Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
NepalChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Dormant
- In one paragraph
- Nepal's privacy law says nothing about sending data abroad, so on paper data can leave freely. There is no privacy regulator at all: breaches are criminal matters taken to a local court, the maximum fine is about 215 US dollars, and no case has produced a public penalty. The real constraint is a 2025 rule on data centres and cloud services, which says customers may only buy hosting from providers on a government list.
- The catch
- The relaxed headline stops being true the moment you look at where the data physically sits. Since January 2025 anyone buying data centre or cloud services in Nepal is supposed to use only providers listed by the Department of Information Technology, and to get listed a provider must be a Nepal-registered company with a physical building in Nepal. Government security agencies must use the state's own data centre, other government bodies are being moved into it, and card payments made in Nepali rupees must be settled inside Nepal.
- Does this apply to me?
- It is unclear, and that is the honest answer. The Privacy Act covers public bodies and companies handling people's information, but it never says whether it reaches a company sitting outside Nepal, and it does not ask you to appoint anyone locally. Two other laws clearly do reach you from abroad: the computer-crime law applies to acts done outside Nepal that involve a computer located in Nepal, and the central bank's payment licensing policy expressly covers firms set up abroad that carry out payment business inside Nepal. There is no revenue or company-size threshold to fall below.Medium confidence
- Can the data leave the country?
- Under the privacy law, yes — it is silent on sending personal data out of Nepal, so there is nothing to comply with. But the country still has walls, and they are about where the machines are rather than where the data goes. Since January 2025 anyone buying data centre or cloud services is meant to use only providers on the government's published list, and listing requires a Nepal-registered company with a building in Nepal. Government security agencies must use the state's own data centre, and card payments made in Nepali rupees must be settled inside Nepal.Medium confidence
- What do I have to do to send it abroad?
- Nothing. There is no approval to get, no standard contract to sign and no list of approved countries, because Nepal's privacy law simply does not deal with sending data abroad. The control that does exist works the other way round: it is an approved-supplier list for hosting. The Department of Information Technology lists data centre and cloud providers, and customers are told to use only listed ones.Medium confidence
- Who enforces this — and are they actually working?
- For personal data, nobody. Nepal has no privacy regulator and no data protection authority. A person whose privacy is breached files a criminal complaint in their local district court within three months, and the court can also award compensation. The bodies that are genuinely active work on cyber security and on industry rules, not on privacy: the National Cyber Security Center published advisories as recently as April 2026, the telecoms authority collects security audit reports, the central bank issues payment directives, and the Department of Information Technology is running the data centre listing scheme.Medium confidence
- How long must I keep it, and when must I delete it?
- There is a floor and almost no ceiling. Tax records must be kept for five years after the tax year ends. Telecom operators must keep security logs for at least six months and internet address-translation logs for at least three months. Data centres must keep camera footage for at least three months. Going the other way, the privacy law has no general delete-by date, so the only real deletion duty found is a telecom rule that says paper customer forms must be destroyed once they have been scanned.Medium confidence
- What happens when something goes wrong?
- There is no general duty to report a personal data breach in Nepal — not to a regulator, and not to the people affected. No rule found sets a deadline in hours. Two narrower duties do exist. A data centre or cloud provider that finds someone has got into its systems must tell the regulator and the National Cyber Security Center immediately, by the fastest means available. A telecom operator hit by a security incident must work with a standing task force at the telecoms authority.Medium confidence
- What's the trap?
- Five. First, privacy breaches are criminal, not administrative — the exposure is up to three years in prison for an individual, not a corporate fine. Second, a victim has only three months from the act to complain, so most claims die of old age. Third, your cloud vendor must be on the government's list, which makes this a supplier problem rather than a policy problem. Fourth, anyone under 18 needs a guardian's consent — there is no lower digital age. Fifth, the online-content offence in the electronic transactions law carries up to five years in prison for material judged contrary to public morality, and it is written vaguely enough to catch ordinary posts.High confidence
- What's about to change?
- No data protection law is on the way that we could find, and no bill for one is before parliament. What is moving is telecoms and broadcasting: the ministry published discussion papers for a new Telecommunications Bill and a National Mass Communication Bill on 5 August 2026. The telecoms authority is consulting on amending its 2020 cyber security rules, on a framework for streaming and messaging services, and on a rule to force the move to newer internet addressing.Medium confidence
- Hardest industry wall
- All industries — डाटा सेन्टर तथा क्लाउड सेवा (सञ्चालन तथा व्यवस्थापन) निर्देशिका, २०८१ (Data Center and Cloud Service (Operation and Management) Directives, 2081)
- Payments — भुक्तानी प्रणालीसम्बन्धी एकीकृत निर्देशन, २०८२ (Unified Directive on Payment Systems, 2082)
IndonesiaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Waking up
- In one paragraph
- Indonesia's general privacy law lets data leave if the destination protects it about as well as Indonesia does, or you use strong safeguards, or the person agrees. Money and health are walled off. Banks, payment firms, insurers and non-bank lenders must run their systems on Indonesian soil unless the financial regulator says otherwise, and medical records must sit with a local storage provider.
- The catch
- The relaxed headline is true only until you touch banking, payments, insurance and other non-bank finance, electronic medical records, or public-sector systems. In those areas the servers themselves must be in Indonesia, and moving them out needs a written permission that the banking regulator may take three months to grant. The general privacy watchdog looks quiet; the financial regulators are not.
- Does this apply to me?
- Yes. The privacy law follows the data, not the office. It covers any organisation, inside or outside Indonesia, whose handling of personal data has legal effects in Indonesia or affects people in Indonesia. There is no size or revenue cut-off to fall below. An organisation with no presence in the country is expected to name a representative in Indonesia, and any online service used by Indonesians is also expected to register with the digital ministry, which can order internet providers to block services that do not.Medium confidence
- Can the data leave the country?
- In general yes, with homework. You must be able to show the destination protects personal data at a level at least equal to Indonesia's, or put binding safeguards in place, or get the person's clear agreement. That general answer stops at the door of finance, health and government. Banks, payment providers, insurers and other non-bank financial firms must keep their systems in Indonesian data centres and back-up centres, and can only go offshore with written regulator permission. Electronic medical records must be stored with a provider that has storage facilities inside Indonesia.High confidence
- What do I have to do to send it abroad?
- There is no published list of approved countries and no official standard contract to sign. Under the general law you assess the destination yourself, write down why it is safe enough, and keep that evidence. In finance the model is completely different: you need a real permission from the regulator before the systems move, and the banking regulator allows itself up to three months to answer once your paperwork is complete.Medium confidence
- Who enforces this — and are they actually working?
- It depends which rule you break. The privacy law's own watchdog is the weak spot: the law says a supervisory body must be set up by the President, and we found no government source showing it is staffed and issuing decisions as of 18 August 2026. Day to day the digital ministry handles complaints, registration and blocking. The financial regulators are a different story — the Financial Services Authority and the central bank are plainly working, and the Authority issued new binding rules as recently as July 2026.Medium confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling and they collide. The hardest floor is health: a hospital or clinic must keep an electronic medical record for at least 25 years after the patient's last visit. Company and tax paperwork must also be kept for years. The ceiling comes from the privacy law, which says personal data must be erased once the purpose is finished, the retention period ends, or the person withdraws consent. Where they clash, the specific keeping rule wins, so a patient asking for deletion does not defeat the 25-year rule.High confidence
- What happens when something goes wrong?
- Count at least three clocks, and the privacy one is not the fastest. Under the privacy law you have 72 hours to tell the affected people and the regulator about a personal data breach. If you are a bank, you must send the financial regulator a first alert within 24 hours of learning about a serious technology incident, and a full incident report within five working days. Other financial firms, such as insurers and lenders, have five working days. Miss the 24-hour one and the fact that you met the 72-hour one will not help you.High confidence
- What's the trap?
- Five things that ruin weekends. (1) In finance the wall is a permission, not a contract — moving systems abroad needs a regulator licence and the banking regulator gives itself up to three months to decide, so cloud migrations must be planned around that. (2) In health your cloud provider must have storage facilities in Indonesia, and the Ministry of Health can demand access to the whole medical record. (3) The 25-year medical record rule beats a patient's deletion request. (4) The privacy law carries prison sentences, not just fines, so directors are personally exposed. (5) A foreign company with no office still needs a named representative in Indonesia, and a consumer service that is not registered with the digital ministry can be blocked at the internet level.Medium confidence
- What's about to change?
- One dated change is certain: from 1 September 2026 trading in digital financial assets, including crypto, runs under the financial regulator's new rulebook, so anyone in that business should re-check where its servers and records must sit. Two things are still pending as far as we could verify: the detailed implementing regulation under the privacy law, and the presidential decision setting up the privacy watchdog itself. Both could land without warning.Medium confidence
- Hardest industry wall
- Banking — Peraturan Otoritas Jasa Keuangan Nomor 11/POJK.03/2022 tentang Penyelenggaraan Teknologi Informasi oleh Bank Umum
- Payments — Peraturan Bank Indonesia Nomor 23/6/PBI/2021 tentang Penyedia Jasa Pembayaran
- Insurance — Peraturan Otoritas Jasa Keuangan Nomor 4/POJK.05/2021 tentang Penerapan Manajemen Risiko dalam Penggunaan Teknologi Informasi oleh Lembaga Jasa Keuangan Nonbank
- Health and social care — Peraturan Menteri Kesehatan Nomor 24 Tahun 2022 tentang Rekam Medis
- Government — Peraturan Pemerintah Nomor 71 Tahun 2019 tentang Penyelenggaraan Sistem dan Transaksi Elektronik
- Mapping and location — Undang-Undang Nomor 4 Tahun 2011 tentang Informasi Geospasial