Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
LuxembourgChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
For most businesses, data can leave Luxembourg on the same terms as anywhere else in the European Union: you need the right paperwork, not a local data centre. Finance is the exception, and finance is most of the economy here. Banks and insurers are bound by a secrecy duty that is a crime to break, and a bank that runs its accounts abroad must still keep a daily backup inside Europe.
The catch
The relaxed general answer stops the moment you touch banking, insurance or investment funds. There, three things bite: breaking client secrecy is a criminal offence, not a fine; you may only send client information to a supplier abroad if the client has accepted the outsourcing, the type of information and the country the supplier sits in; and if a bank's accounting system is hosted outside Luxembourg it must still hold a full end-of-day backup on premises inside the European Economic Area. Telecoms firms face a separate 6-month duty to keep call and location records.
Does this apply to me?
Yes. If you sell to people in Luxembourg or watch what they do online, the European privacy rules reach you even with no office here. There is no revenue or headcount threshold to hide under. A company with no base anywhere in Europe must appoint a representative in Europe, though it does not have to be in Luxembourg. The extra Luxembourg-only duties in the national law mostly apply to organisations that are actually set up here.High confidence
Can the data leave the country?
In general, yes, with paperwork. Luxembourg has no national law telling ordinary companies to keep data in the country, and European law actually forbids member states from forcing non-personal data to stay put except on public-security grounds. But this is a banking and fund centre, and the finance rules change the answer. A bank or insurer may only hand client information to a supplier abroad if the client has been told and has accepted which country that supplier is in. And a bank whose accounting system sits outside Luxembourg must still keep a full daily backup somewhere inside the European Economic Area.High confidence
What do I have to do to send it abroad?
The model is a European approved-list. Sending personal data outside Europe is barred unless the destination is on the European Commission's approved list, or you put an approved safeguard in place first. The list is real and populated. Luxembourg adds no national permit and the regulator does not pre-approve ordinary transfers. In finance, though, you also need the client's acceptance of the destination country before their information moves.High confidence
Who enforces this — and are they actually working?
Yes, the regulators here really work. The privacy regulator is the National Commission for Data Protection, known as the CNPD. It is staffed, it publishes decisions, and in 2025 it handled 846 complaints, 425 breach reports and 59 investigations. It issued the largest privacy fine ever recorded in Europe, against Amazon in 2021. The financial regulator and the insurance regulator are heavyweight supervisors in their own right, and since May 2026 the telecoms regulator also runs the national cybersecurity regime.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and they collide often. You must keep anti-money-laundering records for 5 years after the relationship ends, patient files for at least 10 years after care ends, and telephone and internet connection records for 6 months. In the other direction, European privacy law says delete personal data once you no longer need it, and the anti-money-laundering law says delete it when the 5 years are up unless another law makes you keep it longer. That last sentence is how Luxembourg resolves the clash: the longest specific legal duty wins, and after that you must actually erase.High confidence
What happens when something goes wrong?
Count four clocks, because they overlap and they start at different moments. Privacy breach: 72 hours to tell the privacy regulator. Telephone and internet providers: 24 hours to report a personal data breach. Cybersecurity incidents at important companies: an early warning in 24 hours, a fuller report in 72 hours, and a final report a month later. Banks and insurers have their own European reporting on top. The trap is that one incident can start all of them at once, on different teams, with different forms.High confidence
What's the trap?
Five things that are not in any summary. (1) Breaking bank or insurance client secrecy is a crime, not a fine, and it survives the end of the job. (2) Your works council can freeze an employee-monitoring project: staff have 15 days to ask the privacy regulator for an opinion, and that request suspends the project for a month. (3) Research projects carry a fixed list of 12 extra safeguards you must apply or justify skipping. (4) Using genetic data for employment or insurance purposes is banned outright. (5) The privacy regulator cannot fine the State or a commune, so a public body has far less to lose than you do.High confidence
What's about to change?
Two dated changes and several switches already in someone's hand. The dated ones: from 12 January 2027 cloud providers must let customers move away with no exit or transfer fees at all, and Luxembourg's new cybersecurity law, in force since 10 May 2026, is still being filled in with guidance and templates. The switches to watch: the European approval of United States transfers is under formal challenge, and the 6-month duty on telecoms firms to keep call records sits uneasily with European court rulings and could be struck at any time.Medium confidence
Hardest industry wall
  • Finance Circulaire CSSF 22/806 relative aux arrangements d'externalisation, telle que modifiee par la circulaire CSSF 25/883
ItalyChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
In one paragraph
Italy does not make ordinary business data stay in Italy. European rules decide when data may leave Europe, and Italy layers its own rules on top. But the moment you sell to the Italian state — a ministry, a town hall, a hospital, a school — the picture changes completely. The most sensitive government data has to sit on machines inside Italy, run from Italy.
The catch
"Italy has no data localisation" holds right up until your customer is a public body. Italian government data is sorted into ordinary, critical and strategic. Strategic data belongs on Italian soil under Italian operational control; critical data may not go on a public cloud outside Europe. On top of that, a cloud provider needs a licence from the national cyber agency before any public body is allowed to buy from it at all. Separately, telecoms companies must keep call and connection records for years, and the government can attach storage-location conditions to fifth-generation mobile and cloud contracts case by case.
Does this apply to me?
Yes, it reaches you with no office in Italy. European law applies to any organisation anywhere that offers goods or services to people in Italy, or that monitors what they do online. There is no size or revenue threshold to duck under. If you have no branch anywhere in Europe, you must appoint a written representative based in Europe, and people and regulators can go to that representative instead of chasing you abroad.High confidence
Can the data leave the country?
For a normal private company, yes — with paperwork, exactly as anywhere else in Europe. Italy has no general law saying personal data must be stored in Italy. The real walls are in one place: anything sold to or run by the Italian public sector. Government data is graded ordinary, critical or strategic, and the top two grades cannot sit on a public cloud outside Europe, with strategic data confined to infrastructure inside Italy and operated from Italy.High confidence
What do I have to do to send it abroad?
Three routes, and they are European rather than Italian. Best case, the destination is on Europe's official approved list and you need nothing extra. Otherwise you sign Europe's standard contract with the recipient, or get group-wide internal rules approved by a regulator. With the last two you must also write down an assessment of whether the destination country's surveillance laws would undermine the protection. Italy adds no extra permission step, but it does add a criminal offence for getting it badly wrong.High confidence
Who enforces this — and are they actually working?
The Italian data protection authority, known as the Garante, and it is one of the busiest and boldest regulators in Europe. In 2025 alone it took 807 decisions, of which 506 were corrective or punitive, ran 130 inspections and collected more than 37 million euros (about 41 million dollars) in fines. It was the first regulator in the world to order a temporary halt to a major chatbot service, and it has since blocked or restricted several artificial intelligence products. Cybersecurity is enforced by a separate agency.High confidence
How long must I keep it, and when must I delete it?
Both directions, and they pull hard against each other. The floors: telephone records must be kept 24 months, internet connection records 12 months, unanswered calls 30 days, and a separate six-year rule applies for terrorism and serious crime. Health records in the national system are erased 30 years after the patient dies. The ceiling is much tighter than people expect: the regulator says the technical logs behind staff email may normally be kept for no more than 21 days.High confidence
What happens when something goes wrong?
Count at least three clocks, and they run at the same time. A personal data breach goes to the Garante within 72 hours, and to the people affected without delay where the risk to them is high. If you are in scope of Italy's network security regime, a first warning goes to the national cyber agency within 24 hours, a fuller notification within 72 hours, and a final report within a month. Organisations inside the national cyber perimeter have a much shorter fuse, reported as six hours.Medium confidence
What's the trap?
Five. One: staff email logs may normally be kept only 21 days, and a regional government was punished in 2025 for keeping 90. Two: before you install any tool that could monitor employees, you need a union agreement or a labour inspectorate permit, and skipping it is a criminal matter, not a fine. Three: some data offences in Italy carry prison, not just penalties. Four: children can consent at 14 in Italy, not 16. Five: the widely reported rule forcing public-sector artificial intelligence onto Italian servers was deleted before the law passed, so citing it is wrong.High confidence
What's about to change?
Two firm dates and one open wound. By 31 October 2026 organisations in Italy's network security regime must have their basic security measures in place and evidenced. From 12 January 2027 every cloud provider must charge nothing for switching away or pulling data out. The open wound is the Italian regulator itself: one of four board seats has been empty since January 2026 and Parliament has not filled it.Medium confidence
Hardest industry wall
  • Government Regolamento unico per le infrastrutture e i servizi cloud per la PA — Determinazione ACN n. 21007/24