Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
LatviaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- Latvia follows European Union privacy rules, so personal data may leave the country once the right paperwork is in place. But Latvia adds its own walls. Accounting records may not be stored outside the European Union at all. Phone and internet companies must hold call records for eighteen months. Banks need the central bank's blessing before handing systems to an outside supplier.
- The catch
- The relaxed European headline stops being true the moment you touch four things. (1) Accounting records: paper must stay in Latvia and electronic copies must stay inside the European Union, so a United States accounting or resource-planning cloud is unlawful for a Latvian company. (2) Telecoms: eighteen months of call and connection records, plus a gag on telling the customer. (3) Banking: significant outsourcing needs a filing with the central bank and a thirty-working-day wait. (4) State critical computer systems: the supplier and its owners must be from a NATO, European Union, European Free Trade Association or NATO Indo-Pacific partner country, and audit information may only be handled inside that same group of countries.
- Does this apply to me?
- Yes. A company with no office in Latvia is still caught if it offers goods or services to people in Latvia or watches what they do online. That reach comes from the European Union privacy regulation, which applies directly in Latvia. There is no size or revenue threshold to duck under. A company based outside Europe normally has to name a contact person inside the European Union. Latvia's own privacy act adds national detail rather than a separate territorial test.High confidence
- Can the data leave the country?
- Personal data can leave Latvia, but the answer flips depending on what kind of data it is. For ordinary personal data the European rules apply: send it anywhere with the right legal instrument. For accounting records the door is shut at the edge of the European Union — paper stays in Latvia, electronic files stay inside the European Union. Phone and internet companies must keep eighteen months of call records. Banks must clear big outsourcing deals with the central bank first. State critical computer systems can only be supplied and audited from allied countries.High confidence
- What do I have to do to send it abroad?
- For personal data the model is a permission list, not a ban list. You may send data to a country the European Commission has approved, or use the European Union's standard contract template, or use approved group-wide rules. The approved list is real and long — it includes the United Kingdom, Japan, South Korea, Switzerland and, for self-certified companies only, the United States. For accounting records none of this helps: the wall is geographic, and no contract unlocks it.High confidence
- Who enforces this — and are they actually working?
- The privacy regulator is the State Data Inspectorate, and it is genuinely working, not a name on a door. In 2025 it took 1,034 complaints, ran 1,396 checks, applied corrective measures 62 times and issued fines totalling 326,400 euros (about $355,000), the largest single fine being 300,000 euros (about $327,000). It has about 32 staff. In the first half of 2026 it received 832 complaints and opened 73 checks of its own motion. Separate regulators handle banking, telecoms and cyber security, and all are staffed.High confidence
- How long must I keep it, and when must I delete it?
- Latvia has an unusually crowded set of minimum keeping periods and one surprising maximum. You must keep accounting registers ten years and supporting documents at least five. Phone and internet companies must keep call records eighteen months. Medical records run from one year to forty years depending on the form. In the other direction, security audit trails must normally be deleted after one year — shorter than many global logging policies allow.High confidence
- What happens when something goes wrong?
- Count at least two clocks, and often three. If personal data is exposed you have 72 hours to tell the State Data Inspectorate, and you must tell affected people without delay if the risk to them is high. If you run an essential or important service you also have 24 hours to send an early warning to the cyber incident response body, then 72 hours for a first report — and trust service providers get only 24 hours for that first report too. Banks have a third set of reporting duties under European financial rules.High confidence
- What's the trap?
- Five things that are not in the summary. One: a child can consent from age 13, not 16, so a Latvian teenager can sign up without a parent. Two: mishandling personal data can be a crime, not just a fine, and a company's responsible employee faces up to four years in prison. Three: your accounting system cannot sit outside the European Union, and its entries must be made in Latvian. Four: audit logs must usually be deleted after one year. Five: a bank cannot move systems to a new supplier until it has filed with the central bank and waited thirty working days.High confidence
- What's about to change?
- Two dated items and three switches. On 12 January 2027 the European Data Act bans cloud providers from charging customers to move their data out — a real change to cloud contracts used in Latvia. On 14 October 2026 Latvia holds its next data protection specialist qualification examination. The switches: the government may still write binding rules on where computer systems are hosted and has not done so; the European Union's approval of United States data transfers is under formal challenge; and the cyber security law is being amended piece by piece.Medium confidence
- Hardest industry wall
- All industries — Grāmatvedības likums
- Government — Ministru kabineta noteikumi Nr. 397 "Minimālās kiberdrošības prasības"
SlovakiaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- Slovakia has no general rule that data must stay in the country. It runs on the European rulebook: send data abroad once you have the right paperwork. Three areas break that rule. Online gambling servers must sit on Slovak soil. The most sensitive government data must stay in a Slovak data centre. And anyone who takes aerial survey pictures of Slovakia must hand a copy to a defence ministry archive.
- The catch
- The easy answer stops being true in three places. First, online gambling: the operator's server must be physically in Slovakia, with no European Economic Area alternative. Second, government cloud: a public body handling the top security category of data may only use a service that stores and processes it inside Slovakia, in a data centre within reach of the Slovak state. Third, mapping: primary aerial survey imagery and published maps must be deposited with Slovak state archives, including one run by the Ministry of Defence. Banking, payments, insurance, securities, health and telecoms have no storage-location rule that we could find.
- Does this apply to me?
- Yes. A company with no office in Slovakia is still caught if it offers goods or services to people in Slovakia, or watches what they do online. There is no minimum size, headcount or revenue below which you are safe. If you have no office anywhere in the European Union, you must name a written representative inside the Union, and you can put that person in any member state where your customers are — it does not have to be Slovakia.High confidence
- Can the data leave the country?
- In general, yes — with the standard European paperwork. Nothing in Slovak law says personal data must be kept in Slovakia, and the law says so almost in as many words: it applies to a Slovak company whether it processes data inside or outside the country. But three specific activities do force data to stay. Online gambling operators must put their server in Slovakia. The top security tier of government data must stay in a Slovak data centre. And aerial survey imagery of Slovakia must be handed to a state archive.High confidence
- What do I have to do to send it abroad?
- Slovakia uses the European model, and it is an allowlist. Data may go to a country the European Commission has approved, or to anywhere else if you sign the Commission's standard contract, use approved group-wide rules, or fit one of a few narrow exceptions. The approved list is real and populated — it includes the United Kingdom, Switzerland, Japan, South Korea, Canada for commercial bodies, and the United States only for companies signed up to the transatlantic framework. Slovakia adds nothing of its own on top.High confidence
- Who enforces this — and are they actually working?
- The Office for Personal Data Protection of the Slovak Republic. It is real, staffed and busy. In 2025 it issued 542 final fines totalling about 468,000 euros (roughly $510,000) and actually collected about 411,000 euros of that — a very high number of fines but a very small average, about 860 euros each. It has around 60 staff and got 20 extra posts in 2025. Cybersecurity incidents go to a separate body, the National Security Authority.High confidence
- How long must I keep it, and when must I delete it?
- There is no single retention rule. The general privacy rule is to delete when you no longer need the data. Against that sit long minimum-keeping duties: ten years for accounts and financial statements, and up to one hundred years after death for entries in the national health registers. Telecom companies keep far less than most people assume — Slovakia scrapped blanket call-record retention after its Constitutional Court struck it down, so operators only retain what a court order covers.High confidence
- What happens when something goes wrong?
- There are two clocks and they are different. A personal data breach goes to the privacy authority within 72 hours of you becoming aware of it, and to the affected people without undue delay if the risk to them is high. A cybersecurity incident at a regulated organisation goes to the National Security Authority twice: a first warning within 24 hours, then a fuller report within 72 hours. If you are both, you file both, to two different bodies.High confidence
- What's the trap?
- Five things that are not in the summary. Public bodies can be fined the full amount, with no discount. Mishandling personal data you got through your job is a crime, not just a fine. The age of consent for online services is 16, not 13. The rule on dead people's data changed today. And the gambling server rule has no European workaround.High confidence
- What's about to change?
- The whole national privacy law is being replaced by two new laws — one general, one for police and courts — but they are still bills and have no legal effect. Act 18/2018 was amended today, 18 August 2026, mostly to remove dead people from its scope. Public bodies face a bigger data-registration duty from 1 January 2027, and all cloud switching and data export fees across Europe must drop to zero by 12 January 2027.High confidence
- Hardest industry wall
- Online gaming — Zákon č. 30/2019 Z. z. o hazardných hrách a o zmene a doplnení niektorých zákonov, § 14 ods. 21 a 22
- Government — Metodické usmernenie č. 020775/2025/oSBATA z 11. 4. 2025 pre proces zaradenia cloudovej služby do katalógu vládnych cloudových služieb, vydané podľa § 24a zákona č. 95/2019 Z. z.
- Mapping and location — Zákon Národnej rady Slovenskej republiky č. 215/1995 Z. z. o geodézii a kartografii