Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
South KoreaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
- In one paragraph
- South Korea's privacy law bans sending personal data abroad unless you have one of five grounds. The usual one is a separate consent, ticked apart from every other consent. Since September 2025 the 30 European countries need no extra paperwork. But banking, health records, government cloud and detailed maps have hard walls no consent can unlock, and the regulator fines foreign companies often.
- The catch
- The 'get consent and send it' headline stops being true the moment you touch six areas: bank and payment systems, financial customers' national ID numbers, hospital records, government cloud, detailed mapping data, and personal location services. In those areas the data or the machine holding it must physically sit in South Korea, and in the government cloud case so must the people who run it.
- Does this apply to me?
- Yes. The regulator fines companies with no Korean office. In July 2026 it fined TikTok's Singapore company and two Apple companies based in Ireland and Singapore for collecting Korean users' data and sending it abroad without a proper legal basis. If your worldwide revenue was 1 trillion won (about $720 million) or more last year, or you held data on an average of 1 million or more people in Korea per day over the last three months of last year, you must appoint a representative in Korea. Since April 2026, if you already own or control a Korean company, that Korean company has to be the representative.High confidence
- Can the data leave the country?
- In general yes, but only if you have one of five grounds, and the usual one is a separate consent that the person ticks apart from every other consent. Since September 2025 you can also send data to the 27 European Union countries plus Norway, Iceland and Liechtenstein with no extra step at all, because the regulator has formally accepted their protection as equal to Korea's. That is the only such list, and no other country is on it. Six industries override all of this and are covered below.High confidence
- What do I have to do to send it abroad?
- Korea does not police the destination. It polices your paperwork. There is no banned-country list and no approval application to file: you pick one of the five grounds, and for most companies that means asking each person for a separate transfer consent that lists what goes, where, to whom, for how long and how to refuse. The one destination list that exists is a positive one, and it holds exactly 30 countries: the European Union plus Norway, Iceland and Liechtenstein. Send data anywhere else and you also have to keep security measures, a complaints route and a dispute process in place, and write the transfer into your contract with the recipient.High confidence
- Who enforces this — and are they actually working?
- The Personal Information Protection Commission, chaired by Song Kyoung-hee, and it is one of the busiest privacy regulators in the world right now. In July 2026 alone it fined the telecoms company KT about 54 billion won (roughly $39 million) over a data breach, fined TikTok about 10.3 billion won (roughly $7.4 million) and Apple about 252 million won (roughly $180,000). It referred KT to prosecutors for obstructing the investigation and asked police to investigate LG U+ for destroying a server before the inquiry started. Finance is separately policed by the Financial Services Commission and the Financial Supervisory Service; health by the health ministry; maps by an inter-agency committee that includes the intelligence service.High confidence
- How long must I keep it, and when must I delete it?
- Two forces pull in opposite directions. The ceiling: you must destroy personal data without delay once you no longer need it, and destroy it so it cannot be recovered. The floor: other laws make you keep things. An online seller must keep advertising records for 6 months, complaint and dispute records for 3 years, and contract, cancellation, payment and delivery records for 5 years. Almost everyone must keep system access logs for at least 1 year, and 2 years if the system holds data on 50,000 or more people, holds national ID numbers or sensitive data, or belongs to a licensed telecoms carrier. When the two clash, the keeping rule wins, but you must store that data separately from everything else.High confidence
- What happens when something goes wrong?
- Count two clocks, and in telecoms and finance a third. Under the privacy law you have 72 hours to tell the affected people, and a separate 72 hours to report to the Commission or to the Korea Internet and Security Agency. The reporting clock starts if 1,000 or more people are affected, or if any sensitive data or national ID numbers leaked, or if the cause was someone breaking in from outside. Separately, an internet service provider must report a cyber incident to the science ministry or the same agency immediately. A hospital must also tell the health ministry about a medical-records incident.High confidence
- What's the trap?
- Five things that will cost you a weekend. One: the children's age line is 14, not 13 or 16, and processing an under-14's data without a parent's consent is a crime punishable by up to five years in prison, not just a fine. Two: hiding or destroying material during a regulator's inspection is itself a crime, and the regulator used it in July 2026. Three: stripping names out of a dataset does not free it. Four: a bank's Korean customers' national ID numbers may not leave the country at all, and any offshore processing of customers' financial transaction data needs a report to the supervisor 30 business days before work starts. Five: if you want to run a personal location service you must be a corporation and be registered, so you cannot serve Korea from abroad with no entity.High confidence
- What's about to change?
- The privacy regulator started rewriting the rulebook for artificial intelligence. It set up a reform task force on 30 July 2026, ran a public suggestion window from 6 to 31 August 2026, and plans to publish the direction of reform before the end of 2026. Consent-based rules and the block on sending pseudonymised data abroad for research are both explicitly on the table. Separately, Apple's request to export detailed Korean map data has been pending since its deadline was extended in December 2025, and Google's equivalent request was granted in February 2026 on strict conditions, so the mapping picture can move again at any time.High confidence
- Hardest industry wall
- Banking — 전자금융감독규정 (Regulation on Supervision of Electronic Financial Transactions)
- Finance — 금융회사의 정보처리 업무 위탁에 관한 규정 (Regulation on Outsourcing of Data Processing Business by Financial Companies)
- Health and social care — 전자의무기록의 관리·보존에 필요한 시설과 장비에 관한 기준 (Standards for the Facilities and Equipment Required to Manage and Preserve Electronic Medical Records)
- Government — 클라우드컴퓨팅서비스 보안인증에 관한 고시 (Notice on Security Certification of Cloud Computing Services)
- Mapping and location — 공간정보의 구축 및 관리 등에 관한 법률 (Act on the Establishment and Management of Spatial Data)
TurkeyChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- Turkey lets personal data leave, but only after you build the paperwork yourself. The regulator has never declared a single country safe, so the approved-destination list is empty. Most companies use a government-published standard contract and must file it within five working days. The regulator is busy: it fined 876 organisations in 2025.
- The catch
- The general rule is 'paperwork, then you may send it'. That stops being true the moment you touch payments, banking, telecoms networks, public-sector systems or critical infrastructure. Payment and electronic money firms must keep their systems, their backups and their data inside Turkey, and may only use cloud providers the central bank has approved by name.
- Does this apply to me?
- Yes. A company with no office in Turkey is still caught, and it is caught harder than a local one. Any organisation based outside Turkey that decides why and how Turkish people's data is used must appoint a representative inside Turkey and sign up to the public register of data controllers before it starts processing. That representative has to be a company set up in Turkey or a Turkish citizen. Turkish small businesses can escape the register if they have fewer than 50 staff and a balance sheet under 100 million lira, but there is no such let-off for foreign companies.High confidence
- Can the data leave the country?
- It depends entirely on your industry, which is why Turkey is rated 'sectoral'. Under the general privacy law data may leave, but only after you put an approved safeguard in place, because the regulator has not yet declared any country safe. In payments and banking the answer flips to no: systems, backups and data have to sit inside Turkey. Public bodies, critical infrastructure, telecoms networks and health records all carry their own extra restrictions on top.High confidence
- What do I have to do to send it abroad?
- The model is an approved-destination list, and the list is empty. Nobody can rely on their country being blessed, so almost everyone uses one of the safeguards instead. The usual route is signing one of four standard contracts the regulator publishes, then telling the regulator within five working days of signing. Group companies can instead get binding corporate rules approved, and there is a permission route for bespoke undertakings, but that route almost always fails.High confidence
- Who enforces this — and are they actually working?
- The Personal Data Protection Authority, and it is fully up and running. In 2025 its board met 42 times, took 2,528 decisions, handled 12,512 complaints and fined 876 organisations a combined 352.5 million lira, which is roughly 8 million US dollars. It publishes named breach announcements most weeks. Financial, telecoms and insurance regulators enforce their own rules alongside it, and a new Cybersecurity Directorate has taken over the national cyber incident centre.High confidence
- How long must I keep it, and when must I delete it?
- Both directions apply, and the ceiling is unusual. Turkey does not give you a fixed number of months to delete by. Instead, once your reason for holding data runs out, you must erase it at your next scheduled clear-out, and any organisation on the public register has to publish a written retention and destruction policy setting those dates. The floor comes from ordinary commercial and tax law, which forces you to keep books and invoices for years.Medium confidence
- What happens when something goes wrong?
- There are at least three clocks. The privacy one is 72 hours: from the moment you learn that data has been taken unlawfully, you have three days to tell the Personal Data Protection Board, and you must tell the affected people as soon as you reasonably can. If you miss the 72 hours you must still report and explain why you were late. Companies based abroad have to report too, if people in Turkey are affected.High confidence
- What's the trap?
- Five things bite people. One: most fines are for paperwork, not privacy. Two thirds of the organisations fined in 2025 were punished for the public register, not for mishandling anyone's data. Two: the bespoke permission route for sending data abroad is close to a dead end, with 76 of 89 applications refused in 2025. Three: filing your standard contract invites inspection rather than closing the file. Four: your representative in Turkey must be Turkish. Five: no country is on the safe list, so there is no shortcut.High confidence
- What's about to change?
- Two dated items and one direction of travel. Retailers running loyalty cards have until 28 February 2027 to build a way of checking that the person at the till really owns the card, after the regulator extended the original deadline in July 2026. Public bodies are working to a July 2026 ruling on what they may publish online. And the government is pushing openly on data sovereignty, with the President chairing a cyber security meeting in May 2026 that treated data as a strategic asset.High confidence
- Hardest industry wall
- Payments — Odeme ve Elektronik Para Kuruluslarinin Bilgi Sistemleri ile Odeme Hizmeti Saglayicilarinin Odeme Hizmetleri Alanindaki Veri Paylasim Servislerine Iliskin Teblig
- Banking — Bankalarin Bilgi Sistemleri ve Elektronik Bankacilik Hizmetleri Hakkinda Yonetmelik
- Government — 2019/12 sayili Bilgi ve Iletisim Guvenligi Tedbirleri Genelgesi ve Bilgi ve Iletisim Guvenligi Rehberi