Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
LuxembourgChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- For most businesses, data can leave Luxembourg on the same terms as anywhere else in the European Union: you need the right paperwork, not a local data centre. Finance is the exception, and finance is most of the economy here. Banks and insurers are bound by a secrecy duty that is a crime to break, and a bank that runs its accounts abroad must still keep a daily backup inside Europe.
- The catch
- The relaxed general answer stops the moment you touch banking, insurance or investment funds. There, three things bite: breaking client secrecy is a criminal offence, not a fine; you may only send client information to a supplier abroad if the client has accepted the outsourcing, the type of information and the country the supplier sits in; and if a bank's accounting system is hosted outside Luxembourg it must still hold a full end-of-day backup on premises inside the European Economic Area. Telecoms firms face a separate 6-month duty to keep call and location records.
- Does this apply to me?
- Yes. If you sell to people in Luxembourg or watch what they do online, the European privacy rules reach you even with no office here. There is no revenue or headcount threshold to hide under. A company with no base anywhere in Europe must appoint a representative in Europe, though it does not have to be in Luxembourg. The extra Luxembourg-only duties in the national law mostly apply to organisations that are actually set up here.High confidence
- Can the data leave the country?
- In general, yes, with paperwork. Luxembourg has no national law telling ordinary companies to keep data in the country, and European law actually forbids member states from forcing non-personal data to stay put except on public-security grounds. But this is a banking and fund centre, and the finance rules change the answer. A bank or insurer may only hand client information to a supplier abroad if the client has been told and has accepted which country that supplier is in. And a bank whose accounting system sits outside Luxembourg must still keep a full daily backup somewhere inside the European Economic Area.High confidence
- What do I have to do to send it abroad?
- The model is a European approved-list. Sending personal data outside Europe is barred unless the destination is on the European Commission's approved list, or you put an approved safeguard in place first. The list is real and populated. Luxembourg adds no national permit and the regulator does not pre-approve ordinary transfers. In finance, though, you also need the client's acceptance of the destination country before their information moves.High confidence
- Who enforces this — and are they actually working?
- Yes, the regulators here really work. The privacy regulator is the National Commission for Data Protection, known as the CNPD. It is staffed, it publishes decisions, and in 2025 it handled 846 complaints, 425 breach reports and 59 investigations. It issued the largest privacy fine ever recorded in Europe, against Amazon in 2021. The financial regulator and the insurance regulator are heavyweight supervisors in their own right, and since May 2026 the telecoms regulator also runs the national cybersecurity regime.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling, and they collide often. You must keep anti-money-laundering records for 5 years after the relationship ends, patient files for at least 10 years after care ends, and telephone and internet connection records for 6 months. In the other direction, European privacy law says delete personal data once you no longer need it, and the anti-money-laundering law says delete it when the 5 years are up unless another law makes you keep it longer. That last sentence is how Luxembourg resolves the clash: the longest specific legal duty wins, and after that you must actually erase.High confidence
- What happens when something goes wrong?
- Count four clocks, because they overlap and they start at different moments. Privacy breach: 72 hours to tell the privacy regulator. Telephone and internet providers: 24 hours to report a personal data breach. Cybersecurity incidents at important companies: an early warning in 24 hours, a fuller report in 72 hours, and a final report a month later. Banks and insurers have their own European reporting on top. The trap is that one incident can start all of them at once, on different teams, with different forms.High confidence
- What's the trap?
- Five things that are not in any summary. (1) Breaking bank or insurance client secrecy is a crime, not a fine, and it survives the end of the job. (2) Your works council can freeze an employee-monitoring project: staff have 15 days to ask the privacy regulator for an opinion, and that request suspends the project for a month. (3) Research projects carry a fixed list of 12 extra safeguards you must apply or justify skipping. (4) Using genetic data for employment or insurance purposes is banned outright. (5) The privacy regulator cannot fine the State or a commune, so a public body has far less to lose than you do.High confidence
- What's about to change?
- Two dated changes and several switches already in someone's hand. The dated ones: from 12 January 2027 cloud providers must let customers move away with no exit or transfer fees at all, and Luxembourg's new cybersecurity law, in force since 10 May 2026, is still being filled in with guidance and templates. The switches to watch: the European approval of United States transfers is under formal challenge, and the 6-month duty on telecoms firms to keep call records sits uneasily with European court rulings and could be struck at any time.Medium confidence
- Hardest industry wall
- Finance — Circulaire CSSF 22/806 relative aux arrangements d'externalisation, telle que modifiee par la circulaire CSSF 25/883
ArmeniaChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Dormant
- In one paragraph
- Armenia lets personal data leave, but only to a country on an official approved list of 53 states, or with case-by-case permission from the privacy regulator. That regulator has had no boss since February 2026 and the largest fine it can impose is about 1,300 US dollars. The real constraints are elsewhere: government data sent to a foreign cloud must keep a backup copy inside Armenia, and banking and medical secrecy sit outside the privacy law entirely.
- The catch
- The approved-country list is worthless in three places. Government bodies must keep an in-country backup of anything they put in a cloud abroad. Bank, notarial, lawyer and insurance secrets are carved out of the privacy law and are governed by their own secrecy statutes, which list exhaustively who may see the data and do not mention foreign cloud providers. And leaking medical secrets is a crime that can put a named individual in prison, not just a fine on the company.
- Does this apply to me?
- Probably not, if you have nothing in Armenia. The privacy law describes who it covers by naming Armenian public bodies, companies and individuals who process personal data. It contains no clause saying it follows Armenians' data abroad, and no rule requiring a foreign company to appoint someone inside Armenia. There is no size or revenue threshold either, so a one-person Armenian business is caught exactly like a bank.Medium confidence
- Can the data leave the country?
- Yes, with paperwork. Armenia runs an approved-country list: if the destination is on it, you can send data with no permission from anyone. The list is real and populated — 53 countries, including all of the European Union, the United Kingdom, Canada, Japan, South Korea, Israel, Georgia and Russia. Sending data anywhere else needs written permission from the privacy regulator first, and that regulator currently has nobody in the chair. Three sectors override this entirely: government, banking-type secrets, and health.High confidence
- What do I have to do to send it abroad?
- The model is an approved list, and the list is full. Fifty-three countries were approved on 8 July 2024 and that decision has never been changed. If your destination is on it you need nothing — no standard contract, no filing, no fee. If it is not on it, you must write to the regulator before you send anything, attach the contract you plan to sign, and wait up to 30 days for a yes or a no.High confidence
- Who enforces this — and are they actually working?
- On paper, the Personal Data Protection Agency inside the Ministry of Justice. In practice, nobody right now: its head resigned with effect from 24 February 2026 and no replacement appointment has been published. In more than eleven years the agency has published exactly one general decision — the approved-country list. Two other regulators are genuinely working: the Central Bank supervises banks, payment firms, insurers and securities, and a brand-new Information Systems Regulatory Commission was appointed in March and April 2026 to police cybersecurity and state computer systems.Medium confidence
- How long must I keep it, and when must I delete it?
- The floor is five years for anything that proves your tax position. The ceiling is not a number — it is a principle: you must destroy or block personal data as soon as you no longer need it for the purpose you collected it for. Two hard clocks sit inside that principle. If someone withdraws consent you have ten working days to destroy their data, then three more working days to tell them you did. If you spot unlawful processing you have three working days to fix it or destroy the data.High confidence
- What happens when something goes wrong?
- Count three clocks. Under the privacy law, if data leaks out of your electronic systems you must immediately publish a public announcement about it and at the same time tell the Armenian police and the privacy regulator — there is no grace period and no threshold. If you run a system in a sector the state calls vital, you have 24 hours to tell the cybersecurity regulator, 72 hours to send an update, two days to warn the people affected, and one month to file a final report. Both sets of duties can bite at once.High confidence
- What's the trap?
- Five things that will ruin your week. One: a data leak must be announced publicly and reported to the police, not just to the regulator. Two: encryption is legally compulsory, not a best practice, and failing to use it is its own separate fine. Three: before you process biometric or sensitive data you must notify the regulator in advance and wait to be entered in its register. Four: to process a dead person's data you need the consent of all of their legal heirs. Five: a child is anyone under 16 here, not 13 and not 18.High confidence
- What's about to change?
- Armenia rewired its digital rulebook in December 2025 and the deadlines land through 2026, 2027 and 2028. Rules for cyber incidents and for state computer systems are already live. Detailed technical rules are due by January 2027, internal cybersecurity policies and risk assessments by July 2027, and security certificates for critical systems by January 2028. The change most likely to catch someone out is not a new law at all: the approved-country list can be rewritten by one official's signature.High confidence
- Hardest industry wall
- Government — «Ամպայինն առաջինը» քաղաքականության մշակման և ներդրման մասին ՀՀ կառավարության որոշում