Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
NepalChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Dormant
- In one paragraph
- Nepal's privacy law says nothing about sending data abroad, so on paper data can leave freely. There is no privacy regulator at all: breaches are criminal matters taken to a local court, the maximum fine is about 215 US dollars, and no case has produced a public penalty. The real constraint is a 2025 rule on data centres and cloud services, which says customers may only buy hosting from providers on a government list.
- The catch
- The relaxed headline stops being true the moment you look at where the data physically sits. Since January 2025 anyone buying data centre or cloud services in Nepal is supposed to use only providers listed by the Department of Information Technology, and to get listed a provider must be a Nepal-registered company with a physical building in Nepal. Government security agencies must use the state's own data centre, other government bodies are being moved into it, and card payments made in Nepali rupees must be settled inside Nepal.
- Does this apply to me?
- It is unclear, and that is the honest answer. The Privacy Act covers public bodies and companies handling people's information, but it never says whether it reaches a company sitting outside Nepal, and it does not ask you to appoint anyone locally. Two other laws clearly do reach you from abroad: the computer-crime law applies to acts done outside Nepal that involve a computer located in Nepal, and the central bank's payment licensing policy expressly covers firms set up abroad that carry out payment business inside Nepal. There is no revenue or company-size threshold to fall below.Medium confidence
- Can the data leave the country?
- Under the privacy law, yes — it is silent on sending personal data out of Nepal, so there is nothing to comply with. But the country still has walls, and they are about where the machines are rather than where the data goes. Since January 2025 anyone buying data centre or cloud services is meant to use only providers on the government's published list, and listing requires a Nepal-registered company with a building in Nepal. Government security agencies must use the state's own data centre, and card payments made in Nepali rupees must be settled inside Nepal.Medium confidence
- What do I have to do to send it abroad?
- Nothing. There is no approval to get, no standard contract to sign and no list of approved countries, because Nepal's privacy law simply does not deal with sending data abroad. The control that does exist works the other way round: it is an approved-supplier list for hosting. The Department of Information Technology lists data centre and cloud providers, and customers are told to use only listed ones.Medium confidence
- Who enforces this — and are they actually working?
- For personal data, nobody. Nepal has no privacy regulator and no data protection authority. A person whose privacy is breached files a criminal complaint in their local district court within three months, and the court can also award compensation. The bodies that are genuinely active work on cyber security and on industry rules, not on privacy: the National Cyber Security Center published advisories as recently as April 2026, the telecoms authority collects security audit reports, the central bank issues payment directives, and the Department of Information Technology is running the data centre listing scheme.Medium confidence
- How long must I keep it, and when must I delete it?
- There is a floor and almost no ceiling. Tax records must be kept for five years after the tax year ends. Telecom operators must keep security logs for at least six months and internet address-translation logs for at least three months. Data centres must keep camera footage for at least three months. Going the other way, the privacy law has no general delete-by date, so the only real deletion duty found is a telecom rule that says paper customer forms must be destroyed once they have been scanned.Medium confidence
- What happens when something goes wrong?
- There is no general duty to report a personal data breach in Nepal — not to a regulator, and not to the people affected. No rule found sets a deadline in hours. Two narrower duties do exist. A data centre or cloud provider that finds someone has got into its systems must tell the regulator and the National Cyber Security Center immediately, by the fastest means available. A telecom operator hit by a security incident must work with a standing task force at the telecoms authority.Medium confidence
- What's the trap?
- Five. First, privacy breaches are criminal, not administrative — the exposure is up to three years in prison for an individual, not a corporate fine. Second, a victim has only three months from the act to complain, so most claims die of old age. Third, your cloud vendor must be on the government's list, which makes this a supplier problem rather than a policy problem. Fourth, anyone under 18 needs a guardian's consent — there is no lower digital age. Fifth, the online-content offence in the electronic transactions law carries up to five years in prison for material judged contrary to public morality, and it is written vaguely enough to catch ordinary posts.High confidence
- What's about to change?
- No data protection law is on the way that we could find, and no bill for one is before parliament. What is moving is telecoms and broadcasting: the ministry published discussion papers for a new Telecommunications Bill and a National Mass Communication Bill on 5 August 2026. The telecoms authority is consulting on amending its 2020 cyber security rules, on a framework for streaming and messaging services, and on a rule to force the move to newer internet addressing.Medium confidence
- Hardest industry wall
- All industries — डाटा सेन्टर तथा क्लाउड सेवा (सञ्चालन तथा व्यवस्थापन) निर्देशिका, २०८१ (Data Center and Cloud Service (Operation and Management) Directives, 2081)
- Payments — भुक्तानी प्रणालीसम्बन्धी एकीकृत निर्देशन, २०८२ (Unified Directive on Payment Systems, 2082)
IndiaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Waking up
- In one paragraph
- India's general privacy law is unusually relaxed about sending data abroad — it bans transfers only to countries on a government blacklist, and that blacklist is currently empty. But specific industries have hard walls: payments data, insurance records and telecom network data must stay inside India. The main law is passed but most of it only becomes enforceable in May 2027, and the regulator has no members yet.
- The catch
- The permissive headline is true only until you touch payments, insurance, telecom infrastructure, government cloud, public-health records or detailed mapping data. In those six areas India is one of the strictest jurisdictions in the world.
- Does this apply to me?
- Yes, it reaches you even with no office in India. The law applies to any organisation anywhere in the world that processes Indians' data in connection with offering goods or services to people in India. There is no size or revenue threshold to fall below.High confidence
- Can the data leave the country?
- In general, yes — freely. India's approach is a blacklist: the government may name countries you cannot send data to, and as of today it has named none. Six industries are the exception and are covered below.High confidence
- What do I have to do to send it abroad?
- Nothing to sign, no government approval, no standard contract. Unlike Europe, India requires no paperwork to send personal data abroad under the general law — the only question is whether the destination is on the blacklist, and nothing is. Sector rules override this completely.High confidence
- Who enforces this — and are they actually working?
- On paper, the Data Protection Board of India. In practice, nobody yet — the Board legally exists but as of August 2026 has no chairperson and no members. The government advertised the five posts in May 2026 and re-advertised in June, and they were still vacant in August. Sector regulators, by contrast, are fully active: the central bank, the insurance and securities regulators, the telecom department and the national cyber agency all enforce today.High confidence
- How long must I keep it, and when must I delete it?
- There is both a floor and a ceiling. From May 2027 every organisation must keep processing logs for at least one year. Tax records run six years, company books eight, and security logs 180 days. In the other direction, large consumer platforms must delete a user's data three years after they last engaged — with 48 hours' warning to the user first.High confidence
- What happens when something goes wrong?
- Two clocks, and this trips up almost everyone. You have SIX HOURS to report a cyber incident to India's national cyber agency — one of the shortest deadlines in the world. Separately, from May 2027, you must tell the privacy regulator and affected individuals without delay, then file a detailed report within 72 hours.High confidence
- What's the trap?
- Four things that catch people out. (1) A child is anyone under 18 — there is no lower age of digital consent as there is in Europe, and targeted advertising to under-18s is banned outright. (2) A consent manager must be an Indian company with about $2.3m of net worth, so a foreign entity cannot be one. (3) If designated a 'significant' organisation you must have a data protection officer physically based in India who answers to the board. (4) The general law expressly preserves stricter sector rules, so its liberal transfer regime gives you nothing if you touch payments, insurance or telecom.High confidence
- What's about to change?
- Three dates matter. 13 November 2026: consent managers must register. 13 May 2027: the whole law becomes enforceable, and the government has publicly refused to extend it or exempt startups. At some point before then, the Board should get its members — at which point enforcement switches on.High confidence
- Hardest industry wall
- Payments — Storage of Payment System Data
- Telecoms — Telecommunications (Authorisation) Rules, 2026
- Insurance — IRDAI (Maintenance of Information by Regulated Entities and Sharing of Information by the Authority) Regulations, 2025
- Securities — Cybersecurity and Cyber Resilience Framework, control PR.DS.S2
- All industries — Directions under section 70B(6) of the Information Technology Act, 2000