Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
LatviaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- Latvia follows European Union privacy rules, so personal data may leave the country once the right paperwork is in place. But Latvia adds its own walls. Accounting records may not be stored outside the European Union at all. Phone and internet companies must hold call records for eighteen months. Banks need the central bank's blessing before handing systems to an outside supplier.
- The catch
- The relaxed European headline stops being true the moment you touch four things. (1) Accounting records: paper must stay in Latvia and electronic copies must stay inside the European Union, so a United States accounting or resource-planning cloud is unlawful for a Latvian company. (2) Telecoms: eighteen months of call and connection records, plus a gag on telling the customer. (3) Banking: significant outsourcing needs a filing with the central bank and a thirty-working-day wait. (4) State critical computer systems: the supplier and its owners must be from a NATO, European Union, European Free Trade Association or NATO Indo-Pacific partner country, and audit information may only be handled inside that same group of countries.
- Does this apply to me?
- Yes. A company with no office in Latvia is still caught if it offers goods or services to people in Latvia or watches what they do online. That reach comes from the European Union privacy regulation, which applies directly in Latvia. There is no size or revenue threshold to duck under. A company based outside Europe normally has to name a contact person inside the European Union. Latvia's own privacy act adds national detail rather than a separate territorial test.High confidence
- Can the data leave the country?
- Personal data can leave Latvia, but the answer flips depending on what kind of data it is. For ordinary personal data the European rules apply: send it anywhere with the right legal instrument. For accounting records the door is shut at the edge of the European Union — paper stays in Latvia, electronic files stay inside the European Union. Phone and internet companies must keep eighteen months of call records. Banks must clear big outsourcing deals with the central bank first. State critical computer systems can only be supplied and audited from allied countries.High confidence
- What do I have to do to send it abroad?
- For personal data the model is a permission list, not a ban list. You may send data to a country the European Commission has approved, or use the European Union's standard contract template, or use approved group-wide rules. The approved list is real and long — it includes the United Kingdom, Japan, South Korea, Switzerland and, for self-certified companies only, the United States. For accounting records none of this helps: the wall is geographic, and no contract unlocks it.High confidence
- Who enforces this — and are they actually working?
- The privacy regulator is the State Data Inspectorate, and it is genuinely working, not a name on a door. In 2025 it took 1,034 complaints, ran 1,396 checks, applied corrective measures 62 times and issued fines totalling 326,400 euros (about $355,000), the largest single fine being 300,000 euros (about $327,000). It has about 32 staff. In the first half of 2026 it received 832 complaints and opened 73 checks of its own motion. Separate regulators handle banking, telecoms and cyber security, and all are staffed.High confidence
- How long must I keep it, and when must I delete it?
- Latvia has an unusually crowded set of minimum keeping periods and one surprising maximum. You must keep accounting registers ten years and supporting documents at least five. Phone and internet companies must keep call records eighteen months. Medical records run from one year to forty years depending on the form. In the other direction, security audit trails must normally be deleted after one year — shorter than many global logging policies allow.High confidence
- What happens when something goes wrong?
- Count at least two clocks, and often three. If personal data is exposed you have 72 hours to tell the State Data Inspectorate, and you must tell affected people without delay if the risk to them is high. If you run an essential or important service you also have 24 hours to send an early warning to the cyber incident response body, then 72 hours for a first report — and trust service providers get only 24 hours for that first report too. Banks have a third set of reporting duties under European financial rules.High confidence
- What's the trap?
- Five things that are not in the summary. One: a child can consent from age 13, not 16, so a Latvian teenager can sign up without a parent. Two: mishandling personal data can be a crime, not just a fine, and a company's responsible employee faces up to four years in prison. Three: your accounting system cannot sit outside the European Union, and its entries must be made in Latvian. Four: audit logs must usually be deleted after one year. Five: a bank cannot move systems to a new supplier until it has filed with the central bank and waited thirty working days.High confidence
- What's about to change?
- Two dated items and three switches. On 12 January 2027 the European Data Act bans cloud providers from charging customers to move their data out — a real change to cloud contracts used in Latvia. On 14 October 2026 Latvia holds its next data protection specialist qualification examination. The switches: the government may still write binding rules on where computer systems are hosted and has not done so; the European Union's approval of United States data transfers is under formal challenge; and the cyber security law is being amended piece by piece.Medium confidence
- Hardest industry wall
- All industries — Grāmatvedības likums
- Government — Ministru kabineta noteikumi Nr. 397 "Minimālās kiberdrošības prasības"
IrelandChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
- In one paragraph
- Ireland follows Europe's rules, so personal data can leave the country once you have the right paperwork in place. But a handful of Irish laws force certain records to be kept physically in Ireland, and breaking those is a crime rather than a fine. Ireland's privacy regulator is one of the toughest in Europe: in 2025 it fined TikTok 530 million euro and ordered it to stop sending data to China.
- The catch
- The relaxed headline stops being true in four places. Trust and company service providers, and cheque-cashing firms, must keep their anti-money-laundering records at premises inside Ireland for six years, and failing to do so is a criminal offence carrying up to five years in prison. Every Irish company must keep accounting information and returns at a place in Ireland even when the books themselves sit on a foreign server. Health records and telephone and internet connection records each have their own separate rules on top.
- Does this apply to me?
- Yes. Ireland's data protection law reaches a company with no office in Ireland whenever it offers goods or services to people in Europe or watches what they do online. There is no revenue or headcount threshold to duck under. A company based outside Europe normally has to name a representative inside Europe who regulators and members of the public can write to.High confidence
- Can the data leave the country?
- In general, yes, with paperwork. Ireland does not have a general rule saying personal data must stay in the country. Sending it outside Europe is allowed once you use one of the approved legal routes. But several Irish laws quietly demand that particular records sit on Irish soil, and those override the friendly headline.High confidence
- What do I have to do to send it abroad?
- Ireland uses the European model. A destination outside Europe is off limits unless it is on the European Commission's approved list, or you put an approved safeguard in place first. The approved list is real and populated: it currently covers seventeen destinations, including the United Kingdom, Japan, South Korea, Switzerland and Brazil. The United States counts only for companies that have signed up to the European Union to United States Data Privacy Framework.High confidence
- Who enforces this — and are they actually working?
- The Data Protection Commission, and it is very much awake. It has three commissioners in post — Des Hogan as chairperson, Dale Sunderland and Niamh Sweeney — and it published its 2025 annual report on 30 June 2026. In 2025 it finished four large inquiries and imposed fines of just over 530 million euro (about 580 million US dollars), almost all of it on TikTok, which it also ordered to stop sending European user data to China.High confidence
- How long must I keep it, and when must I delete it?
- Both directions apply, and Ireland's floors are longer than most people expect. Anti-money-laundering customer records must be kept for at least five years. Company accounting records and returns must be kept for at least six years. Trust and company service providers and cheque-cashing firms must keep their records for six years and keep them in Ireland. Telephone and internet providers must keep subscriber details for one year.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. You have 72 hours to tell the Data Protection Commission about a personal data breach that puts people at risk, and you must tell the affected people without delay if the risk is high. Telephone and internet providers report through a separate channel under separate rules. And if the police send you an order to take down terrorist content, you have one hour.High confidence
- What's the trap?
- Five things that cost people their weekend. First, Ireland's famous ban on advertising to children has never actually switched on. Second, the official copy of the law on the government's own statute website can be out of date and misleading. Third, a child in Ireland is anyone under 16 for consent purposes, not 13. Fourth, some record-keeping failures are crimes, not fines. Fifth, the regulator can only fine a public body up to 1 million euro (about 1.1 million US dollars), so it uses stop orders instead.High confidence
- What's about to change?
- Three things land in the next year. Ireland's new health records law is switching on in stages, and the parts that let doctors share your file and that allow sharing with countries outside Europe are still switched off. Europe's cloud switching rules make all data exit fees zero on 12 January 2027. And Ireland still has not written the European cybersecurity directive into Irish law, almost two years past the deadline.High confidence
- Hardest industry wall
- Finance — Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 106
- Payments — Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 108I
- All industries — Companies Act 2014, sections 283 and 285