Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
OmanChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Oman has a full privacy law, policed by a government ministry rather than by a separate privacy watchdog. Personal data may leave the country, but only with the person's clear permission, only if the destination protects the data at least as well as Oman does, and only after you have written a risk assessment. Data held for an Omani government body is different: it must stay inside Oman.
The catch
The permissive answer is true for ordinary commercial data. It is false for anything hosted on behalf of an Omani government body, where every copy including backups must sit inside Oman. It is unverified for banks, insurers and investment firms: the Central Bank and the Financial Services Authority websites could not be reached during this research, so their rules are recorded as unknown, not as absent.
Does this apply to me?
The law does not say. It states only that it applies to personal data that is processed. There is no sentence about companies based abroad, no revenue or headcount threshold to fall below, and no requirement to appoint a local representative. If you have people, a branch or servers in Oman you are plainly covered. If you sell to Omanis purely from abroad, the position is genuinely unsettled, and no official guidance answering the question was found.Medium confidence
Can the data leave the country?
Yes, data can leave Oman, and no country is banned. But four things must be true before it goes. The person must have given clear, specific permission. The transfer must not damage national security or the higher interests of the state. The organisation receiving the data must protect it at least as well as Oman's own rules do. And you must have written a risk assessment of the transfer, which the ministry can demand a copy of at any time.Medium confidence
What do I have to do to send it abroad?
There is no list of approved countries and no list of banned ones, and no government form to file for an ordinary transfer. Oman puts the work on you: get clear permission from the person, satisfy yourself that the recipient protects the data as well as Oman does, and keep a written assessment on file. The exception is sensitive data such as health or biometric records, which you cannot process at all until the ministry grants you a permit, and the permit application has to name where the data will be stored or sent.Medium confidence
Who enforces this — and are they actually working?
There is no separate privacy watchdog. The regulator is the Ministry of Transport, Communications and Information Technology, working through an in-house personal data protection department. It exists and it is doing things: it issued the detailed rules in 2024, it publishes an address for breach reports and complaints, and it put out a compliance self-check tool for companies in 2025. What we could not find is a single published decision, fine or enforcement report, even though the law tells the ministry to publish reports on its work. So the machinery is switched on, but its teeth have not been seen in public.Medium confidence
How long must I keep it, and when must I delete it?
Oman sets a firm floor and a soft ceiling. The floor: tax records, books and the documents behind them must be kept for at least ten years after the accounting period ends. The ceiling: there is no fixed maximum, but you must decide a retention period for every purpose, write down why, keep it proportionate, and delete when a person asks unless you have a legal reason to refuse. Where the two collide, the keeping duty wins, because complying with a legal obligation is one of the situations the privacy law does not cover.Medium confidence
What happens when something goes wrong?
Two clocks, both seventy-two hours, and they start at different moments for different audiences. Tell the ministry's data protection department within seventy-two hours of learning about a breach if it could put people's rights at risk. Tell the affected people themselves within seventy-two hours of learning about it if the breach could cause them serious harm or high risk. The ministry can also order you to notify people when you had decided not to. Failing to report is a criminal offence, not just a paperwork slip.Medium confidence
What's the trap?
Five things that are not in the summary. One: you need a government permit before you touch health, genetic, biometric, ethnic, sex life, political or religious, or criminal record data, and the ministry has forty-five days to answer, with silence counting as a no. Two: the fine for sending data abroad unlawfully runs from one hundred thousand to five hundred thousand Omani rials, about two hundred and sixty thousand to one and a third million United States dollars, which is a court fine, far above the two thousand rial administrative cap people quote. Three: the ministry can order you to hire an external auditor that it has licensed, and a copy of the audit report goes to the ministry. Four: there is no legitimate interest basis, so consent has to carry almost everything, in writing, and again separately before any marketing message. Five: the law's exemption list is enormous and includes performing a contract with the person, so both sides of an argument can point at it.Medium confidence
What's about to change?
Nothing new is scheduled to hit private companies in the next twelve months that we could find. The recent movement has all been in cyber and government rules: a brand new technology crimes law took effect on 2 June 2026, and a fresh cloud policy for government bodies landed on 28 June 2026. The bigger risk is not a bill but a switch already in the minister's hand: the ministry can order transfers to any country or international organisation to stop, and can suspend or cancel a processing permit, with no consultation and no notice period.Medium confidence
Hardest industry wall
  • Government Cloud and Hosting Services Standard
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
The catch
The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
Does this apply to me?
Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
Can the data leave the country?
Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
What do I have to do to send it abroad?
The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
Who enforces this — and are they actually working?
The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
What happens when something goes wrong?
There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
What's the trap?
Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
What's about to change?
Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
Hardest industry wall
  • Telecoms Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
  • E-commerce Loi n° 18-05 relative au commerce electronique
  • Government Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees