Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
MaltaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Malta runs on the European rulebook. Data may go abroad once the right paperwork is in place, and there is no general rule that it must stay on the island. Two things break that. Online gaming companies must keep their core systems inside Europe. And any Maltese company that keeps its books abroad must still keep a copy of its accounts in Malta.
- The catch
- The easy answer stops being true in three places. First, online gaming, which is Malta's biggest regulated industry: a licensed operator's 'key technical setup' — including the player database, the financial database and the control system — must sit in Malta or another European Economic Area country, unless the Malta Gaming Authority approves another location one case at a time. The same operator must also run a live mirror of its essential regulatory data that the Authority can reach at any moment, including physically. Second, company law: if a company keeps its accounting records outside Malta, it must still send to Malta, and keep in Malta, accounts and returns good enough to show the financial position at least every six months. Third, government: the public administration's own cloud policy says cloud services should as a rule be inside the European Union or European Economic Area, and anything classified must go on the government's own cloud. Banking, payments, insurance, securities, health, education and mapping have no storage-location rule that we could find, checked 18 August 2026.
- Does this apply to me?
- Yes. Malta's Data Protection Act reaches a company with no office in Malta if it offers goods or services to people in Malta, or watches their behaviour in Malta. There is no size or revenue threshold. There is no extra Maltese representative to appoint beyond the one the European rules already require of companies based outside Europe.High confidence
- Can the data leave the country?
- In general, yes. Malta has no law saying personal data must be stored on the island. It follows the European Union rules: send data outside Europe once you have an approved destination or the right contract. Three areas override that. Online gaming is the big one, and it is Malta's flagship industry.High confidence
- What do I have to do to send it abroad?
- Use the European toolkit. Send data to a country the European Commission has approved, or sign the European standard contract, or use approved group-wide rules. Malta adds nothing on top. Malta's own minister has a power to restrict transfers of named categories of data, but has never used it, so the list of Maltese restrictions is empty today.High confidence
- Who enforces this — and are they actually working?
- The Information and Data Protection Commissioner. It is real, staffed and issuing decisions: its public register shows around nineteen decisions published in 2026 and thirty-eight in 2025. The fines are small by European standards — most sit between about 2,000 and 20,000 euros (roughly $2,300 to $23,000). The gaming regulator is the harder one, and it cancels licences.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling. The floor: company accounting records for ten years, tax and value-added-tax records for at least six years, and anti-money-laundering records for five years. The ceiling: the European rule that you delete personal data once you no longer need it. Where they clash, the specific Maltese law that orders you to keep something wins, because keeping it is then a legal duty.High confidence
- What happens when something goes wrong?
- Count three clocks, and they do not line up. Seventy-two hours to tell the privacy regulator about a personal data breach. Twenty-four hours to send a first warning about a serious cyber incident, then seventy-two hours for the full report and one month for the final one. Phone and internet companies have their own separate duty to report straight away.High confidence
- What's the trap?
- Five things that are not in the summary. A child in Malta is thirteen, not sixteen. Health and biometric research needs the regulator's written permission before you start, not just a risk assessment. Copying someone's identity card is restricted. Leaking a client secret can be a crime, not a fine. And the gaming regulator can keep personal data forever, in a law that says so out loud.High confidence
- What's about to change?
- Three dated changes. On 1 January 2027 a new law stops insurers, banks and employers asking about a cancer diagnosis once enough time has passed since treatment. On 12 January 2027 European rules make cloud switching and data export fees free. And Malta's artificial intelligence rules started phasing in on 2 August 2026, with the privacy regulator now policing the market.High confidence
- Hardest industry wall
- All industries — Att dwar il-Kumpaniji (Kap. 386), artikolu 163
RussiaChecked 18 August 2026
A copy must stayWork: Very highEnforcement: Active
- In one paragraph
- If you collect personal data from people in Russia, the database you collect it into must sit inside Russia. You may then send a copy abroad, but only after you tell the regulator first and only to a country on its approved list. The United States is not on that list. Breaking the storage rule costs up to 6 million roubles, about $75,000, and leaking data can now put a person in prison.
- The catch
- The 'copy may go abroad' part disappears in several industries. Payments, electronic money, biometrics, telecoms, internet messaging services, government systems and detailed mapping are hard walls: the data must stay in Russia and no copy may leave. Since 1 September 2025 any company running 'significant' critical infrastructure — which includes most banks, telecoms operators and large energy and health providers — must also run Russian-registered software on those systems.
- Does this apply to me?
- Yes. The law reaches a foreign company with no office in Russia. It applies whenever you process the personal data of Russian citizens under a contract with them, under any other agreement with them, or on the basis of their consent. There is no size or revenue threshold. Almost every organisation must also file a notice with the regulator before it starts processing, and file a second, separate notice before any data leaves the country.High confidence
- Can the data leave the country?
- A copy can leave, but the original must stay. When you collect personal data about Russian citizens, the database you record, store, update or retrieve it from has to be physically in Russia. Since 1 July 2025 the law says this as a flat ban on using databases outside Russia for those steps. After that, sending a copy abroad is a separate question with its own paperwork. Several industries are stricter still and allow no copy out at all.High confidence
- What do I have to do to send it abroad?
- Russia runs an approved-destinations list, so a transfer is banned unless the destination is on it. Before any data leaves you must send the regulator a separate written notice naming the countries, the data and the recipients, and you must first collect written assurances from the recipient about how it will protect the data. If the destination is on the approved list you may start as soon as the notice is sent. If it is not, you must wait, and in practice you will be refused. The United States is not on the list.High confidence
- Who enforces this — and are they actually working?
- Roskomnadzor, the federal communications and media supervisor, is the data protection regulator. It is a long-established federal service, fully staffed, and it is still issuing binding orders — its most recent inspection check-list order was published on the state legal portal in December 2025. It is not the only enforcer. The security service runs the national cyber-attack reporting system, the technical regulator FSTEC sets security requirements for government and critical systems, and the Bank of Russia supervises banks and payment firms.Medium confidence
- How long must I keep it, and when must I delete it?
- Both directions apply and they collide. Personal data must be destroyed within 30 days of the purpose being achieved, or within 30 days of consent being withdrawn, and within 10 working days if the processing was unlawful. Against that, staff records must be kept for 50 years, telecoms and messaging metadata for three years, and message content for up to six months. Where a statute sets a minimum, the minimum wins and you keep the data.High confidence
- What happens when something goes wrong?
- There are at least three clocks and they run at once. You have 24 hours to tell the data regulator that personal data has leaked, and 72 hours to give it the results of your internal investigation. Separately, if the leak came from a computer attack you must report it to the security service's national attack-detection system. Banks and payment firms report to the Bank of Russia as well. Missing the 24-hour notice is itself a fine of up to 3 million roubles, about $37,000.High confidence
- What's the trap?
- Five things catch people out. First, leaking data is now a crime, and doing it across a border carries up to eight years in prison. Second, repeat leaks are fined as a share of worldwide-style annual revenue, between 1 and 3 percent, with a floor of 20 million roubles, about $250,000. Third, staff files must be kept 50 years, which flatly conflicts with the 30-day deletion duty. Fourth, biometric data can only be handled by a Russian-controlled company using databases in Russia. Fifth, refusing to serve a customer because they will not give biometrics is itself a fine.High confidence
- What's about to change?
- One dated change is already fixed: from 1 September 2027, Moscow's public bodies move onto a single city technology platform, which will pull a large volume of citizen data into one place. Much more important are the switches the government already holds and can flip with no consultation. The approved-country list can be cut by a single regulator order. Any transfer can be banned outright on security or economic grounds. And the rules for foreign use of Russian mapping technology have been written into the law but never issued.High confidence
- Hardest industry wall
- All industries — Федеральный закон от 27.07.2006 № 152-ФЗ «О персональных данных», статья 18 часть 5
- All industries — Федеральный закон № 152-ФЗ, статья 21 часть 3.1 и статья 19 часть 12
- All industries — Уголовный кодекс Российской Федерации, статья 272.1
- Payments — Федеральный закон от 27.06.2011 № 161-ФЗ «О национальной платежной системе», статьи 12 и 16
- All industries — Федеральный закон от 29.12.2022 № 572-ФЗ об идентификации и аутентификации с использованием биометрических персональных данных
- Telecoms — Федеральный закон от 07.07.2003 № 126-ФЗ «О связи», статья 64; Федеральный закон от 27.07.2006 № 149-ФЗ, статья 10.1
- Government — Приказ ФСТЭК России от 11.04.2025 № 117; Указ Президента РФ от 30.03.2022 № 166; Указ Президента РФ от 01.05.2022 № 250; Федеральный закон от 07.04.2025 № 58-ФЗ
- Mapping and location — Федеральный закон от 30.12.2015 № 431-ФЗ «О геодезии, картографии и пространственных данных», статьи 23 и 24
- Health and social care — Федеральный закон от 21.11.2011 № 323-ФЗ «Об основах охраны здоровья граждан в Российской Федерации», статья 13
- Social media and online platforms — Федеральный закон от 01.07.2021 № 236-ФЗ «О деятельности иностранных лиц в информационно-телекоммуникационной сети «Интернет» на территории Российской Федерации»