Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
MaltaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Malta runs on the European rulebook. Data may go abroad once the right paperwork is in place, and there is no general rule that it must stay on the island. Two things break that. Online gaming companies must keep their core systems inside Europe. And any Maltese company that keeps its books abroad must still keep a copy of its accounts in Malta.
- The catch
- The easy answer stops being true in three places. First, online gaming, which is Malta's biggest regulated industry: a licensed operator's 'key technical setup' — including the player database, the financial database and the control system — must sit in Malta or another European Economic Area country, unless the Malta Gaming Authority approves another location one case at a time. The same operator must also run a live mirror of its essential regulatory data that the Authority can reach at any moment, including physically. Second, company law: if a company keeps its accounting records outside Malta, it must still send to Malta, and keep in Malta, accounts and returns good enough to show the financial position at least every six months. Third, government: the public administration's own cloud policy says cloud services should as a rule be inside the European Union or European Economic Area, and anything classified must go on the government's own cloud. Banking, payments, insurance, securities, health, education and mapping have no storage-location rule that we could find, checked 18 August 2026.
- Does this apply to me?
- Yes. Malta's Data Protection Act reaches a company with no office in Malta if it offers goods or services to people in Malta, or watches their behaviour in Malta. There is no size or revenue threshold. There is no extra Maltese representative to appoint beyond the one the European rules already require of companies based outside Europe.High confidence
- Can the data leave the country?
- In general, yes. Malta has no law saying personal data must be stored on the island. It follows the European Union rules: send data outside Europe once you have an approved destination or the right contract. Three areas override that. Online gaming is the big one, and it is Malta's flagship industry.High confidence
- What do I have to do to send it abroad?
- Use the European toolkit. Send data to a country the European Commission has approved, or sign the European standard contract, or use approved group-wide rules. Malta adds nothing on top. Malta's own minister has a power to restrict transfers of named categories of data, but has never used it, so the list of Maltese restrictions is empty today.High confidence
- Who enforces this — and are they actually working?
- The Information and Data Protection Commissioner. It is real, staffed and issuing decisions: its public register shows around nineteen decisions published in 2026 and thirty-eight in 2025. The fines are small by European standards — most sit between about 2,000 and 20,000 euros (roughly $2,300 to $23,000). The gaming regulator is the harder one, and it cancels licences.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling. The floor: company accounting records for ten years, tax and value-added-tax records for at least six years, and anti-money-laundering records for five years. The ceiling: the European rule that you delete personal data once you no longer need it. Where they clash, the specific Maltese law that orders you to keep something wins, because keeping it is then a legal duty.High confidence
- What happens when something goes wrong?
- Count three clocks, and they do not line up. Seventy-two hours to tell the privacy regulator about a personal data breach. Twenty-four hours to send a first warning about a serious cyber incident, then seventy-two hours for the full report and one month for the final one. Phone and internet companies have their own separate duty to report straight away.High confidence
- What's the trap?
- Five things that are not in the summary. A child in Malta is thirteen, not sixteen. Health and biometric research needs the regulator's written permission before you start, not just a risk assessment. Copying someone's identity card is restricted. Leaking a client secret can be a crime, not a fine. And the gaming regulator can keep personal data forever, in a law that says so out loud.High confidence
- What's about to change?
- Three dated changes. On 1 January 2027 a new law stops insurers, banks and employers asking about a cancer diagnosis once enough time has passed since treatment. On 12 January 2027 European rules make cloud switching and data export fees free. And Malta's artificial intelligence rules started phasing in on 2 August 2026, with the privacy regulator now policing the market.High confidence
- Hardest industry wall
- All industries — Att dwar il-Kumpaniji (Kap. 386), artikolu 163
NetherlandsChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
- In one paragraph
- For most businesses the Netherlands follows the ordinary European rules: data may leave the country once you have the right paperwork in place. Two areas are much harder. Online gambling firms must keep their regulator-facing database physically in the Netherlands, and central government now has to keep all its information inside Europe. The Dutch privacy regulator hands out some of the largest transfer fines in Europe.
- The catch
- The relaxed headline stops being true the moment you touch online gambling, central government work, health records or a regulated financial firm. An online gambling licence forces one database onto Dutch soil. Central government contracts now bar storage outside Europe. And a brand-new cybersecurity law switched on three days ago, on 15 August 2026, with a 24-hour incident alarm most companies have not built yet.
- Does this apply to me?
- Yes, it reaches you with no Dutch office. Europe's privacy law applies to any organisation anywhere that offers goods or services to people in the Netherlands or watches what they do online, and there is no size or revenue floor. Separately, the new Dutch cybersecurity law says that if you are a cloud provider, data centre, managed service provider, online marketplace, search engine or social network based outside Europe but selling into the Netherlands, you must appoint a representative inside the European Union.High confidence
- Can the data leave the country?
- In general yes, with paperwork, because the Netherlands is an EU country and European rules govern transfers. But three Dutch walls override that. An online gambling licence holder must physically place its regulator-facing control database in the Netherlands. Central government must keep all its information inside the European Economic Area plus Switzerland. And a healthcare provider, bank or insurer can put data abroad only if the supervisor can still see and audit it.High confidence
- What do I have to do to send it abroad?
- The model is an allowlist run at European level, not a Dutch one. You may send personal data outside Europe only if the destination has been officially approved, or you sign the standard European contract, or you use approved group-wide rules. The approved list is full and active. The Netherlands adds no national approval step and keeps no blocklist of its own.High confidence
- Who enforces this — and are they actually working?
- The Dutch Data Protection Authority, and it is very much operational and very much willing to fine. It has a full three-person board, and a new chair, Geert Potjewijd, took office on 1 August 2026. It has issued two of the largest cross-border transfer fines in Europe: 290 million euros against Uber in 2024 and 100 million euros against a taxi app in May 2026. Cybersecurity is enforced separately, by sector ministries and inspectorates, and that machinery is only now being assembled.High confidence
- How long must I keep it, and when must I delete it?
- There is a firm floor and a soft ceiling. You must keep your books and tax records for seven years, and money-laundering records for five years after the relationship or transaction ends. Against that, privacy law says you must delete personal data once you no longer need it, and there is no fixed number. When the two collide, the legal duty to keep wins for as long as it lasts, and deletion follows immediately after.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. For a personal data breach you have 72 hours to tell the Dutch Data Protection Authority. If you are covered by the new cybersecurity law that started on 15 August 2026, you must raise an early warning within 24 hours, file a full report within 72 hours, and deliver a final report within one month. Telecom operators have a fourth clock and must tell the privacy regulator without delay.High confidence
- What's the trap?
- Five things that are not in the summary. Your works council can block an HR or monitoring system. Breaking a professional secrecy duty is a crime, not a fine. The telecom retention duty printed in the law cannot be enforced. Children need a parent's permission until they turn sixteen. And the new cybersecurity law started on 15 August 2026 with a phased exception for universities that most checklists miss.High confidence
- What's about to change?
- Three dated changes. On 1 September 2026 an amendment act tidies up the Dutch privacy law and adds new rules for handing over health files, but one part of it has deliberately been left switched off. Registration and incident duties under the cybersecurity law that started on 15 August 2026 are being phased in now. And by 12 January 2027 every cloud provider must drop switching and data export charges to zero across Europe.High confidence
- Hardest industry wall
- Online gaming — Besluit kansspelen op afstand, artikel 4.42, tweede lid
- Government — Herziening rijksbreed cloudbeleid 2026