Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
NepalChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Dormant
In one paragraph
Nepal's privacy law says nothing about sending data abroad, so on paper data can leave freely. There is no privacy regulator at all: breaches are criminal matters taken to a local court, the maximum fine is about 215 US dollars, and no case has produced a public penalty. The real constraint is a 2025 rule on data centres and cloud services, which says customers may only buy hosting from providers on a government list.
The catch
The relaxed headline stops being true the moment you look at where the data physically sits. Since January 2025 anyone buying data centre or cloud services in Nepal is supposed to use only providers listed by the Department of Information Technology, and to get listed a provider must be a Nepal-registered company with a physical building in Nepal. Government security agencies must use the state's own data centre, other government bodies are being moved into it, and card payments made in Nepali rupees must be settled inside Nepal.
Does this apply to me?
It is unclear, and that is the honest answer. The Privacy Act covers public bodies and companies handling people's information, but it never says whether it reaches a company sitting outside Nepal, and it does not ask you to appoint anyone locally. Two other laws clearly do reach you from abroad: the computer-crime law applies to acts done outside Nepal that involve a computer located in Nepal, and the central bank's payment licensing policy expressly covers firms set up abroad that carry out payment business inside Nepal. There is no revenue or company-size threshold to fall below.Medium confidence
Can the data leave the country?
Under the privacy law, yes — it is silent on sending personal data out of Nepal, so there is nothing to comply with. But the country still has walls, and they are about where the machines are rather than where the data goes. Since January 2025 anyone buying data centre or cloud services is meant to use only providers on the government's published list, and listing requires a Nepal-registered company with a building in Nepal. Government security agencies must use the state's own data centre, and card payments made in Nepali rupees must be settled inside Nepal.Medium confidence
What do I have to do to send it abroad?
Nothing. There is no approval to get, no standard contract to sign and no list of approved countries, because Nepal's privacy law simply does not deal with sending data abroad. The control that does exist works the other way round: it is an approved-supplier list for hosting. The Department of Information Technology lists data centre and cloud providers, and customers are told to use only listed ones.Medium confidence
Who enforces this — and are they actually working?
For personal data, nobody. Nepal has no privacy regulator and no data protection authority. A person whose privacy is breached files a criminal complaint in their local district court within three months, and the court can also award compensation. The bodies that are genuinely active work on cyber security and on industry rules, not on privacy: the National Cyber Security Center published advisories as recently as April 2026, the telecoms authority collects security audit reports, the central bank issues payment directives, and the Department of Information Technology is running the data centre listing scheme.Medium confidence
How long must I keep it, and when must I delete it?
There is a floor and almost no ceiling. Tax records must be kept for five years after the tax year ends. Telecom operators must keep security logs for at least six months and internet address-translation logs for at least three months. Data centres must keep camera footage for at least three months. Going the other way, the privacy law has no general delete-by date, so the only real deletion duty found is a telecom rule that says paper customer forms must be destroyed once they have been scanned.Medium confidence
What happens when something goes wrong?
There is no general duty to report a personal data breach in Nepal — not to a regulator, and not to the people affected. No rule found sets a deadline in hours. Two narrower duties do exist. A data centre or cloud provider that finds someone has got into its systems must tell the regulator and the National Cyber Security Center immediately, by the fastest means available. A telecom operator hit by a security incident must work with a standing task force at the telecoms authority.Medium confidence
What's the trap?
Five. First, privacy breaches are criminal, not administrative — the exposure is up to three years in prison for an individual, not a corporate fine. Second, a victim has only three months from the act to complain, so most claims die of old age. Third, your cloud vendor must be on the government's list, which makes this a supplier problem rather than a policy problem. Fourth, anyone under 18 needs a guardian's consent — there is no lower digital age. Fifth, the online-content offence in the electronic transactions law carries up to five years in prison for material judged contrary to public morality, and it is written vaguely enough to catch ordinary posts.High confidence
What's about to change?
No data protection law is on the way that we could find, and no bill for one is before parliament. What is moving is telecoms and broadcasting: the ministry published discussion papers for a new Telecommunications Bill and a National Mass Communication Bill on 5 August 2026. The telecoms authority is consulting on amending its 2020 cyber security rules, on a framework for streaming and messaging services, and on a rule to force the move to newer internet addressing.Medium confidence
Hardest industry wall
  • All industries डाटा सेन्टर तथा क्लाउड सेवा (सञ्चालन तथा व्यवस्थापन) निर्देशिका, २०८१ (Data Center and Cloud Service (Operation and Management) Directives, 2081)
  • Payments भुक्तानी प्रणालीसम्बन्धी एकीकृत निर्देशन, २०८२ (Unified Directive on Payment Systems, 2082)
FranceChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
In one paragraph
France follows the European rule: data may leave, but only once the right paperwork is in place. France then adds hard walls of its own. Health records must be stored inside Europe. Online gambling records must sit on a machine in mainland France. From 1 September 2026 the invoicing platform every French business must use has to run entirely from inside Europe.
The catch
"France has no local storage rule" is true for an ordinary business and false the moment you touch health data, online gambling, electronic invoicing or a government contract involving sensitive state data. In those four areas France is among the strictest countries in Europe. Since March 2026 the health rule sits in a decree, not just a certification standard, so it now binds the customer as well as the supplier.
Does this apply to me?
Yes. France reaches a company with no office in the country. European law already applies to anyone offering goods or services to people in Europe. On top of that, France's own privacy law says its national rules apply as soon as the person concerned lives in France, even when the company is based somewhere else. There is no size or revenue threshold that lets you escape.High confidence
Can the data leave the country?
For an ordinary business, yes, with paperwork: the European transfer rules apply and nothing extra is added. But four French sectors override that. Health records must be stored inside Europe and nowhere else. Online gambling records must be archived in real time on hardware in mainland France. Electronic invoicing platforms must run their whole system from inside Europe. And sensitive state data must sit on a cloud that the French cyber agency has certified as beyond the reach of foreign authorities.High confidence
What do I have to do to send it abroad?
The model is an approved-list one, run from Brussels rather than Paris. Data may go to a country the European Commission has formally approved, or anywhere else if you sign the official standard contract and write down why you think the data will still be safe. The list of approved countries is full, not empty: it includes the United Kingdom, Japan, South Korea, Canada, Switzerland, Brazil and about a dozen others, plus American companies that have signed up to the transatlantic framework. France adds no separate national approval step.High confidence
Who enforces this — and are they actually working?
The privacy regulator is the CNIL, and it is one of the busiest in Europe. In 2025 alone it issued 83 penalties totalling about 487 million euros (roughly 530 million dollars), plus 143 formal warnings. It is still fining in 2026: 5 million euros against the national employment agency in January and 5 million against a health data company in May. Separate regulators run the sector walls, and all of them are staffed and working.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling and they pull in opposite directions. You must keep accounting books and supporting documents for ten years, tax records for six, employment contracts and pay records for five, and telephone and internet subscriber identity data for five. In the other direction, European law says you must delete personal data once you no longer need it. France resolves the clash the same way most of Europe does: the legal minimum wins, but only for the specific documents the law names, and only for as long as it names.High confidence
What happens when something goes wrong?
Count the clocks, because France has at least four and they run at different speeds. Every organisation has 72 hours to tell the CNIL about a personal data breach. Telephone and internet providers have only 24 hours. Hospitals and clinics must report a serious computer security incident to their regional health agency immediately. Banks, insurers and investment firms have their own European deadlines: an initial report within 4 hours of classifying a major incident and no later than 24 hours after they notice it.High confidence
What's the trap?
Five things that are not in the summary. (1) Breaking the privacy law in France is a crime, not just a fine: sending data out of Europe unlawfully carries up to five years in prison and a 300,000 euro fine (about 330,000 dollars), and it attaches to people, not only companies. (2) A child is anyone under 15 for consent, not 13 or 16. (3) A 2023 law setting a social media age of 15 is printed in the statute book but has never come into force and cannot be enforced. (4) Handing documents to a foreign court or regulator can itself be a criminal offence in France. (5) Cookies are policed separately from the rest of privacy law, so a foreign company cannot hide behind its lead European regulator.High confidence
What's about to change?
Four dates in the next twelve months. 1 September 2026: every French business must be able to send and receive invoices through an approved platform, and those platforms must run entirely from inside Europe. Around 27 September 2026: the second phase of the health data hosting decree starts. 21 October 2026: the order forcing telephone and internet companies to keep everyone's connection records for a year expires unless the Prime Minister renews it. 12 January 2027: cloud providers across Europe must drop switching and data export fees to zero.Medium confidence
Hardest industry wall
  • Health and social care Decret n° 2026-209 du 24 mars 2026 portant modification de certaines dispositions du code de la sante publique relatives a l'hebergement de donnees de sante a caractere personnel
  • Government Decret n° 2026-272 du 14 avril 2026 relatif a la protection des donnees d'une sensibilite particuliere des administrations, operateurs et groupements d'interet public de l'Etat traitees par un service d'informatique en nuage fourni par un prestataire prive
  • All industries Immatriculation des plateformes agreees (ex plateformes de dematerialisation partenaires) - facturation electronique
  • Online gaming Article 31 de la loi n° 2010-476 du 12 mai 2010 relative a l'ouverture a la concurrence et a la regulation du secteur des jeux d'argent et de hasard en ligne