Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
PeruChecked 19 August 2026
Yes, with paperworkWork: HighEnforcement: Active
In one paragraph
Peru lets personal data leave the country, but only on conditions. You may send it to a country the government has judged to protect data properly - and it has judged none. So everyone uses the fallback: sign the regulator's model contract, then file the transfer on a public register. No industry has to keep data inside Peru. The regulator is real, staffed and fining people.
The catch
The headline stays true in every sector, but three industries add a gate on top. Banks, insurers and pension funds need the financial regulator's permission before using an offshore data centre where local law would block that regulator's access. Online gambling operators must hand the trade ministry logins to their own servers and databases. Phone and internet companies must hold three years of call and location records and hand them to Peruvian police in real time.
Does this apply to me?
Yes. Peru's privacy rules reach a company with no office in Peru if it offers goods or services to people in Peru, or if it watches their behaviour online or builds profiles of them. There is no size or revenue threshold that lets you escape. If you are caught this way you must appoint a representative for Peru, who is the contact point for the regulator. That representative can sit outside Peru, but must be named either in your public privacy notice or in a filing to the regulator.High confidence
Can the data leave the country?
Yes, with conditions, and the same conditions apply to every industry. The rule is that you may only send personal data to a country that Peru has decided protects data properly. Peru has not yet decided that about any country, so almost every transfer runs on the backup route: give 'adequate guarantees', normally by signing the model contract the regulator published. Nothing has to physically stay in Peru - there is no localisation rule in banking, payments, insurance, securities, health, telecoms, government cloud, gambling or mapping that we could find.High confidence
What do I have to do to send it abroad?
The model is an allowlist, and the list is empty. Peru says you may only export to a country it has formally judged adequate, and we found no decision naming any country. So nearly everyone uses the escape hatch: sign the regulator's published model contract clauses, or an equivalent contract that imposes the same duties on the receiver. You do not need permission first. You do need to tell the regulator: every cross-border flow must be reported and entered on the National Registry of Personal Data Protection, and there is an online form for it. You can also ask the regulator for a formal opinion on your transfer, and it must answer within thirty days.Medium confidence
Who enforces this — and are they actually working?
The National Authority for the Protection of Personal Data, which sits inside the Ministry of Justice and Human Rights. It is genuinely operational, not a paper regulator. In 2025 it inspected 760 organisations, made 198 site visits, opened 136 penalty cases, issued 211 decisions and imposed about 11.3 million soles in fines, roughly 3.2 million dollars. It was still issuing decisions in May 2026. In finance and insurance the banking regulator enforces separately, and the cyber-incident regulator sits in the Prime Minister's Office.High confidence
How long must I keep it, and when must I delete it?
Peru is unusual because the privacy rules set both a floor and a hard ceiling. The floor: security and access logs must be kept at least two years, phone and internet records three years, tax and accounting records for as long as the tax can still be assessed - in practice five years or more - and patient records twenty years. The ceiling: a supplier processing data for you may keep it at most two years after the job ends, and keeping personal data forever is banned as a general rule. Where a specific law demands longer, the data goes back to the client and is kept only while that legal duty lasts.High confidence
What happens when something goes wrong?
Two clocks, both 48 hours, and they are not the same clock. First: if personal data is exposed in bulk, or sensitive data is involved, or a lot of people are affected, you must tell the privacy authority within 48 hours of finding out - and you still must tell it even if you fixed the problem yourself. Miss the 48 hours and you may still file, but you must explain and evidence the delay. Second: public bodies and digital service providers in finance, utilities, health, transport, internet access, education and other critical activities must tell the National Digital Security Centre within 48 hours of a critical-level incident. A single breach can trigger both.High confidence
What's the trap?
Five things that catch people out. One: you must register every collection of personal data with the national register, and separately register the fact that you send data abroad - a filing duty most foreign companies do not know exists. Two: a supplier may only hold your data for two years after the work ends, so long-tail archives at vendors are unlawful by default. Three: a child under fourteen needs a parent's consent, but a fourteen to seventeen year old can consent alone for digital services - the opposite of what most global consent flows assume. Four: an online gambling licensee must give the trade ministry the usernames and passwords to its own servers and databases. Five: mishandling personal data can be a crime, not just a fine.Medium confidence
What's about to change?
One firm date in the next twelve months. On 30 November 2026 medium-sized companies - those with yearly sales between roughly 9.4 and 12.7 million soles, about 2.7 to 3.6 million dollars - must have appointed a Personal Data Officer. Small companies follow in 2027 and the smallest in 2028. Separately, a bill amending the privacy law cleared a congressional committee in November 2025 but is not law and must not be treated as binding. Watch three switches the government can flip without warning.Medium confidence
Hardest industry wall
None found.
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
The catch
The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
Does this apply to me?
Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
Can the data leave the country?
Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
What do I have to do to send it abroad?
The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
Who enforces this — and are they actually working?
The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
What happens when something goes wrong?
There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
What's the trap?
Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
What's about to change?
Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
Hardest industry wall
  • Telecoms Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
  • E-commerce Loi n° 18-05 relative au commerce electronique
  • Government Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees