Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
NetherlandsChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
- In one paragraph
- For most businesses the Netherlands follows the ordinary European rules: data may leave the country once you have the right paperwork in place. Two areas are much harder. Online gambling firms must keep their regulator-facing database physically in the Netherlands, and central government now has to keep all its information inside Europe. The Dutch privacy regulator hands out some of the largest transfer fines in Europe.
- The catch
- The relaxed headline stops being true the moment you touch online gambling, central government work, health records or a regulated financial firm. An online gambling licence forces one database onto Dutch soil. Central government contracts now bar storage outside Europe. And a brand-new cybersecurity law switched on three days ago, on 15 August 2026, with a 24-hour incident alarm most companies have not built yet.
- Does this apply to me?
- Yes, it reaches you with no Dutch office. Europe's privacy law applies to any organisation anywhere that offers goods or services to people in the Netherlands or watches what they do online, and there is no size or revenue floor. Separately, the new Dutch cybersecurity law says that if you are a cloud provider, data centre, managed service provider, online marketplace, search engine or social network based outside Europe but selling into the Netherlands, you must appoint a representative inside the European Union.High confidence
- Can the data leave the country?
- In general yes, with paperwork, because the Netherlands is an EU country and European rules govern transfers. But three Dutch walls override that. An online gambling licence holder must physically place its regulator-facing control database in the Netherlands. Central government must keep all its information inside the European Economic Area plus Switzerland. And a healthcare provider, bank or insurer can put data abroad only if the supervisor can still see and audit it.High confidence
- What do I have to do to send it abroad?
- The model is an allowlist run at European level, not a Dutch one. You may send personal data outside Europe only if the destination has been officially approved, or you sign the standard European contract, or you use approved group-wide rules. The approved list is full and active. The Netherlands adds no national approval step and keeps no blocklist of its own.High confidence
- Who enforces this — and are they actually working?
- The Dutch Data Protection Authority, and it is very much operational and very much willing to fine. It has a full three-person board, and a new chair, Geert Potjewijd, took office on 1 August 2026. It has issued two of the largest cross-border transfer fines in Europe: 290 million euros against Uber in 2024 and 100 million euros against a taxi app in May 2026. Cybersecurity is enforced separately, by sector ministries and inspectorates, and that machinery is only now being assembled.High confidence
- How long must I keep it, and when must I delete it?
- There is a firm floor and a soft ceiling. You must keep your books and tax records for seven years, and money-laundering records for five years after the relationship or transaction ends. Against that, privacy law says you must delete personal data once you no longer need it, and there is no fixed number. When the two collide, the legal duty to keep wins for as long as it lasts, and deletion follows immediately after.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. For a personal data breach you have 72 hours to tell the Dutch Data Protection Authority. If you are covered by the new cybersecurity law that started on 15 August 2026, you must raise an early warning within 24 hours, file a full report within 72 hours, and deliver a final report within one month. Telecom operators have a fourth clock and must tell the privacy regulator without delay.High confidence
- What's the trap?
- Five things that are not in the summary. Your works council can block an HR or monitoring system. Breaking a professional secrecy duty is a crime, not a fine. The telecom retention duty printed in the law cannot be enforced. Children need a parent's permission until they turn sixteen. And the new cybersecurity law started on 15 August 2026 with a phased exception for universities that most checklists miss.High confidence
- What's about to change?
- Three dated changes. On 1 September 2026 an amendment act tidies up the Dutch privacy law and adds new rules for handing over health files, but one part of it has deliberately been left switched off. Registration and incident duties under the cybersecurity law that started on 15 August 2026 are being phased in now. And by 12 January 2027 every cloud provider must drop switching and data export charges to zero across Europe.High confidence
- Hardest industry wall
- Online gaming — Besluit kansspelen op afstand, artikel 4.42, tweede lid
- Government — Herziening rijksbreed cloudbeleid 2026
MongoliaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Waking up
- In one paragraph
- Mongolia is not an open country for data. As a rule you may not send personal data abroad at all unless the person agrees or a law says you can. On top of that, a 2023 ministry order says that any server handling sensitive data must sit in Mongolia and must be reachable only from inside Mongolia. Sensitive data is defined very widely and includes health records and the content of messages.
- The catch
- Do not read 'depends on your industry' as 'open in general'. The baseline is already a ban with a consent exception. The hard walls are drawn by data type as much as by industry: health data, biometrics, genetic data, criminal records, digital signature keys and the content of letters, e-mail and messages all fall inside the server-in-Mongolia rule, whatever business you are in. Government bodies, state-owned and state-part-owned companies, and any company running a government service under a law or contract face a second wall over their databases.
- Does this apply to me?
- Probably not, if you have no presence in Mongolia at all. The privacy law says it governs how people, companies and unincorporated bodies collect, process and use personal data, but it does not say it reaches organisations outside the country. There is no revenue or size threshold, and there is no duty to appoint a local representative. In practice the rules bite through your Mongolian company, your Mongolian server, or your Mongolian licence rather than through long-arm reach.Medium confidence
- Can the data leave the country?
- Only sometimes, and for a lot of data the answer is a flat no. The general rule is that sending personal data to a person, company or international body abroad is banned unless a law or a treaty allows it, or the person the data is about has agreed. Then a separate ministry order takes health data, biometrics, genetic data, criminal records, digital signature keys and the content of letters, e-mail and messages out of reach entirely: the server has to be in Mongolia and has to be reachable only from Mongolia. Government systems and the country's foundational databases must also stay in Mongolia.High confidence
- What do I have to do to send it abroad?
- There is no approval process, no standard contract and no list of approved countries. Mongolia works the other way round: the transfer is banned, and the only ways out are a law or treaty that allows it, or the written consent of the person concerned. Consent is not a light-touch tick box. You must name every recipient before you collect the data, you must be able to prove the consent, and the person can withdraw it at any time.High confidence
- Who enforces this — and are they actually working?
- Nobody owns privacy on its own. The law splits the job three ways: the National Human Rights Commission handles complaints and supervision, the Ministry of Digital Development, Innovation and Communications writes the technical rules and takes cyber incident reports, and other state bodies police their own sectors. The ministry is clearly working: it has issued binding orders and it keeps a live register of 49 licensed information security auditors. What we could not find is any published privacy fine or decision, so treat the privacy side as switched on but not yet biting.Medium confidence
- How long must I keep it, and when must I delete it?
- Mongolia is unusual: the privacy law tells you when you may delete, not just when you must. You may only erase personal data on four listed grounds, and deleting it on any other ground is forbidden. Pulling the other way, payment businesses must keep their records for at least 15 years, anyone handling sensitive data must keep a history log of every change, deletion and restoration, and organisations running shared information systems must keep activity logs for a period fixed by government rules.High confidence
- What happens when something goes wrong?
- There are three clocks and none of them is measured in hours. The word the laws use is 'immediately', which they define as the shortest possible time. You tell the affected person immediately if the problem could harm them, you tell the ministry immediately if your system's security failed or you were attacked, and if you run critical national infrastructure you tell the national response centre immediately as well. Once a year, every January, you also send the human rights commission a register of the incidents you had and what you did about them.High confidence
- What's the trap?
- Five things catch people out. First, fingerprint scanners at work are illegal for private employers: an employer may use other biometrics with the worker's consent, but never fingerprints, and may not pass that biometric data to anyone else. Second, 'sensitive data' includes the content of letters, e-mail and messages, which drags ordinary company mail systems towards the server-in-Mongolia rule. Third, financial and payment data is not classed as sensitive, but a fingerprint or face login for a banking app is, so banks land inside the strict rules by the back door. Fourth, breaking the privacy law can be a crime, not just a fine. Fifth, if you build data storage or a content delivery network inside Mongolia you need a telecoms licence.High confidence
- What's about to change?
- One big thing is in motion. The government decided on 13 May 2026 to build a legal framework for putting data into economic circulation and reuse, and to prepare for a green, energy-efficient data centre in Mongolia. The ministry is now consulting on a first Data Law. It is a draft, so nothing in it binds anyone yet. The bigger short-term risk is not new legislation at all: the minister can rewrite the server and storage rules by a simple order, without parliament and without consultation.Medium confidence
- Hardest industry wall
- Health and social care — Хүний эмзэг мэдээлэл, генетик болон биометрик мэдээлэл боловсруулахад баримтлах технологийн аюулгүй байдлын шаардлага, журам
- Government — Нийтийн мэдээллийн ил тод байдлын тухай хууль
- Mapping and location — Нийтийн мэдээллийн ил тод байдлын тухай хууль, 27.3, 27.7 дугаар зүйл
- All industries — Хүний хувийн мэдээлэл хамгаалах тухай хууль, 10, 31 дүгээр зүйл