Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
LuxembourgChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
For most businesses, data can leave Luxembourg on the same terms as anywhere else in the European Union: you need the right paperwork, not a local data centre. Finance is the exception, and finance is most of the economy here. Banks and insurers are bound by a secrecy duty that is a crime to break, and a bank that runs its accounts abroad must still keep a daily backup inside Europe.
The catch
The relaxed general answer stops the moment you touch banking, insurance or investment funds. There, three things bite: breaking client secrecy is a criminal offence, not a fine; you may only send client information to a supplier abroad if the client has accepted the outsourcing, the type of information and the country the supplier sits in; and if a bank's accounting system is hosted outside Luxembourg it must still hold a full end-of-day backup on premises inside the European Economic Area. Telecoms firms face a separate 6-month duty to keep call and location records.
Does this apply to me?
Yes. If you sell to people in Luxembourg or watch what they do online, the European privacy rules reach you even with no office here. There is no revenue or headcount threshold to hide under. A company with no base anywhere in Europe must appoint a representative in Europe, though it does not have to be in Luxembourg. The extra Luxembourg-only duties in the national law mostly apply to organisations that are actually set up here.High confidence
Can the data leave the country?
In general, yes, with paperwork. Luxembourg has no national law telling ordinary companies to keep data in the country, and European law actually forbids member states from forcing non-personal data to stay put except on public-security grounds. But this is a banking and fund centre, and the finance rules change the answer. A bank or insurer may only hand client information to a supplier abroad if the client has been told and has accepted which country that supplier is in. And a bank whose accounting system sits outside Luxembourg must still keep a full daily backup somewhere inside the European Economic Area.High confidence
What do I have to do to send it abroad?
The model is a European approved-list. Sending personal data outside Europe is barred unless the destination is on the European Commission's approved list, or you put an approved safeguard in place first. The list is real and populated. Luxembourg adds no national permit and the regulator does not pre-approve ordinary transfers. In finance, though, you also need the client's acceptance of the destination country before their information moves.High confidence
Who enforces this — and are they actually working?
Yes, the regulators here really work. The privacy regulator is the National Commission for Data Protection, known as the CNPD. It is staffed, it publishes decisions, and in 2025 it handled 846 complaints, 425 breach reports and 59 investigations. It issued the largest privacy fine ever recorded in Europe, against Amazon in 2021. The financial regulator and the insurance regulator are heavyweight supervisors in their own right, and since May 2026 the telecoms regulator also runs the national cybersecurity regime.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and they collide often. You must keep anti-money-laundering records for 5 years after the relationship ends, patient files for at least 10 years after care ends, and telephone and internet connection records for 6 months. In the other direction, European privacy law says delete personal data once you no longer need it, and the anti-money-laundering law says delete it when the 5 years are up unless another law makes you keep it longer. That last sentence is how Luxembourg resolves the clash: the longest specific legal duty wins, and after that you must actually erase.High confidence
What happens when something goes wrong?
Count four clocks, because they overlap and they start at different moments. Privacy breach: 72 hours to tell the privacy regulator. Telephone and internet providers: 24 hours to report a personal data breach. Cybersecurity incidents at important companies: an early warning in 24 hours, a fuller report in 72 hours, and a final report a month later. Banks and insurers have their own European reporting on top. The trap is that one incident can start all of them at once, on different teams, with different forms.High confidence
What's the trap?
Five things that are not in any summary. (1) Breaking bank or insurance client secrecy is a crime, not a fine, and it survives the end of the job. (2) Your works council can freeze an employee-monitoring project: staff have 15 days to ask the privacy regulator for an opinion, and that request suspends the project for a month. (3) Research projects carry a fixed list of 12 extra safeguards you must apply or justify skipping. (4) Using genetic data for employment or insurance purposes is banned outright. (5) The privacy regulator cannot fine the State or a commune, so a public body has far less to lose than you do.High confidence
What's about to change?
Two dated changes and several switches already in someone's hand. The dated ones: from 12 January 2027 cloud providers must let customers move away with no exit or transfer fees at all, and Luxembourg's new cybersecurity law, in force since 10 May 2026, is still being filled in with guidance and templates. The switches to watch: the European approval of United States transfers is under formal challenge, and the 6-month duty on telecoms firms to keep call records sits uneasily with European court rulings and could be struck at any time.Medium confidence
Hardest industry wall
  • Finance Circulaire CSSF 22/806 relative aux arrangements d'externalisation, telle que modifiee par la circulaire CSSF 25/883
CanadaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Canada lets data leave the country. There is no approved-country list and no banned-country list. You stay responsible for the data wherever it goes, and you must tell people it may be handled abroad. The catch is that Canada is really ten jurisdictions at once, and several of them add hard storage rules on top of the national one.
The catch
The relaxed national answer stops being true the moment you touch four things: personal information about people in Quebec, a Nova Scotia public body or its suppliers, federal government data rated Protected B or higher, or a federally regulated bank. Add to that a brand-new cyber security law that says records about critical systems in banking, telecoms, energy and transport must be kept in Canada. In those places Canada is genuinely restrictive.
Does this apply to me?
Yes. Canada's national privacy law reaches a foreign company with no office here if it handles personal information about people in Canada as part of doing business. There is no revenue or headcount threshold that lets you out. You do not normally need a local representative, but payment companies are an exception: a payment firm based abroad that aims its service at people in Canada must register with the central bank and name an agent inside Canada to receive official notices.High confidence
Can the data leave the country?
In general, yes, and with no government permission. Canada's national law does not restrict where personal data is stored or processed. But the headline is wrong for at least six groups. Quebec makes you do a written risk assessment first — and that applies even to sending data to Ontario. Nova Scotia public bodies and their suppliers must keep the data in Canada. Federal government data rated Protected B or higher must sit in Canada. Banks must keep a full copy of their records on servers in Canada. And under the new cyber security law, records about critical systems must be kept in Canada.High confidence
What do I have to do to send it abroad?
At the national level there is no list at all — no approved countries, no banned countries, no government form to file. What you must do instead is stay accountable: put a contract or similar protection in place with whoever handles the data for you, and tell people plainly that their information may be processed in another country and could be seen by foreign courts, police or security agencies. Quebec is different and stricter: there you must complete a written privacy risk assessment before the data moves, and sign a written agreement.High confidence
Who enforces this — and are they actually working?
Canada has many regulators and they are all real, staffed and issuing decisions. The national one, the Privacy Commissioner of Canada, published findings against OpenAI, X, Bell and WestJet in the first half of 2026 alone. But it cannot fine anyone — it makes findings and recommendations, and a case has to go to the Federal Court for money. Quebec's regulator can fine, and has blocked a national grocery chain from switching on a face-recognition system. Banking, payments and cyber security each have their own separate supervisor.High confidence
How long must I keep it, and when must I delete it?
The floor and the ceiling pull in opposite directions. Tax law says keep your business records for six years after the tax year they relate to, and keep them at a place of business in Canada unless the tax authority agrees to somewhere else. Privacy law says the opposite: delete personal information once the reason you collected it has gone. Where the two clash, the duty to keep wins — but only for the specific records the law names, and only for as long as it names.High confidence
What happens when something goes wrong?
Count at least four clocks and they do not agree. The national privacy law gives no fixed number of hours — you report 'as soon as feasible', which in practice means days, not weeks. Payment firms get 48 hours to tell the central bank about a serious incident. Critical infrastructure operators will get no more than 72 hours to tell the national cyber agency, then must tell their own regulator immediately after. Health and provincial rules add more. The overlap is where people get caught: one incident, several reports, several deadlines.High confidence
What's the trap?
Five things that are not in any summary. Quebec's cross-border rule catches you sending data to Ontario, not just abroad. Quebec also makes you tell its regulator 60 days before you switch on any face or fingerprint system, and it has already blocked a big grocery chain from doing so. British Columbia repealed its keep-it-in-Canada rule in 2021, so trackers that still show it are wrong. Nova Scotia's Canada-only rule reaches private suppliers, with fines up to half a million dollars. And your tax records have to sit at a place of business in Canada.High confidence
What's about to change?
One big bill and one big law already passed. The bill is Canada's third attempt to replace its 25-year-old privacy law: it would force a written risk assessment before any personal data goes outside Canada, give people a right to have data deleted, treat everyone under 18 as sensitive, and set up a new commissioner. It was only introduced in June 2026 and is not law — do not plan around it as if it were. The law already passed is the cyber security act, which switches on in stages over the coming year.High confidence
Hardest industry wall
  • Government Personal Information International Disclosure Protection Act
  • Government Direction for Electronic Data Residency (ITPIN 2017-02), with the Policy on Service and Digital
  • Banking Guideline B-10 Third-Party Risk Management, read with Bank Act section 245 and the equivalent provisions of the Insurance Companies Act and Trust and Loan Companies Act
  • All industries Critical Cyber Systems Protection Act, enacted by the Cyber Security Act (Bill C-8)