Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
Sri LankaChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Waking up
- In one paragraph
- Sri Lanka has a full privacy law on the books, but almost none of the parts that create duties for companies are switched on yet. The government has now fixed 1 January 2027 as the day the core duties start. Data may leave the country freely today. From 2027 you will need a written contract or similar promise from whoever receives it abroad. No fines have ever been issued.
- The catch
- The 'conditional' rating describes 1 January 2027, not today. As of 18 August 2026 the transfer rule is not in force, the individual-rights section has no start date at all, and the penalty section has no start date either. There are no industry data-storage walls: banking, payments, insurance, securities, health and telecom all lack a localisation rule. The only place data location is even mentioned is government, and there it is a preference, not a ban.
- Does this apply to me?
- Yes. The law reaches a company with no office in Sri Lanka if it offers goods or services to people in Sri Lanka, or watches how they behave online. It also catches anyone processing data inside the country. There is no size or revenue floor to fall below, and no requirement to appoint a local representative. But none of this bites until 1 January 2027, because the scope section itself has not started yet.High confidence
- Can the data leave the country?
- Today, yes, with nothing to sign — the transfer section is not in force. From 1 January 2027 data can still leave, but you must first get a binding promise from the receiver abroad that Sri Lankan protections will be honoured. There is no banned-country list and no approved-country list: Sri Lanka scrapped its country-approval system in October 2025. No industry has a rule forcing data to stay in Sri Lanka.High confidence
- What do I have to do to send it abroad?
- Right now, nothing. There is no approval to get, no list to check and no form to file, because the transfer section has not started. From 1 January 2027 you will need a written, binding commitment from the overseas receiver. The Authority is supposed to say exactly what form that takes, and it has not done so — only a draft from October 2024 exists, and that draft was written for a version of the law that no longer exists.High confidence
- Who enforces this — and are they actually working?
- The Data Protection Authority of Sri Lanka. It genuinely exists: it has a chairman, a seven-person board, a director-general, an office in Colombo and it publishes circulars and draft rules. But it has never issued a fine or a decision, and legally it cannot yet. The Authority itself says in writing that it will only investigate complaints once the relevant sections are switched on. The penalty section still has no start date.High confidence
- How long must I keep it, and when must I delete it?
- The floor is clearer than the ceiling. Banks, finance companies and other reporting institutions must keep transaction records for six years, and identity records for six years after the account closes. The ceiling is a principle, not a number: from 1 January 2027 you must not keep personal data in a form that identifies someone for longer than the purpose needs. Where the two clash, the six-year legal duty wins.High confidence
- What happens when something goes wrong?
- There is no deadline, because there is no duty yet. This is unusual and worth saying plainly: as of 18 August 2026 a company suffering a data breach in Sri Lanka has no legal obligation to tell anyone. Reporting to the national cyber team is voluntary. From 1 January 2027 you must notify the Authority, but the rules that set the form and the clock are still a draft. Banks are the exception and must report technology and cyber incidents to the Central Bank.High confidence
- What's the trap?
- Five things that will cost you a weekend. A child in Sri Lanka is anyone under sixteen, not eighteen, and a parent must consent for them. Fines are small but personal: directors can be made to pay unless they prove they did not know. The advertised start date of 18 March 2025 was cancelled four days before it arrived, so anything written before November 2025 is wrong. Company data is not protected the way you would expect, because the individual-rights section still has no start date. And the published transfer guidance describes a law that no longer exists.High confidence
- What's about to change?
- One hard date and four switches. On 1 January 2027 the scope, the processing duties and the controller duties all start, and the Central Bank's new outsourcing rules for banks start the same day. Before then the Authority is expected to finalise its rules on breach reporting, impact assessments, data protection officers and overseas transfers. Watch also for a second gazette bringing individual rights and the penalty section into force — without it, the law has duties but no teeth.High confidence
- Hardest industry wall
- Government — Personal Data Protection Act section 26(4) and 26(5), as substituted by Act No. 22 of 2025
GermanyChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Contrary to widespread belief, neither Europe nor Germany requires personal data to be stored in Europe. What the law requires is a valid legal instrument before data leaves — an official decision that the destination is safe enough, or a standard contract, plus a documented risk assessment. Germany then adds its own layer on top, and one genuine hard wall: health and social data may only be processed in the cloud within Europe, by a provider holding a specific German security certificate.
- The catch
- 'Germany doesn't require local storage' is true right up until you sell to a hospital, a health insurer, a doctor, a lawyer or a tax adviser. In health and social care it is simply false, and for the professional-secrecy trades a standard data processing agreement is not enough and getting it wrong is a criminal matter.
- Does this apply to me?
- Yes, it reaches you with no office in Germany. Europe's privacy law applies to any organisation anywhere that offers goods or services to people in Europe or monitors their behaviour. If you have no European establishment you must also appoint a representative inside Europe.High confidence
- Can the data leave the country?
- Yes — with paperwork. This is the single most misunderstood point in the field. European law does not say where data must sit; it says what you must have in place before it leaves Europe. Storage location is a risk factor in that assessment, never a prohibition. For non-personal data, Europe goes further and actually forbids member states from imposing storage-location rules.High confidence
- What do I have to do to send it abroad?
- One of three routes. Best case, the destination is on Europe's official 'adequate' list and you need nothing extra — currently 17 entries including the UK, Japan, South Korea, Switzerland, Canada for commercial bodies, Brazil since January 2026, and the United States but only for companies self-certified under the EU-US Data Privacy Framework. Otherwise you sign Europe's standard contract clauses, or get group-wide internal rules approved. In either of those two cases you must also document an assessment of whether the destination country's surveillance laws undermine the protection.High confidence
- Who enforces this — and are they actually working?
- Eighteen separate authorities, and for a private company it is almost never the federal one. Each of the 16 states has its own regulator, and you answer to the one where your German office is. The federal regulator handles government bodies plus telecoms and postal operators. Bavaria splits it further, with different bodies for private and public sector. If you operate across Europe, a separate rule lets you deal mainly with the regulator where your main European establishment sits.High confidence
- How long must I keep it, and when must I delete it?
- Business records have a floor: accounting vouchers must be kept 8 years (cut from 10 with effect from 2025, and from 2026 for banks and insurers), the annual accounts and trading books still 10 years, and business correspondence 6 years. Privacy law pushes the other way — don't keep personal data longer than you need it. Where the two collide, German law has an elegant answer: you restrict processing of the data instead of deleting it.High confidence
- What happens when something goes wrong?
- 72 hours to tell your state regulator about a personal data breach, and without undue delay to tell affected people where the risk to them is high. Separately, since December 2025 Germany's cybersecurity law adds its own clocks for around 29,500 in-scope companies: a first warning within 24 hours, an update at 72 hours, and a full report within a month. Financial firms follow a separate European regime instead.High confidence
- What's the trap?
- Four. (1) Health and social data really does have to stay in Europe, with a specific German security certificate — the general 'no localisation' answer is wrong here. (2) For doctors, lawyers, tax advisers and notaries, a standard data processing agreement is NOT enough: you need explicit secrecy undertakings flowed down to every subcontractor, and breach is a criminal offence, not a fine. (3) Germany still requires a data protection officer at just 20 employees involved in data processing — far stricter than European law, and still in force despite a government promise to scrap it by the end of 2026. (4) The German rule people cite for employee data was effectively struck down by Europe's top court in 2023 but never removed from the statute book, so citing it as your legal basis is a mistake.High confidence
- What's about to change?
- Two hard dates and one live risk. From 12 January 2027 every cloud provider must drop switching and data egress fees to zero — renegotiate contracts now. By 31 December 2026 Germany's banking IT rulebook is fully withdrawn in favour of the European financial regime. The live risk is the US arrangement: Europe's data protection board formally asked the Commission on 31 July 2026 to review whether it is still valid, and a separate court appeal is pending. If it falls, thousands of transfers move to standard contracts overnight.High confidence
- Hardest industry wall
- Health and social care — § 393 SGB V — Cloud-Einsatz im Gesundheitswesen
- Telecoms — §§ 175–181 TKG — Vorratsdatenspeicherung