Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
Sri LankaChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Waking up
- In one paragraph
- Sri Lanka has a full privacy law on the books, but almost none of the parts that create duties for companies are switched on yet. The government has now fixed 1 January 2027 as the day the core duties start. Data may leave the country freely today. From 2027 you will need a written contract or similar promise from whoever receives it abroad. No fines have ever been issued.
- The catch
- The 'conditional' rating describes 1 January 2027, not today. As of 18 August 2026 the transfer rule is not in force, the individual-rights section has no start date at all, and the penalty section has no start date either. There are no industry data-storage walls: banking, payments, insurance, securities, health and telecom all lack a localisation rule. The only place data location is even mentioned is government, and there it is a preference, not a ban.
- Does this apply to me?
- Yes. The law reaches a company with no office in Sri Lanka if it offers goods or services to people in Sri Lanka, or watches how they behave online. It also catches anyone processing data inside the country. There is no size or revenue floor to fall below, and no requirement to appoint a local representative. But none of this bites until 1 January 2027, because the scope section itself has not started yet.High confidence
- Can the data leave the country?
- Today, yes, with nothing to sign — the transfer section is not in force. From 1 January 2027 data can still leave, but you must first get a binding promise from the receiver abroad that Sri Lankan protections will be honoured. There is no banned-country list and no approved-country list: Sri Lanka scrapped its country-approval system in October 2025. No industry has a rule forcing data to stay in Sri Lanka.High confidence
- What do I have to do to send it abroad?
- Right now, nothing. There is no approval to get, no list to check and no form to file, because the transfer section has not started. From 1 January 2027 you will need a written, binding commitment from the overseas receiver. The Authority is supposed to say exactly what form that takes, and it has not done so — only a draft from October 2024 exists, and that draft was written for a version of the law that no longer exists.High confidence
- Who enforces this — and are they actually working?
- The Data Protection Authority of Sri Lanka. It genuinely exists: it has a chairman, a seven-person board, a director-general, an office in Colombo and it publishes circulars and draft rules. But it has never issued a fine or a decision, and legally it cannot yet. The Authority itself says in writing that it will only investigate complaints once the relevant sections are switched on. The penalty section still has no start date.High confidence
- How long must I keep it, and when must I delete it?
- The floor is clearer than the ceiling. Banks, finance companies and other reporting institutions must keep transaction records for six years, and identity records for six years after the account closes. The ceiling is a principle, not a number: from 1 January 2027 you must not keep personal data in a form that identifies someone for longer than the purpose needs. Where the two clash, the six-year legal duty wins.High confidence
- What happens when something goes wrong?
- There is no deadline, because there is no duty yet. This is unusual and worth saying plainly: as of 18 August 2026 a company suffering a data breach in Sri Lanka has no legal obligation to tell anyone. Reporting to the national cyber team is voluntary. From 1 January 2027 you must notify the Authority, but the rules that set the form and the clock are still a draft. Banks are the exception and must report technology and cyber incidents to the Central Bank.High confidence
- What's the trap?
- Five things that will cost you a weekend. A child in Sri Lanka is anyone under sixteen, not eighteen, and a parent must consent for them. Fines are small but personal: directors can be made to pay unless they prove they did not know. The advertised start date of 18 March 2025 was cancelled four days before it arrived, so anything written before November 2025 is wrong. Company data is not protected the way you would expect, because the individual-rights section still has no start date. And the published transfer guidance describes a law that no longer exists.High confidence
- What's about to change?
- One hard date and four switches. On 1 January 2027 the scope, the processing duties and the controller duties all start, and the Central Bank's new outsourcing rules for banks start the same day. Before then the Authority is expected to finalise its rules on breach reporting, impact assessments, data protection officers and overseas transfers. Watch also for a second gazette bringing individual rights and the penalty section into force — without it, the law has duties but no teeth.High confidence
- Hardest industry wall
- Government — Personal Data Protection Act section 26(4) and 26(5), as substituted by Act No. 22 of 2025
Hong Kong SARChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Hong Kong's privacy law contains a cross-border transfer ban that has never been switched on. It was written in 1995 and, thirty years later, still has no start date. So under the general law you can send personal data anywhere with no paperwork at all. The privacy regulator is busy and prosecutes people, but it cannot fine you directly.
- The catch
- The free-for-all stops at three doors. Licensed securities and futures firms need written permission from the markets regulator before their records live only on servers outside Hong Kong. Government departments are told not to put sensitive or personal information on public cloud at all. And data coming the other way, from mainland China into Hong Kong, is tightly controlled by mainland law, not by Hong Kong law - that is the wall most companies actually hit.
- Does this apply to me?
- Yes, it can reach you with no office in Hong Kong. The privacy law bites on whoever controls the collection, holding, use or processing of personal data in or from Hong Kong, so a foreign company running a Hong Kong-facing service is caught. There is no revenue or headcount threshold to fall below, no register to join, and no requirement to appoint a local representative. The anti-doxxing powers go further still: the regulator can order an overseas platform to take material down.High confidence
- Can the data leave the country?
- Under the general privacy law, yes - freely, with nothing to sign. The one section that would have restricted transfers abroad was written into the law in 1995 and has never been brought into operation, so today there is no legal control on personal data leaving Hong Kong. Industry rules are where the real limits sit, and there are fewer of them than people expect: the securities regulator is the main one, and government departments have their own restriction.High confidence
- What do I have to do to send it abroad?
- Nothing. There is no approval to seek, no standard contract to sign and no government list to check before personal data leaves Hong Kong. The model on paper is an allowlist - the regulator would publish a list of approved destinations - but because the section was never switched on, that list has never been issued and is empty. The regulator does publish a voluntary guide and encourages firms to build the safeguards now, but that is advice, not law.High confidence
- Who enforces this — and are they actually working?
- The Privacy Commissioner for Personal Data, and it is genuinely busy. By the end of December 2025 it had issued 2,104 orders to 57 online platforms to take down 33,743 doxxing messages, opened 519 criminal investigations and arrested 81 people. But there is a catch that changes the risk picture completely: the Commissioner cannot impose a fine for breaking the privacy principles. It serves a notice telling you to fix the problem, and only ignoring that notice is a crime.High confidence
- How long must I keep it, and when must I delete it?
- There is a hard ceiling and almost no floor in the privacy law itself. You must erase personal data once it is no longer needed for the purpose you collected it for, and failing to do so is a criminal offence carrying a fine of up to HK$10,000 (about $1,300). The privacy law sets no minimum keeping periods; those come from tax, company and anti-money-laundering law instead. Where the two pull against each other, the specific keeping duty in the other law wins, and you delete once it expires.Medium confidence
- What happens when something goes wrong?
- For a normal data breach there is no deadline, because there is no duty. Telling the Privacy Commissioner about a breach is voluntary in Hong Kong - the regulator asks you to do it as good practice and gives you a form, but no law compels it. That is unusual and it is changing: since 1 January 2026 operators of designated critical infrastructure must report computer-system security incidents, so those firms now have a real clock while everyone else has none.High confidence
- What's the trap?
- Five things that catch people out. First, marketing mistakes are crimes here, not fines - using someone's data for direct marketing without the right consent can mean five years in prison. Second, the regulator cannot fine you, so people assume the risk is low and miss the criminal exposure entirely. Third, Hong Kong sets no age at which a child can consent, so there is no simple number to code into a sign-up flow. Fourth, licensed securities firms need written permission before their records live only on overseas servers, and two named people who live in Hong Kong must be able to unlock them. Fifth, the dormant transfer section, if ever switched on, would also catch data moving between two foreign countries when a Hong Kong company controls it.Medium confidence
- What's about to change?
- Nothing is scheduled to land in the next twelve months that we could confirm. The critical infrastructure security law already started on 1 January 2026, and the government's guideline for generative artificial intelligence was revised in December 2025. The thing to watch is not a new bill. It is a switch the government has held for thirty years: the cross-border transfer section can be brought into force by a simple commencement notice, with no consultation and no new vote.Medium confidence
- Hardest industry wall
- None found.