Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
NetherlandsChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
- In one paragraph
- For most businesses the Netherlands follows the ordinary European rules: data may leave the country once you have the right paperwork in place. Two areas are much harder. Online gambling firms must keep their regulator-facing database physically in the Netherlands, and central government now has to keep all its information inside Europe. The Dutch privacy regulator hands out some of the largest transfer fines in Europe.
- The catch
- The relaxed headline stops being true the moment you touch online gambling, central government work, health records or a regulated financial firm. An online gambling licence forces one database onto Dutch soil. Central government contracts now bar storage outside Europe. And a brand-new cybersecurity law switched on three days ago, on 15 August 2026, with a 24-hour incident alarm most companies have not built yet.
- Does this apply to me?
- Yes, it reaches you with no Dutch office. Europe's privacy law applies to any organisation anywhere that offers goods or services to people in the Netherlands or watches what they do online, and there is no size or revenue floor. Separately, the new Dutch cybersecurity law says that if you are a cloud provider, data centre, managed service provider, online marketplace, search engine or social network based outside Europe but selling into the Netherlands, you must appoint a representative inside the European Union.High confidence
- Can the data leave the country?
- In general yes, with paperwork, because the Netherlands is an EU country and European rules govern transfers. But three Dutch walls override that. An online gambling licence holder must physically place its regulator-facing control database in the Netherlands. Central government must keep all its information inside the European Economic Area plus Switzerland. And a healthcare provider, bank or insurer can put data abroad only if the supervisor can still see and audit it.High confidence
- What do I have to do to send it abroad?
- The model is an allowlist run at European level, not a Dutch one. You may send personal data outside Europe only if the destination has been officially approved, or you sign the standard European contract, or you use approved group-wide rules. The approved list is full and active. The Netherlands adds no national approval step and keeps no blocklist of its own.High confidence
- Who enforces this — and are they actually working?
- The Dutch Data Protection Authority, and it is very much operational and very much willing to fine. It has a full three-person board, and a new chair, Geert Potjewijd, took office on 1 August 2026. It has issued two of the largest cross-border transfer fines in Europe: 290 million euros against Uber in 2024 and 100 million euros against a taxi app in May 2026. Cybersecurity is enforced separately, by sector ministries and inspectorates, and that machinery is only now being assembled.High confidence
- How long must I keep it, and when must I delete it?
- There is a firm floor and a soft ceiling. You must keep your books and tax records for seven years, and money-laundering records for five years after the relationship or transaction ends. Against that, privacy law says you must delete personal data once you no longer need it, and there is no fixed number. When the two collide, the legal duty to keep wins for as long as it lasts, and deletion follows immediately after.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. For a personal data breach you have 72 hours to tell the Dutch Data Protection Authority. If you are covered by the new cybersecurity law that started on 15 August 2026, you must raise an early warning within 24 hours, file a full report within 72 hours, and deliver a final report within one month. Telecom operators have a fourth clock and must tell the privacy regulator without delay.High confidence
- What's the trap?
- Five things that are not in the summary. Your works council can block an HR or monitoring system. Breaking a professional secrecy duty is a crime, not a fine. The telecom retention duty printed in the law cannot be enforced. Children need a parent's permission until they turn sixteen. And the new cybersecurity law started on 15 August 2026 with a phased exception for universities that most checklists miss.High confidence
- What's about to change?
- Three dated changes. On 1 September 2026 an amendment act tidies up the Dutch privacy law and adds new rules for handing over health files, but one part of it has deliberately been left switched off. Registration and incident duties under the cybersecurity law that started on 15 August 2026 are being phased in now. And by 12 January 2027 every cloud provider must drop switching and data export charges to zero across Europe.High confidence
- Hardest industry wall
- Online gaming — Besluit kansspelen op afstand, artikel 4.42, tweede lid
- Government — Herziening rijksbreed cloudbeleid 2026
SerbiaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Serbia copied Europe's privacy law almost word for word, so the duties feel familiar. Data can leave the country, and for most of Europe and a long list of other countries it can leave with no paperwork at all. The privacy regulator is busy — over a thousand inspections in 2025 — but it hands out warnings, not fines. The biggest fine any Serbian court imposed for a privacy breach in 2025 was about $950.
- The catch
- Two industries break the general picture. Online gambling operators must keep a copy of their whole player and transaction database physically inside Serbia. Banks, insurers and other financial firms cannot move any IT work abroad without telling the central bank 30 days ahead, proving the foreign country would let Serbian supervisors inspect on site, and risking a veto that forces them to cancel the contract.
- Does this apply to me?
- Yes. The law reaches a company anywhere in the world if it offers goods or services to people in Serbia, or watches what they do in Serbia. There is no size or revenue threshold to hide behind. If you are caught this way you must appoint a written representative living or based in Serbia, unless your processing is occasional and low risk or you are a public body.High confidence
- Can the data leave the country?
- Yes, with paperwork — and often with none at all. Serbia treats a very long list of countries as automatically safe: every member of the Council of Europe's data protection treaty, which covers all of Europe plus Argentina, Mexico, Morocco, Mauritius, Senegal, Tunisia, Uruguay, Cape Verde and others, and separately every country the European Union has approved. Sending data there needs no permission and no contract. Everywhere else you sign the Commissioner's standard contract or use approved group rules. Only one industry has a hard wall: online gambling. Banking has a gate rather than a wall.High confidence
- What do I have to do to send it abroad?
- First check the destination. If it is on the safe list, you need nothing — no contract, no filing, no approval. If it is not, you sign the standard contract the Serbian regulator published in January 2020, or you get approved group-wide rules. If you want to use your own wording instead of the standard contract, the regulator must approve it and has 60 days to answer. As a last resort there are narrow exceptions such as the person's explicit consent.High confidence
- Who enforces this — and are they actually working?
- The Commissioner for Information of Public Importance and Personal Data Protection, and it is genuinely working. In 2025 it finished 1,169 inspections, received 5,310 cases and issued 102 corrective orders. But it almost never fines. Of those 102 orders, 101 were warnings and one was a ban on processing. It asked the courts to punish only three organisations all year. Banks answer to the National Bank of Serbia instead, and it is fully active. A brand-new Office for Information Security exists on paper since October 2025 but we could find no sign it is running yet.High confidence
- How long must I keep it, and when must I delete it?
- There is no single national rule. The privacy law says keep data only as long as you need it, and each sector sets its own clock. Online gambling operators must keep every transaction for at least ten years. Phone and internet companies must keep who-called-whom records for exactly 12 months and then destroy them. Anyone selling a phone line must keep the customer's identity check for 12 months after the service ends. Financial firms must keep a live register of every outsourced service, including which countries the data sits in.High confidence
- What happens when something goes wrong?
- Count three clocks. Privacy breach: tell the Commissioner without delay and at the latest within 72 hours, and if you miss that you must explain why. Cyber incident: if you run an information system the state has classed as important, you have only 24 hours to report it. Then a third clock starts — updates every 24 hours for a serious incident, every three days for a middling one, and a final report within 15 days of the incident ending. Banks report cyber incidents to the central bank instead, promptly, with no fixed hour count.High confidence
- What's the trap?
- Five. (1) A child can consent for themselves at 15, not 13 or 16 — plan your age gates around 15. (2) A foreign court order or foreign tax authority demand for data is recognised in Serbia only if a treaty backs it, so handing data to an overseas authority on request can itself be unlawful. (3) Individuals, not just companies, can be prosecuted; the regulator has filed 49 criminal complaints since 2010. (4) Dozens of older Serbian laws still contradict the privacy law and were never fixed. (5) The government's official list of safe destination countries has not been touched since 2019 and still names a United States framework that died in 2020.High confidence
- What's about to change?
- One dated change and several unscheduled ones. From 1 January 2027 the ministry formally takes over supervising the new Office for Information Security, which should mean the office is actually up and running by then. A rewrite of the privacy law is being drafted by a special working group covering video surveillance, biometrics, genetic data and artificial intelligence, and a separate group is drafting an artificial intelligence law. Neither has been published as a bill, so neither is binding.High confidence
- Hardest industry wall
- Online gaming — Pravilnik o informaciono-komunikacionom sistemu za priređivanje posebnih igara na sreću preko sredstava elektronske komunikacije