Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
MexicoChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Waking up
In one paragraph
Mexico's general privacy law does not care where you store data. There is no approved-country list, no standard contract to sign and no permission to ask for. You need the right wording in your privacy notice and, usually, the person's consent. The rules that actually pin data to Mexico live in banking, money-laundering and tax law, not in the privacy law.
The catch
The relaxed headline stops the moment you are a bank, a stockbroker, a crowdfunding platform, an insurer or a phone company. Banks need written permission from the banking regulator before any processing happens abroad. Separately, anti-money-laundering law and tax law require many ordinary businesses to keep their records at a Mexican address for ten and five years. Those rules bind companies that have never read a privacy law.
Does this apply to me?
Probably yes, but Mexico is unusually vague about it. The privacy law says only that it applies across Mexican territory. It does not spell out when it reaches a company based abroad. The old rulebook did say the law caught a foreign company that used equipment or systems located in Mexico, and let that company appoint a local representative instead of opening an office. That old rulebook belonged to a law that was scrapped in March 2025, so its status today is genuinely unclear. There is no revenue or headcount threshold to fall below.Medium confidence
Can the data leave the country?
Under the general privacy law, yes, and with very little paperwork. Mexico has no list of approved countries and no list of banned ones. Sending data to a company abroad is treated exactly like sending it to a company down the road: say so in your privacy notice, get the person's consent unless one of seven exceptions applies, and pass the privacy notice on to whoever receives the data. Handing data to your own supplier who only follows your instructions is not even counted as a transfer. Five sectors override this, and in three of them the override is severe.High confidence
What do I have to do to send it abroad?
Nothing needs approval and no list exists in either direction. The model is simply unrestricted: any destination is allowed. What you need is a privacy notice that names the transfer and carries a clause where the person accepts or refuses it, plus that person's consent unless one of seven legal exceptions covers you. Because there is no list to populate, the government cannot make this stricter by adding a country. It would take a new law or a new regulation.High confidence
Who enforces this — and are they actually working?
Mexico abolished its independent privacy regulator. The National Institute for Transparency, Access to Information and Data Protection was wound up in March 2025 and its staff, files and cases were moved into a government ministry, the Anti-Corruption and Good Government Ministry. So the referee is now part of the government rather than independent of it. The ministry is staffed, but the law says the detailed procedure for complaints, inspections and fines will be set out in a regulation, and that regulation still has not been published. Financial regulators, by contrast, are visibly active and update their rulebooks almost monthly.Medium confidence
How long must I keep it, and when must I delete it?
There is no single retention period. The privacy law says delete data once it is no longer needed, after a blocking period equal to the time limit for suing over the relationship. One hard ceiling is written into the law: information about someone breaking a contract must be erased six years after the default. The floors are longer and come from other laws. Tax records must be kept five years and their supporting documents must be available at your Mexican tax address. Anti-money-laundering records must be kept ten years at an address you register with the Finance Ministry. Phone companies keep call and location records for two years. Where a floor and a ceiling clash, the floor wins, because the privacy law lets you keep data to meet a legal duty.High confidence
What happens when something goes wrong?
There are at least three clocks and they do not agree. Under the general privacy law you must tell the affected people immediately if a breach significantly harms their money or their reputation, and there is no duty to tell the regulator at all. Banks face a much tighter set: tell the banking regulator immediately, tell affected customers within forty-eight hours, file a full report within five working days, and send a remediation plan within fifteen working days of the incident ending. Phone companies must hand requested records to the authorities within twenty-four hours and keep a team available every hour of every day. Mexico has no general cyber-incident reporting law that catches everyone.High confidence
What's the trap?
Five things catch people out. Every private business in Mexico is now legally required to ask customers for their national population ID number. Anti-money-laundering rules force many ordinary businesses to keep ten years of records at a Mexican address, which quietly rules out a pure foreign cloud setup. Mishandling data can put a person in prison, not just cost a company money. Banks must get written permission before any processing happens abroad, and that includes routine cloud hosting. And the rulebook the privacy law keeps pointing at does not exist.High confidence
What's about to change?
The biggest thing coming is a regulation that is already overdue. The privacy law repeatedly says a rulebook will set the deadlines for complaints, inspections and fines, and the government missed its own June 2025 deadline to publish it. When it lands it could change how enforcement works overnight, with no consultation. Health law was changed in January 2026 to put telehealth on a statutory footing, and the biometric national ID is still being rolled out. The dangerous powers are the ones the government already holds rather than any bill in parliament.Medium confidence
Hardest industry wall
  • Payments Disposiciones de carácter general aplicables a las instituciones de tecnología financiera, artículos 85 a 87
  • Finance Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita, artículos 15 y 18
  • All industries Código Fiscal de la Federación, artículos 28 y 30
  • Telecoms Ley en Materia de Telecomunicaciones y Radiodifusión, artículo 183
TaiwanChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Taiwan lets personal data leave the country freely unless the ministry that regulates your industry has issued an order stopping it. There is no single privacy regulator: each industry ministry polices its own sector, and each has written its own security and breach-reporting rules. A big reform that would create one national regulator was passed in November 2025 but has never been switched on.
The catch
The relaxed headline stops being true the moment you touch health records, national health insurance data, banking or telecoms. Hospital data held in the cloud must physically sit in Taiwan. National health insurance records cannot be released to any organisation set up outside Taiwan at all. Banks need the financial regulator's permission before major consumer-finance systems go offshore, and must keep a backup of important customer data in Taiwan if they do.
Does this apply to me?
Yes. Taiwan's privacy law reaches a foreign company with no office and no staff in Taiwan. The law says plainly that it also applies to organisations outside Taiwan that collect, process or use the personal data of Taiwanese people. There is no revenue or headcount threshold to fall below, and the law does not require you to appoint a local representative.High confidence
Can the data leave the country?
In general, yes. Taiwan's privacy law does not ask you to sign anything or get anyone's permission before sending personal data abroad. Instead it gives each industry ministry the power to order that data in its sector may not go to a particular country. But four sectors have real walls, and in two of them the wall is absolute.High confidence
What do I have to do to send it abroad?
Under the general law, nothing. No standard contract, no government approval, no adequacy finding, no consent form. The model is a blocklist run sector by sector: you may send data anywhere unless the ministry that supervises your industry has issued an order stopping it. Your real job is to find out which ministry supervises you and check whether it has issued one.High confidence
Who enforces this — and are they actually working?
There is no national privacy regulator in Taiwan today. A Personal Data Protection Commission is named in the law as the authority in charge, but that provision has never been switched on, the law creating the Commission is still only a bill, and what exists is a preparatory office that writes draft rules and cannot fine anyone. Enforcement is done instead by whichever ministry regulates your industry, plus city and county governments, and those bodies are genuinely active.High confidence
How long must I keep it, and when must I delete it?
Both directions apply, and the floors are set by other laws, not the privacy law. Accounting vouchers must be kept at least five years and account books and financial statements at least ten years. Medical records must be kept at least seven years, and for children until seven years after they turn eighteen; records from human trials must be kept forever. Going the other way, you must delete personal data once the purpose you collected it for has gone or the period you set has run out.High confidence
What happens when something goes wrong?
Count at least three clocks, and the fastest is one hour. Telecoms companies and larger internet providers must tell the communications regulator within one hour of learning about a major personal data incident, then file a full report within seventy-two hours. Government bodies and designated critical infrastructure operators also have one hour, under the separate cyber security law. Financial firms get seventy-two hours. And under the privacy law itself you must tell the affected people once you have established the facts, with no fixed deadline attached.High confidence
What's the trap?
Five things that will cost someone their weekend. First, the official English text of the privacy law on the government's own website includes provisions that are not law yet, including the one naming the national regulator. Second, breaking a cross-border transfer order is a crime, not a fine — up to five years in prison. Third, there is no single regulator to ask; your duties depend on which ministry supervises you. Fourth, a bank asked for Taiwanese customer data by a foreign financial regulator must get Taiwan's regulator's permission first. Fifth, if you are sued, you have to prove you were not at fault.High confidence
What's about to change?
One thing has already landed and one is waiting on a switch. The National Health Insurance Data Management Act came into force on 10 August 2026, and it gives people a short window to opt their health records out of research use before silence counts as agreement. Separately, the big privacy reform passed in November 2025 is sitting on the shelf: the Cabinet can bring it into force whenever it likes, by a single order, with no consultation.High confidence
Hardest industry wall
  • Health and social care 醫療機構電子病歷製作及管理辦法 (Regulations Governing the Production and Management of Electronic Medical Records by Medical Institutions)
  • Health and social care 全民健康保險資料管理條例 (National Health Insurance Data Management Act)
  • Banking 金融機構作業委託他人處理內部作業制度及程序辦法 (Regulations Governing Internal Operating Systems and Procedures for the Outsourcing of Financial Institution Operation)