Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
LatviaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Latvia follows European Union privacy rules, so personal data may leave the country once the right paperwork is in place. But Latvia adds its own walls. Accounting records may not be stored outside the European Union at all. Phone and internet companies must hold call records for eighteen months. Banks need the central bank's blessing before handing systems to an outside supplier.
The catch
The relaxed European headline stops being true the moment you touch four things. (1) Accounting records: paper must stay in Latvia and electronic copies must stay inside the European Union, so a United States accounting or resource-planning cloud is unlawful for a Latvian company. (2) Telecoms: eighteen months of call and connection records, plus a gag on telling the customer. (3) Banking: significant outsourcing needs a filing with the central bank and a thirty-working-day wait. (4) State critical computer systems: the supplier and its owners must be from a NATO, European Union, European Free Trade Association or NATO Indo-Pacific partner country, and audit information may only be handled inside that same group of countries.
Does this apply to me?
Yes. A company with no office in Latvia is still caught if it offers goods or services to people in Latvia or watches what they do online. That reach comes from the European Union privacy regulation, which applies directly in Latvia. There is no size or revenue threshold to duck under. A company based outside Europe normally has to name a contact person inside the European Union. Latvia's own privacy act adds national detail rather than a separate territorial test.High confidence
Can the data leave the country?
Personal data can leave Latvia, but the answer flips depending on what kind of data it is. For ordinary personal data the European rules apply: send it anywhere with the right legal instrument. For accounting records the door is shut at the edge of the European Union — paper stays in Latvia, electronic files stay inside the European Union. Phone and internet companies must keep eighteen months of call records. Banks must clear big outsourcing deals with the central bank first. State critical computer systems can only be supplied and audited from allied countries.High confidence
What do I have to do to send it abroad?
For personal data the model is a permission list, not a ban list. You may send data to a country the European Commission has approved, or use the European Union's standard contract template, or use approved group-wide rules. The approved list is real and long — it includes the United Kingdom, Japan, South Korea, Switzerland and, for self-certified companies only, the United States. For accounting records none of this helps: the wall is geographic, and no contract unlocks it.High confidence
Who enforces this — and are they actually working?
The privacy regulator is the State Data Inspectorate, and it is genuinely working, not a name on a door. In 2025 it took 1,034 complaints, ran 1,396 checks, applied corrective measures 62 times and issued fines totalling 326,400 euros (about $355,000), the largest single fine being 300,000 euros (about $327,000). It has about 32 staff. In the first half of 2026 it received 832 complaints and opened 73 checks of its own motion. Separate regulators handle banking, telecoms and cyber security, and all are staffed.High confidence
How long must I keep it, and when must I delete it?
Latvia has an unusually crowded set of minimum keeping periods and one surprising maximum. You must keep accounting registers ten years and supporting documents at least five. Phone and internet companies must keep call records eighteen months. Medical records run from one year to forty years depending on the form. In the other direction, security audit trails must normally be deleted after one year — shorter than many global logging policies allow.High confidence
What happens when something goes wrong?
Count at least two clocks, and often three. If personal data is exposed you have 72 hours to tell the State Data Inspectorate, and you must tell affected people without delay if the risk to them is high. If you run an essential or important service you also have 24 hours to send an early warning to the cyber incident response body, then 72 hours for a first report — and trust service providers get only 24 hours for that first report too. Banks have a third set of reporting duties under European financial rules.High confidence
What's the trap?
Five things that are not in the summary. One: a child can consent from age 13, not 16, so a Latvian teenager can sign up without a parent. Two: mishandling personal data can be a crime, not just a fine, and a company's responsible employee faces up to four years in prison. Three: your accounting system cannot sit outside the European Union, and its entries must be made in Latvian. Four: audit logs must usually be deleted after one year. Five: a bank cannot move systems to a new supplier until it has filed with the central bank and waited thirty working days.High confidence
What's about to change?
Two dated items and three switches. On 12 January 2027 the European Data Act bans cloud providers from charging customers to move their data out — a real change to cloud contracts used in Latvia. On 14 October 2026 Latvia holds its next data protection specialist qualification examination. The switches: the government may still write binding rules on where computer systems are hosted and has not done so; the European Union's approval of United States data transfers is under formal challenge; and the cyber security law is being amended piece by piece.Medium confidence
Hardest industry wall
  • All industries Grāmatvedības likums
  • Government Ministru kabineta noteikumi Nr. 397 "Minimālās kiberdrošības prasības"
SpainChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
In one paragraph
Spain follows the normal European rule: personal data may leave the country once you have the right paperwork in place. But four named categories of data held by the Spanish state must physically stay inside the European Union, and may only travel further to a country Europe has officially approved. Spain's privacy regulator is one of the busiest in the world.
The catch
The relaxed headline stops being true the moment you touch the electoral roll, town-hall population registers, Spanish tax records or data about users of the Spanish national health service. For those four things a standard European transfer contract is not enough and never will be — the law allows only officially approved destinations. Online gambling, telecoms and any system sold to the Spanish public sector carry their own separate rules.
Does this apply to me?
Yes. A company with no office in Spain is still caught if it offers goods or services to people in Spain or watches what they do online. There is no size or revenue threshold to hide under. If you have no base anywhere in Europe you must appoint a written representative inside Europe, and Spain's regulator will happily deal with that representative instead of you.High confidence
Can the data leave the country?
For most businesses, yes, with paperwork — the ordinary European rules apply and nothing in Spanish law says data must sit on Spanish soil. The exception is sharp. If the data is the electoral roll, a town-hall population register, Spanish tax records, or information about users of the Spanish national health service, the computers holding it must be inside the European Union, and that data may only go outside Europe to a country Europe has officially approved. A standard European transfer contract does not work for those four things.High confidence
What do I have to do to send it abroad?
The model is an approved-list one, run at European level, not by Spain. You may send data outside Europe if the destination country is on Europe's approved list, or if you sign Europe's standard contract, or if your corporate group has approved internal rules. The list is real and populated. Spain adds one twist: if you want to use a home-made contract instead of the standard one, you must get written permission from the Spanish regulator first.High confidence
Who enforces this — and are they actually working?
The Spanish Data Protection Agency, and it is very much awake. Its public decision database held 46,925 decisions when we checked on 18 August 2026, with rulings signed as recently as 12 August 2026. Three regional authorities also enforce, covering public bodies in Catalonia, the Basque Country and Andalusia. Spain's artificial intelligence supervisor is now operating too and met the privacy agency in July 2026 to divide up the work.High confidence
How long must I keep it, and when must I delete it?
Both directions, and they collide. The longest floor is money laundering records: ten years, and the same law then orders you to destroy them. Business books run six years, clinical records at least five years from the end of each course of treatment, phone and internet connection records twelve months, and the taxman can come back four years. In the other direction Spain does something unusual: when someone asks you to delete their data you must not actually delete it, you must lock it away.High confidence
What happens when something goes wrong?
Count three clocks, not one. Everyone has 72 hours to tell the privacy regulator about a personal data breach. Phone and internet providers have only 24 hours under a separate European rule. And if you run something the state treats as an essential service, the cyber clock says report immediately, then send an update within 24 to 48 hours if the incident is critical, or 72 hours if it is very serious, with a final report 20 or 40 days later.High confidence
What's the trap?
Five things that ruin weekends. One: a child can consent at fourteen in Spain, not sixteen, so your global age gate is probably wrong here. Two: 'delete my data' legally means 'lock my data away', so a hard-delete pipeline breaks the law. Three: Spain forces far more organisations to appoint a data protection officer than Europe does, including every school, university, bank, insurer, energy supplier and online gambling operator. Four: misusing someone's personal records is a crime punishable by prison, and companies themselves can be prosecuted. Five: telecoms operators can be ordered to hand over the encryption method they use.High confidence
What's about to change?
The biggest thing is what has not happened. Spain still has not passed the law that brings Europe's new cybersecurity rules into Spanish law, so the old 2018 regime is still what binds — expect that to change and to widen sharply who must report incidents. From 12 January 2027 no cloud provider may charge you to leave or to pull your data out. Watch three switches the government can flip with no consultation: taking over telecoms networks, ordering gambling systems into Spain, and demanding an operator's encryption method.Medium confidence
Hardest industry wall
None found.