digital forensic investigation into a cyber incident must be kept for at least three years.Medium confidence
- What happens when something goes wrong?
- There is no personal data breach notification duty at all. The 2010 law never created one, and nothing since has added one, so losing customer records triggers no report to any regulator and no letter to the people affected. What does exist is a cyber incident duty, and it is fast: since August 2026, organisations that run information infrastructure must pass information about cyber threats, attacks and incidents to the National CERT immediately. Once the National CERT asks you something, you have 24 hours to answer a threat research request and 5 working days to answer a digital investigation request. Financial firms have a second clock through the Central Bank's FinCERT portal.High confidence
- What's the trap?
- Five. One: you cannot start. Collecting or processing personal data in an unregistered system is an offence, and registration takes up to a month. Two: the security rules are engineering specifications, not principles, and include a minimum 256-bit encryption key, a data centre archive system housed in a separate building, and state expert review of your system design documents. Three: every operator must set things up so that police and intelligence bodies can carry out surveillance, and must keep the methods secret. Four: the fine for breaking the data law is 300 to 500 manat, roughly 175 to 290 US dollars, which tells you the real risk is being ordered to stop, not being fined. Five: the law says data system work needs a special licence, and no licensing regime matching it appears to be running.High confidence
- What's about to change?
- One big date and one big gap. The big date is roughly August 2027, twelve months after publication, when Azerbaijan's minimum age of 16 for social network accounts starts. Providers must verify age using a bank card, an email address and a mobile number, must delete what they collected for that check immediately, and must open a local branch. The penalty ladder ends with a court ordering the platform's traffic in Azerbaijan cut by 90 per cent. The big gap is that the July 2026 cybersecurity law leaves the important lists and technical requirements to be written by ministries, and they are not out yet.High confidence
- Hardest industry wall
- Government — “Hökumət buludu”nun (G-cloud) yaradılması və “bulud” xidmətlərinin göstərilməsi sahəsində tədbirlər haqqında Azərbaycan Respublikası Prezidentinin Fərmanı