Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
MaltaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
In one paragraph
Malta runs on the European rulebook. Data may go abroad once the right paperwork is in place, and there is no general rule that it must stay on the island. Two things break that. Online gaming companies must keep their core systems inside Europe. And any Maltese company that keeps its books abroad must still keep a copy of its accounts in Malta.
The catch
The easy answer stops being true in three places. First, online gaming, which is Malta's biggest regulated industry: a licensed operator's 'key technical setup' — including the player database, the financial database and the control system — must sit in Malta or another European Economic Area country, unless the Malta Gaming Authority approves another location one case at a time. The same operator must also run a live mirror of its essential regulatory data that the Authority can reach at any moment, including physically. Second, company law: if a company keeps its accounting records outside Malta, it must still send to Malta, and keep in Malta, accounts and returns good enough to show the financial position at least every six months. Third, government: the public administration's own cloud policy says cloud services should as a rule be inside the European Union or European Economic Area, and anything classified must go on the government's own cloud. Banking, payments, insurance, securities, health, education and mapping have no storage-location rule that we could find, checked 18 August 2026.
Does this apply to me?
Yes. Malta's Data Protection Act reaches a company with no office in Malta if it offers goods or services to people in Malta, or watches their behaviour in Malta. There is no size or revenue threshold. There is no extra Maltese representative to appoint beyond the one the European rules already require of companies based outside Europe.High confidence
Can the data leave the country?
In general, yes. Malta has no law saying personal data must be stored on the island. It follows the European Union rules: send data outside Europe once you have an approved destination or the right contract. Three areas override that. Online gaming is the big one, and it is Malta's flagship industry.High confidence
What do I have to do to send it abroad?
Use the European toolkit. Send data to a country the European Commission has approved, or sign the European standard contract, or use approved group-wide rules. Malta adds nothing on top. Malta's own minister has a power to restrict transfers of named categories of data, but has never used it, so the list of Maltese restrictions is empty today.High confidence
Who enforces this — and are they actually working?
The Information and Data Protection Commissioner. It is real, staffed and issuing decisions: its public register shows around nineteen decisions published in 2026 and thirty-eight in 2025. The fines are small by European standards — most sit between about 2,000 and 20,000 euros (roughly $2,300 to $23,000). The gaming regulator is the harder one, and it cancels licences.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling. The floor: company accounting records for ten years, tax and value-added-tax records for at least six years, and anti-money-laundering records for five years. The ceiling: the European rule that you delete personal data once you no longer need it. Where they clash, the specific Maltese law that orders you to keep something wins, because keeping it is then a legal duty.High confidence
What happens when something goes wrong?
Count three clocks, and they do not line up. Seventy-two hours to tell the privacy regulator about a personal data breach. Twenty-four hours to send a first warning about a serious cyber incident, then seventy-two hours for the full report and one month for the final one. Phone and internet companies have their own separate duty to report straight away.High confidence
What's the trap?
Five things that are not in the summary. A child in Malta is thirteen, not sixteen. Health and biometric research needs the regulator's written permission before you start, not just a risk assessment. Copying someone's identity card is restricted. Leaking a client secret can be a crime, not a fine. And the gaming regulator can keep personal data forever, in a law that says so out loud.High confidence
What's about to change?
Three dated changes. On 1 January 2027 a new law stops insurers, banks and employers asking about a cancer diagnosis once enough time has passed since treatment. On 12 January 2027 European rules make cloud switching and data export fees free. And Malta's artificial intelligence rules started phasing in on 2 August 2026, with the privacy regulator now policing the market.High confidence
Hardest industry wall
  • All industries Att dwar il-Kumpaniji (Kap. 386), artikolu 163
UzbekistanChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Uzbekistan used to say that data about its citizens had to sit on machines inside the country. In March 2026 it dropped that blanket rule. Most personal data may now be stored abroad if the destination country is on a new government approved list, or you use an approved contract, or you meet international standards. Three kinds of data still cannot leave at all.
The catch
The relaxed headline stops at three walls. Face and fingerprint data, genetic data, and data about customers of telephone and internet companies must be kept inside Uzbekistan. Banks face a separate rule that bans handing the running of their systems to an outside supplier, which blocks most managed cloud arrangements. Detailed maps are handled under state-secrecy rules.
Does this apply to me?
The law is written to cover the handling of personal data whatever tools are used, and it was aimed at foreign online platforms when the storage rules were first tightened in 2021. It does not set a size or revenue threshold, so a small foreign company is treated the same as a large one. We found no clear wording that forces a foreign company to appoint a representative living in Uzbekistan, and no explicit sentence saying the law follows the data outside the country.Medium confidence
Can the data leave the country?
Mostly yes, but only if you can point to one of three permissions. Face and fingerprint data, genetic data, and data about customers of telephone and internet companies must stay in Uzbekistan. Everything else may be stored and processed abroad if the destination country is on the government's approved list, or you sign an approved standard contract or use approved group rules, or you follow recognised international data standards.Medium confidence
What do I have to do to send it abroad?
The model is an approved list. Before ordinary personal data leaves the country you need one of three things: the destination is on the Cabinet of Ministers' list of countries with adequate protection, or you use the standard contract terms or group rules approved by the data authority, or you meet recognised international data standards. The country list was signed on 29 July 2026 and started on 3 August 2026, so it is brand new. We could not read which countries are on it, and no approved standard contract template appears to have been published yet.Medium confidence
Who enforces this — and are they actually working?
The data regulator is the State Centre for Personalization, which sits under the Cabinet of Ministers. It keeps the national register of personal data databases and can issue orders that companies and individuals must obey. It is a working government body and the registration service has run since 2020, but we found no published fines or decisions, so treat enforcement as waking up rather than active. Cyber incidents are handled by a different body, the State Security Service, and banks answer separately to the Central Bank.Medium confidence
How long must I keep it, and when must I delete it?
The ceiling is clear: personal data must be destroyed once the purpose is achieved, once consent is withdrawn, once the agreed period ends, or when a court orders it. The floor is thinner. Organisations covered by the cybersecurity law must keep backup copies covering at least the last three months. We did not verify the general tax and accounting minimum keeping periods during this run, so plan on the usual company record rules as well.Medium confidence
What happens when something goes wrong?
There are two clocks and they are not the same. The privacy law itself contains no duty to report a data breach to the regulator or to the people affected — we checked the text on 18 August 2026 and found none. The cybersecurity law is where reporting lives: organisations covered by it must tell the State Security Service about cyber incidents. Banks also report to the Central Bank under its security rules. We could not confirm a firm deadline in hours for any of these.Medium confidence
What's the trap?
First, every database of personal data has to be entered in a national register — it is a notification, it is free and it takes five working days, but skipping it is still a breach. Second, breaking the personal data rules can be a crime, not just a fine, so a named person can be prosecuted. Third, the face and fingerprint wall catches ordinary products like fingerprint logins and identity checks, not just spy technology. Fourth, banks are banned from handing the running of their technology and security systems to an outside supplier, which rules out most managed cloud and outsourced security operations. Fifth, the standard contract route for sending data abroad exists on paper but no approved template appears to have been published.Medium confidence
What's about to change?
The big change already happened in March 2026 and the follow-up is still landing. The approved country list started on 3 August 2026 and can be widened or cut by the Cabinet of Ministers at any time. The approved standard contract for sending data abroad is still missing, so watch for it. A new Tashkent International Financial Centre opened its legal regime on 25 July 2026 and its law also touched the privacy law, which may create a separate rulebook inside the centre. A national cybersecurity strategy was signed in March 2026.Medium confidence
Hardest industry wall
  • All industries Закон «О персональных данных», статья 27-1, часть 2
  • Telecoms Закон «О персональных данных», статья 27-1, часть 2 (данные пользователей услуг операторов телекоммуникаций)
  • Finance Кредит бюроларининг ахборот хавфсизлиги ва киберхавфсизлигига доир минимал талаблар тўғрисидаги низом
  • Mapping and location Положение о порядке установления ограничительных грифов картографических и геодезических материалов (данных)
  • Government О мерах по организации деятельности Центра обработки данных системы «Электронное правительство»