Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
MauritiusChecked 19 August 2026
Yes, with paperworkWork: HighEnforcement: Active
In one paragraph
Personal data can leave Mauritius, but almost never without paperwork. You have to satisfy the privacy regulator that the data will still be protected, and in practice the regulator signs transfers off one at a time. Every organisation that handles personal data must also register with it. From January 2027 each one must name a trained, certified privacy officer from its own staff.
The catch
That answer covers personal data only. If you run a Mauritius company, your official company records must be kept on the island, and if your accounting records live abroad you must still send summary accounts back to a place in Mauritius. Banks, insurers, fund managers and gambling operators need their own regulator's clearance before moving systems or data offshore. Penalties here are criminal, not administrative fines.
Does this apply to me?
Only if you have a foothold on the island. The law catches you if you are set up in Mauritius, meaning you live there or run an office, branch or agency there. It also catches you if you are not set up there but use equipment inside Mauritius to handle the data. Selling to Mauritians from abroad, with no kit on the island, is not enough by itself. If you do use equipment there, you must name a representative based in Mauritius, and you must register with the privacy regulator before you start. There is no size or revenue floor to duck under.High confidence
Can the data leave the country?
Yes, but you have to earn it. The general rule is that personal data may go abroad if you can show the privacy regulator that it will still be properly protected, or if a narrow exception applies such as the person's explicit informed consent. In practice the regulator handles this as an approval queue: it cleared 112 transfer requests in 2024. There is no list of pre-approved countries, so no destination is automatically safe. Several industries add their own gate on top, and company law adds a hard one that has nothing to do with privacy.High confidence
What do I have to do to send it abroad?
The model is case-by-case approval, not a country list. Before personal data leaves, you must put appropriate protections in place and file proof of them with the privacy regulator. If you cannot provide those protections, you must go and ask the regulator for permission first. Mauritius has published no list of approved destinations and no official standard contract template, so you cannot rely on where the data is going. Requests go through the regulator's online portal, and it approved 112 of them in 2024.High confidence
Who enforces this — and are they actually working?
The Data Protection Office, headed by Commissioner Drudeisha Madhub, who has held the post since 2007. It is real and it is working: 209 published decisions up to November 2025, 179 new complaints and 65 site inspections in 2024, 105 breach reports received and 112 transfer approvals granted. But it is thinly staffed, with one officer in post against twelve requested, and its own report says enforcement action has been delayed by that. It issues no fines, because every penalty in the Act is a criminal one that a court must impose. Financial and gambling regulators enforce separately and are fully active.High confidence
How long must I keep it, and when must I delete it?
Two forces pull against each other. The privacy law says delete: keep personal data only as long as you need it, and destroy it as soon as the purpose has gone. Company law and money-laundering rules say keep: seven years for company records, accounting records and customer due diligence files. The keep rules win where they apply, because the privacy law lets you process where a law requires it. In practice you set a seven-year clock on financial and corporate paperwork and a short, purpose-based clock on everything else.High confidence
What happens when something goes wrong?
One firm clock and several soft ones. A personal data breach must be reported to the Commissioner without undue delay and, where possible, within 72 hours of you finding out. If you miss that, you must explain why you were late. Where the breach is likely to seriously harm people, you must also tell them, without undue delay. A supplier who spots a breach must tell the organisation it works for straight away. Cyber incidents affecting critical national systems go to the national cyber team as well, and that route has no fixed deadline in the law.High confidence
What's the trap?
Five things that catch people out. One: suppliers must register too, not just the organisation in charge, and the certificate expires every three years. Two: from January 2027 every organisation must name a privacy officer from its own payroll, holding a certificate from the regulator or a school the regulator approves, with no exemption for tiny firms. Three: getting it wrong is a crime, not a fine, and a person can go to prison for up to five years. Four: your company paperwork must physically stay in Mauritius. Five: the telecoms regulator can order the internet shut off, and did in November 2024.High confidence
What's about to change?
One dated change dominates: on 1 January 2027 every organisation must have its certified in-house privacy officer in place, so the work has to start now. Owners of systems the government has labelled critical - banking, public service, technology and broadcasting, energy and water, transport - have until 1 June 2027 to comply with directions. Beyond that the government has announced a national cyber agency, a digital identity bill, artificial intelligence rules and social media responsibility measures, none of them law yet. Several powers already on the books could change the picture with no warning.High confidence
Hardest industry wall
  • All industries Companies Act 2001
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
The catch
The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
Does this apply to me?
Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
Can the data leave the country?
Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
What do I have to do to send it abroad?
The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
Who enforces this — and are they actually working?
The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
What happens when something goes wrong?
There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
What's the trap?
Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
What's about to change?
Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
Hardest industry wall
  • Telecoms Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
  • E-commerce Loi n° 18-05 relative au commerce electronique
  • Government Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees