Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
South KoreaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
In one paragraph
South Korea's privacy law bans sending personal data abroad unless you have one of five grounds. The usual one is a separate consent, ticked apart from every other consent. Since September 2025 the 30 European countries need no extra paperwork. But banking, health records, government cloud and detailed maps have hard walls no consent can unlock, and the regulator fines foreign companies often.
The catch
The 'get consent and send it' headline stops being true the moment you touch six areas: bank and payment systems, financial customers' national ID numbers, hospital records, government cloud, detailed mapping data, and personal location services. In those areas the data or the machine holding it must physically sit in South Korea, and in the government cloud case so must the people who run it.
Does this apply to me?
Yes. The regulator fines companies with no Korean office. In July 2026 it fined TikTok's Singapore company and two Apple companies based in Ireland and Singapore for collecting Korean users' data and sending it abroad without a proper legal basis. If your worldwide revenue was 1 trillion won (about $720 million) or more last year, or you held data on an average of 1 million or more people in Korea per day over the last three months of last year, you must appoint a representative in Korea. Since April 2026, if you already own or control a Korean company, that Korean company has to be the representative.High confidence
Can the data leave the country?
In general yes, but only if you have one of five grounds, and the usual one is a separate consent that the person ticks apart from every other consent. Since September 2025 you can also send data to the 27 European Union countries plus Norway, Iceland and Liechtenstein with no extra step at all, because the regulator has formally accepted their protection as equal to Korea's. That is the only such list, and no other country is on it. Six industries override all of this and are covered below.High confidence
What do I have to do to send it abroad?
Korea does not police the destination. It polices your paperwork. There is no banned-country list and no approval application to file: you pick one of the five grounds, and for most companies that means asking each person for a separate transfer consent that lists what goes, where, to whom, for how long and how to refuse. The one destination list that exists is a positive one, and it holds exactly 30 countries: the European Union plus Norway, Iceland and Liechtenstein. Send data anywhere else and you also have to keep security measures, a complaints route and a dispute process in place, and write the transfer into your contract with the recipient.High confidence
Who enforces this — and are they actually working?
The Personal Information Protection Commission, chaired by Song Kyoung-hee, and it is one of the busiest privacy regulators in the world right now. In July 2026 alone it fined the telecoms company KT about 54 billion won (roughly $39 million) over a data breach, fined TikTok about 10.3 billion won (roughly $7.4 million) and Apple about 252 million won (roughly $180,000). It referred KT to prosecutors for obstructing the investigation and asked police to investigate LG U+ for destroying a server before the inquiry started. Finance is separately policed by the Financial Services Commission and the Financial Supervisory Service; health by the health ministry; maps by an inter-agency committee that includes the intelligence service.High confidence
How long must I keep it, and when must I delete it?
Two forces pull in opposite directions. The ceiling: you must destroy personal data without delay once you no longer need it, and destroy it so it cannot be recovered. The floor: other laws make you keep things. An online seller must keep advertising records for 6 months, complaint and dispute records for 3 years, and contract, cancellation, payment and delivery records for 5 years. Almost everyone must keep system access logs for at least 1 year, and 2 years if the system holds data on 50,000 or more people, holds national ID numbers or sensitive data, or belongs to a licensed telecoms carrier. When the two clash, the keeping rule wins, but you must store that data separately from everything else.High confidence
What happens when something goes wrong?
Count two clocks, and in telecoms and finance a third. Under the privacy law you have 72 hours to tell the affected people, and a separate 72 hours to report to the Commission or to the Korea Internet and Security Agency. The reporting clock starts if 1,000 or more people are affected, or if any sensitive data or national ID numbers leaked, or if the cause was someone breaking in from outside. Separately, an internet service provider must report a cyber incident to the science ministry or the same agency immediately. A hospital must also tell the health ministry about a medical-records incident.High confidence
What's the trap?
Five things that will cost you a weekend. One: the children's age line is 14, not 13 or 16, and processing an under-14's data without a parent's consent is a crime punishable by up to five years in prison, not just a fine. Two: hiding or destroying material during a regulator's inspection is itself a crime, and the regulator used it in July 2026. Three: stripping names out of a dataset does not free it. Four: a bank's Korean customers' national ID numbers may not leave the country at all, and any offshore processing of customers' financial transaction data needs a report to the supervisor 30 business days before work starts. Five: if you want to run a personal location service you must be a corporation and be registered, so you cannot serve Korea from abroad with no entity.High confidence
What's about to change?
The privacy regulator started rewriting the rulebook for artificial intelligence. It set up a reform task force on 30 July 2026, ran a public suggestion window from 6 to 31 August 2026, and plans to publish the direction of reform before the end of 2026. Consent-based rules and the block on sending pseudonymised data abroad for research are both explicitly on the table. Separately, Apple's request to export detailed Korean map data has been pending since its deadline was extended in December 2025, and Google's equivalent request was granted in February 2026 on strict conditions, so the mapping picture can move again at any time.High confidence
Hardest industry wall
  • Banking 전자금융감독규정 (Regulation on Supervision of Electronic Financial Transactions)
  • Finance 금융회사의 정보처리 업무 위탁에 관한 규정 (Regulation on Outsourcing of Data Processing Business by Financial Companies)
  • Health and social care 전자의무기록의 관리·보존에 필요한 시설과 장비에 관한 기준 (Standards for the Facilities and Equipment Required to Manage and Preserve Electronic Medical Records)
  • Government 클라우드컴퓨팅서비스 보안인증에 관한 고시 (Notice on Security Certification of Cloud Computing Services)
  • Mapping and location 공간정보의 구축 및 관리 등에 관한 법률 (Act on the Establishment and Management of Spatial Data)
MaltaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
In one paragraph
Malta runs on the European rulebook. Data may go abroad once the right paperwork is in place, and there is no general rule that it must stay on the island. Two things break that. Online gaming companies must keep their core systems inside Europe. And any Maltese company that keeps its books abroad must still keep a copy of its accounts in Malta.
The catch
The easy answer stops being true in three places. First, online gaming, which is Malta's biggest regulated industry: a licensed operator's 'key technical setup' — including the player database, the financial database and the control system — must sit in Malta or another European Economic Area country, unless the Malta Gaming Authority approves another location one case at a time. The same operator must also run a live mirror of its essential regulatory data that the Authority can reach at any moment, including physically. Second, company law: if a company keeps its accounting records outside Malta, it must still send to Malta, and keep in Malta, accounts and returns good enough to show the financial position at least every six months. Third, government: the public administration's own cloud policy says cloud services should as a rule be inside the European Union or European Economic Area, and anything classified must go on the government's own cloud. Banking, payments, insurance, securities, health, education and mapping have no storage-location rule that we could find, checked 18 August 2026.
Does this apply to me?
Yes. Malta's Data Protection Act reaches a company with no office in Malta if it offers goods or services to people in Malta, or watches their behaviour in Malta. There is no size or revenue threshold. There is no extra Maltese representative to appoint beyond the one the European rules already require of companies based outside Europe.High confidence
Can the data leave the country?
In general, yes. Malta has no law saying personal data must be stored on the island. It follows the European Union rules: send data outside Europe once you have an approved destination or the right contract. Three areas override that. Online gaming is the big one, and it is Malta's flagship industry.High confidence
What do I have to do to send it abroad?
Use the European toolkit. Send data to a country the European Commission has approved, or sign the European standard contract, or use approved group-wide rules. Malta adds nothing on top. Malta's own minister has a power to restrict transfers of named categories of data, but has never used it, so the list of Maltese restrictions is empty today.High confidence
Who enforces this — and are they actually working?
The Information and Data Protection Commissioner. It is real, staffed and issuing decisions: its public register shows around nineteen decisions published in 2026 and thirty-eight in 2025. The fines are small by European standards — most sit between about 2,000 and 20,000 euros (roughly $2,300 to $23,000). The gaming regulator is the harder one, and it cancels licences.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling. The floor: company accounting records for ten years, tax and value-added-tax records for at least six years, and anti-money-laundering records for five years. The ceiling: the European rule that you delete personal data once you no longer need it. Where they clash, the specific Maltese law that orders you to keep something wins, because keeping it is then a legal duty.High confidence
What happens when something goes wrong?
Count three clocks, and they do not line up. Seventy-two hours to tell the privacy regulator about a personal data breach. Twenty-four hours to send a first warning about a serious cyber incident, then seventy-two hours for the full report and one month for the final one. Phone and internet companies have their own separate duty to report straight away.High confidence
What's the trap?
Five things that are not in the summary. A child in Malta is thirteen, not sixteen. Health and biometric research needs the regulator's written permission before you start, not just a risk assessment. Copying someone's identity card is restricted. Leaking a client secret can be a crime, not a fine. And the gaming regulator can keep personal data forever, in a law that says so out loud.High confidence
What's about to change?
Three dated changes. On 1 January 2027 a new law stops insurers, banks and employers asking about a cancer diagnosis once enough time has passed since treatment. On 12 January 2027 European rules make cloud switching and data export fees free. And Malta's artificial intelligence rules started phasing in on 2 August 2026, with the privacy regulator now policing the market.High confidence
Hardest industry wall
  • All industries Att dwar il-Kumpaniji (Kap. 386), artikolu 163