Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
NepalChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Dormant
- In one paragraph
- Nepal's privacy law says nothing about sending data abroad, so on paper data can leave freely. There is no privacy regulator at all: breaches are criminal matters taken to a local court, the maximum fine is about 215 US dollars, and no case has produced a public penalty. The real constraint is a 2025 rule on data centres and cloud services, which says customers may only buy hosting from providers on a government list.
- The catch
- The relaxed headline stops being true the moment you look at where the data physically sits. Since January 2025 anyone buying data centre or cloud services in Nepal is supposed to use only providers listed by the Department of Information Technology, and to get listed a provider must be a Nepal-registered company with a physical building in Nepal. Government security agencies must use the state's own data centre, other government bodies are being moved into it, and card payments made in Nepali rupees must be settled inside Nepal.
- Does this apply to me?
- It is unclear, and that is the honest answer. The Privacy Act covers public bodies and companies handling people's information, but it never says whether it reaches a company sitting outside Nepal, and it does not ask you to appoint anyone locally. Two other laws clearly do reach you from abroad: the computer-crime law applies to acts done outside Nepal that involve a computer located in Nepal, and the central bank's payment licensing policy expressly covers firms set up abroad that carry out payment business inside Nepal. There is no revenue or company-size threshold to fall below.Medium confidence
- Can the data leave the country?
- Under the privacy law, yes — it is silent on sending personal data out of Nepal, so there is nothing to comply with. But the country still has walls, and they are about where the machines are rather than where the data goes. Since January 2025 anyone buying data centre or cloud services is meant to use only providers on the government's published list, and listing requires a Nepal-registered company with a building in Nepal. Government security agencies must use the state's own data centre, and card payments made in Nepali rupees must be settled inside Nepal.Medium confidence
- What do I have to do to send it abroad?
- Nothing. There is no approval to get, no standard contract to sign and no list of approved countries, because Nepal's privacy law simply does not deal with sending data abroad. The control that does exist works the other way round: it is an approved-supplier list for hosting. The Department of Information Technology lists data centre and cloud providers, and customers are told to use only listed ones.Medium confidence
- Who enforces this — and are they actually working?
- For personal data, nobody. Nepal has no privacy regulator and no data protection authority. A person whose privacy is breached files a criminal complaint in their local district court within three months, and the court can also award compensation. The bodies that are genuinely active work on cyber security and on industry rules, not on privacy: the National Cyber Security Center published advisories as recently as April 2026, the telecoms authority collects security audit reports, the central bank issues payment directives, and the Department of Information Technology is running the data centre listing scheme.Medium confidence
- How long must I keep it, and when must I delete it?
- There is a floor and almost no ceiling. Tax records must be kept for five years after the tax year ends. Telecom operators must keep security logs for at least six months and internet address-translation logs for at least three months. Data centres must keep camera footage for at least three months. Going the other way, the privacy law has no general delete-by date, so the only real deletion duty found is a telecom rule that says paper customer forms must be destroyed once they have been scanned.Medium confidence
- What happens when something goes wrong?
- There is no general duty to report a personal data breach in Nepal — not to a regulator, and not to the people affected. No rule found sets a deadline in hours. Two narrower duties do exist. A data centre or cloud provider that finds someone has got into its systems must tell the regulator and the National Cyber Security Center immediately, by the fastest means available. A telecom operator hit by a security incident must work with a standing task force at the telecoms authority.Medium confidence
- What's the trap?
- Five. First, privacy breaches are criminal, not administrative — the exposure is up to three years in prison for an individual, not a corporate fine. Second, a victim has only three months from the act to complain, so most claims die of old age. Third, your cloud vendor must be on the government's list, which makes this a supplier problem rather than a policy problem. Fourth, anyone under 18 needs a guardian's consent — there is no lower digital age. Fifth, the online-content offence in the electronic transactions law carries up to five years in prison for material judged contrary to public morality, and it is written vaguely enough to catch ordinary posts.High confidence
- What's about to change?
- No data protection law is on the way that we could find, and no bill for one is before parliament. What is moving is telecoms and broadcasting: the ministry published discussion papers for a new Telecommunications Bill and a National Mass Communication Bill on 5 August 2026. The telecoms authority is consulting on amending its 2020 cyber security rules, on a framework for streaming and messaging services, and on a rule to force the move to newer internet addressing.Medium confidence
- Hardest industry wall
- All industries — डाटा सेन्टर तथा क्लाउड सेवा (सञ्चालन तथा व्यवस्थापन) निर्देशिका, २०८१ (Data Center and Cloud Service (Operation and Management) Directives, 2081)
- Payments — भुक्तानी प्रणालीसम्बन्धी एकीकृत निर्देशन, २०८२ (Unified Directive on Payment Systems, 2082)
United Arab EmiratesChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Waking up
- In one paragraph
- The national privacy law has been in force since January 2022, but the rules that make it work were never written, so almost none of it can be enforced. Meanwhile the industries that matter have hard walls: health records, payment data, insurance data and identity-check reports must stay inside the country. Two financial districts run their own separate privacy systems, and those regulators do issue penalties.
- The catch
- The relaxed national picture is false the moment you touch health, payments, insurance, credit and identity checks, or government data. The national law expressly does not cover health data, banking data, government data, or companies inside the financial free zones. For most regulated businesses the national law is not the rule that binds them.
- Does this apply to me?
- Yes. The national privacy law reaches a company with no office in the country, as long as it handles the personal data of people inside the country. There is no revenue or headcount threshold to hide under. But the law carves out huge areas: government bodies, government data, health data, banking and credit data, and companies inside the financial free zones that have their own privacy laws.High confidence
- Can the data leave the country?
- It depends entirely on your industry. Under the national law data can leave once you have the right paperwork, and in practice nobody is checking. But four industries have real walls. Health records may not be stored or sent abroad at all. Payment data must be stored inside the country. Insurance data must be stored inside the country. And since April 2026 the national identity-check report may not be taken out of the country at all.High confidence
- What do I have to do to send it abroad?
- On paper the model is an approved-destinations list. The regulator is supposed to name countries whose protection is good enough, and no list has ever been published. So in practice everyone uses the fallback route: a contract with the recipient promising equivalent protection, or the person's explicit consent, or a narrow necessity exception. No government permission is needed and no filing is made, because the rules that would create those steps were never written.High confidence
- Who enforces this — and are they actually working?
- On paper the UAE Data Office. In practice it has never enforced anything: it has no public website, it has published no approved-destinations list, and the government decision that would set the fines has not been made. The regulators that really bite are elsewhere — the central bank fined a foreign bank branch about 5.4 million dollars in June 2026, and the data protection commissioner in the Abu Dhabi financial district has issued published penalty notices.Medium confidence
- How long must I keep it, and when must I delete it?
- The floors are long and they are set by industry, not by the privacy law. Health records must be kept for at least 25 years after the last treatment. Payment data must be kept for 5 years with a separate backup. Identity-check reports must be kept for at least 5 years. There is no working national deletion deadline, because the detailed rules that would set one were never issued.High confidence
- What happens when something goes wrong?
- There is no national deadline in hours today. The privacy law says you must tell the regulator as soon as you discover a breach, and leaves the actual timing and the wording of the notice to detailed rules that were never issued. So the clocks that really run are the ones set by your own regulator: the central bank for financial firms, and the separate data protection offices in the two financial districts. The national cyber incident reporting service is aimed at government bodies, not at private companies.Medium confidence
- What's the trap?
- Five things that cost people their weekend. One: the national privacy law does not cover health data, banking data, government data, or companies in the financial free zones, so most regulated firms are not governed by it at all. Two: health data may not leave the country, ever, and the fine is up to about 190 thousand dollars. Three: since April 2026 the national identity-check report may not be sent abroad. Four: a child is anyone under 18, but the parental consent line is drawn at 13. Five: there are two extra legal systems inside the country, and their regulators actually issue penalties.High confidence
- What's about to change?
- The single biggest thing is a rule that could appear on any Tuesday. When the government finally publishes the detailed rules under the privacy law, every company gets six months to comply and the law switches from decorative to real. Nothing signals when that will happen. In the meantime the new child safety law needs its penalty schedule, and the national identity-check platform is being rolled out across banks.Medium confidence
- Hardest industry wall
- Health and social care — Federal Law No. (2) of 2019 Concerning the Use of the Information and Communications Technology in Health Fields
- Payments — Retail Payment Services and Card Schemes Regulation
- Insurance — Insurance Authority Board of Directors' Resolution No. (18) of 2020 Concerning the Electronic Insurance Regulations
- Banking — Cabinet Resolution No. (55) of 2026 Promulgating the Executive Regulations of Federal Decree-Law No. (30) of 2024 Regarding the "Know Your Customer" Digital Platform