Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
NetherlandsChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
In one paragraph
For most businesses the Netherlands follows the ordinary European rules: data may leave the country once you have the right paperwork in place. Two areas are much harder. Online gambling firms must keep their regulator-facing database physically in the Netherlands, and central government now has to keep all its information inside Europe. The Dutch privacy regulator hands out some of the largest transfer fines in Europe.
The catch
The relaxed headline stops being true the moment you touch online gambling, central government work, health records or a regulated financial firm. An online gambling licence forces one database onto Dutch soil. Central government contracts now bar storage outside Europe. And a brand-new cybersecurity law switched on three days ago, on 15 August 2026, with a 24-hour incident alarm most companies have not built yet.
Does this apply to me?
Yes, it reaches you with no Dutch office. Europe's privacy law applies to any organisation anywhere that offers goods or services to people in the Netherlands or watches what they do online, and there is no size or revenue floor. Separately, the new Dutch cybersecurity law says that if you are a cloud provider, data centre, managed service provider, online marketplace, search engine or social network based outside Europe but selling into the Netherlands, you must appoint a representative inside the European Union.High confidence
Can the data leave the country?
In general yes, with paperwork, because the Netherlands is an EU country and European rules govern transfers. But three Dutch walls override that. An online gambling licence holder must physically place its regulator-facing control database in the Netherlands. Central government must keep all its information inside the European Economic Area plus Switzerland. And a healthcare provider, bank or insurer can put data abroad only if the supervisor can still see and audit it.High confidence
What do I have to do to send it abroad?
The model is an allowlist run at European level, not a Dutch one. You may send personal data outside Europe only if the destination has been officially approved, or you sign the standard European contract, or you use approved group-wide rules. The approved list is full and active. The Netherlands adds no national approval step and keeps no blocklist of its own.High confidence
Who enforces this — and are they actually working?
The Dutch Data Protection Authority, and it is very much operational and very much willing to fine. It has a full three-person board, and a new chair, Geert Potjewijd, took office on 1 August 2026. It has issued two of the largest cross-border transfer fines in Europe: 290 million euros against Uber in 2024 and 100 million euros against a taxi app in May 2026. Cybersecurity is enforced separately, by sector ministries and inspectorates, and that machinery is only now being assembled.High confidence
How long must I keep it, and when must I delete it?
There is a firm floor and a soft ceiling. You must keep your books and tax records for seven years, and money-laundering records for five years after the relationship or transaction ends. Against that, privacy law says you must delete personal data once you no longer need it, and there is no fixed number. When the two collide, the legal duty to keep wins for as long as it lasts, and deletion follows immediately after.High confidence
What happens when something goes wrong?
Count three clocks, not one. For a personal data breach you have 72 hours to tell the Dutch Data Protection Authority. If you are covered by the new cybersecurity law that started on 15 August 2026, you must raise an early warning within 24 hours, file a full report within 72 hours, and deliver a final report within one month. Telecom operators have a fourth clock and must tell the privacy regulator without delay.High confidence
What's the trap?
Five things that are not in the summary. Your works council can block an HR or monitoring system. Breaking a professional secrecy duty is a crime, not a fine. The telecom retention duty printed in the law cannot be enforced. Children need a parent's permission until they turn sixteen. And the new cybersecurity law started on 15 August 2026 with a phased exception for universities that most checklists miss.High confidence
What's about to change?
Three dated changes. On 1 September 2026 an amendment act tidies up the Dutch privacy law and adds new rules for handing over health files, but one part of it has deliberately been left switched off. Registration and incident duties under the cybersecurity law that started on 15 August 2026 are being phased in now. And by 12 January 2027 every cloud provider must drop switching and data export charges to zero across Europe.High confidence
Hardest industry wall
  • Online gaming Besluit kansspelen op afstand, artikel 4.42, tweede lid
  • Government Herziening rijksbreed cloudbeleid 2026
CanadaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Canada lets data leave the country. There is no approved-country list and no banned-country list. You stay responsible for the data wherever it goes, and you must tell people it may be handled abroad. The catch is that Canada is really ten jurisdictions at once, and several of them add hard storage rules on top of the national one.
The catch
The relaxed national answer stops being true the moment you touch four things: personal information about people in Quebec, a Nova Scotia public body or its suppliers, federal government data rated Protected B or higher, or a federally regulated bank. Add to that a brand-new cyber security law that says records about critical systems in banking, telecoms, energy and transport must be kept in Canada. In those places Canada is genuinely restrictive.
Does this apply to me?
Yes. Canada's national privacy law reaches a foreign company with no office here if it handles personal information about people in Canada as part of doing business. There is no revenue or headcount threshold that lets you out. You do not normally need a local representative, but payment companies are an exception: a payment firm based abroad that aims its service at people in Canada must register with the central bank and name an agent inside Canada to receive official notices.High confidence
Can the data leave the country?
In general, yes, and with no government permission. Canada's national law does not restrict where personal data is stored or processed. But the headline is wrong for at least six groups. Quebec makes you do a written risk assessment first — and that applies even to sending data to Ontario. Nova Scotia public bodies and their suppliers must keep the data in Canada. Federal government data rated Protected B or higher must sit in Canada. Banks must keep a full copy of their records on servers in Canada. And under the new cyber security law, records about critical systems must be kept in Canada.High confidence
What do I have to do to send it abroad?
At the national level there is no list at all — no approved countries, no banned countries, no government form to file. What you must do instead is stay accountable: put a contract or similar protection in place with whoever handles the data for you, and tell people plainly that their information may be processed in another country and could be seen by foreign courts, police or security agencies. Quebec is different and stricter: there you must complete a written privacy risk assessment before the data moves, and sign a written agreement.High confidence
Who enforces this — and are they actually working?
Canada has many regulators and they are all real, staffed and issuing decisions. The national one, the Privacy Commissioner of Canada, published findings against OpenAI, X, Bell and WestJet in the first half of 2026 alone. But it cannot fine anyone — it makes findings and recommendations, and a case has to go to the Federal Court for money. Quebec's regulator can fine, and has blocked a national grocery chain from switching on a face-recognition system. Banking, payments and cyber security each have their own separate supervisor.High confidence
How long must I keep it, and when must I delete it?
The floor and the ceiling pull in opposite directions. Tax law says keep your business records for six years after the tax year they relate to, and keep them at a place of business in Canada unless the tax authority agrees to somewhere else. Privacy law says the opposite: delete personal information once the reason you collected it has gone. Where the two clash, the duty to keep wins — but only for the specific records the law names, and only for as long as it names.High confidence
What happens when something goes wrong?
Count at least four clocks and they do not agree. The national privacy law gives no fixed number of hours — you report 'as soon as feasible', which in practice means days, not weeks. Payment firms get 48 hours to tell the central bank about a serious incident. Critical infrastructure operators will get no more than 72 hours to tell the national cyber agency, then must tell their own regulator immediately after. Health and provincial rules add more. The overlap is where people get caught: one incident, several reports, several deadlines.High confidence
What's the trap?
Five things that are not in any summary. Quebec's cross-border rule catches you sending data to Ontario, not just abroad. Quebec also makes you tell its regulator 60 days before you switch on any face or fingerprint system, and it has already blocked a big grocery chain from doing so. British Columbia repealed its keep-it-in-Canada rule in 2021, so trackers that still show it are wrong. Nova Scotia's Canada-only rule reaches private suppliers, with fines up to half a million dollars. And your tax records have to sit at a place of business in Canada.High confidence
What's about to change?
One big bill and one big law already passed. The bill is Canada's third attempt to replace its 25-year-old privacy law: it would force a written risk assessment before any personal data goes outside Canada, give people a right to have data deleted, treat everyone under 18 as sensitive, and set up a new commissioner. It was only introduced in June 2026 and is not law — do not plan around it as if it were. The law already passed is the cyber security act, which switches on in stages over the coming year.High confidence
Hardest industry wall
  • Government Personal Information International Disclosure Protection Act
  • Government Direction for Electronic Data Residency (ITPIN 2017-02), with the Policy on Service and Digital
  • Banking Guideline B-10 Third-Party Risk Management, read with Bank Act section 245 and the equivalent provisions of the Insurance Companies Act and Trust and Loan Companies Act
  • All industries Critical Cyber Systems Protection Act, enacted by the Cyber Security Act (Bill C-8)