Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
PhilippinesChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
The Philippines does not force data to stay in the country. Its privacy law lets data go abroad with no permit and no approved-country list. Instead it makes you stay responsible for the data after it leaves, register your systems with the regulator, and name a privacy officer. Get it badly wrong and a person can go to prison. Banks and government bodies face extra conditions.
The catch
The open headline is true only for the general privacy law. Two areas change the answer. Banks and other firms supervised by the central bank may only send work offshore if the receiving country has confidentiality and privacy laws that do not clash with Philippine law, and the central bank can order the arrangement unwound. Government bodies and their contractors may only take sensitive personal data off site with written approval from the agency head, and never more than one thousand records at a time, which rules out bulk offshore processing of government files. Separately, bank deposit secrecy is a criminal matter, so putting deposit records in a foreign cloud is a criminal-law question, not a privacy one.
Does this apply to me?
Yes. The law reaches a company with no office in the Philippines. It applies if you process data about Philippine citizens or residents, if you use equipment in the country, or if you have enough of a link to the country such as carrying on business there. There is no revenue floor and no company-size floor that lets you out. There is no formal 'local representative' role, but in practice you must name a data protection officer and register with the regulator, and foreign companies must file apostilled corporate papers to do it.High confidence
Can the data leave the country?
In general, yes, and easily. The privacy law has no rule that keeps data in the country, no list of approved or banned destinations, and no permit to apply for. The regulator has said in writing that the law is not a barrier to sending data abroad. Two sectors change that answer. Banks and other firms the central bank supervises may only send work offshore if the destination country has confidentiality and privacy laws that do not clash with Philippine law. Government bodies and their contractors cannot take sensitive personal data off site in bulk at all.Medium confidence
What do I have to do to send it abroad?
Nothing has to be approved before data leaves. There is no destination list to check, either of banned or of blessed countries, so the list question does not arise. What you must have is a paper trail: you stay legally responsible for the data after it goes, your supplier may only move it on your written instructions, and you have to declare planned overseas transfers when you register with the regulator. The regulator published a model contract in 2024, but using it is optional and it will not review your contract.High confidence
Who enforces this — and are they actually working?
The National Privacy Commission enforces the privacy law, and it is genuinely working. It has a serving commissioner and two deputies, it publishes decisions and orders, and it ordered a face-scanning identity product to stop processing data in the Philippines in late 2025. It has a published fine schedule that scales with company income. The central bank supervises banks and payment firms and enforces its own technology and outsourcing rules. Rate the country as actively enforced, not dormant.High confidence
How long must I keep it, and when must I delete it?
The privacy law sets no fixed number of years. It says keep personal data only as long as you need it for the purpose, then destroy it safely and be able to show how. The hard minimum periods come from other rules. Banks and other financial firms must keep records for at least five years, and money-laundering records for five years after an account closes. If a money-laundering case is filed, you keep everything until the case is finished, with no end date.Medium confidence
What happens when something goes wrong?
There are at least two clocks and they are very different lengths. For personal data, you have seventy-two hours from the moment you know or reasonably believe a serious breach happened to tell the regulator and the affected people. If you are a bank or other firm supervised by the central bank, you have two hours from discovery to tell your supervisor about a major cyber incident, then a fuller report within twenty-four hours. Everyone covered by the privacy law also files a yearly summary of all incidents, due by the thirty-first of March.High confidence
What's the trap?
Five things catch people out. A child is anyone under eighteen, not thirteen or sixteen. Breaking the privacy law can put a named individual in prison, not just cost the company money. You have to register your processing systems with the regulator, and a foreign company has to file apostilled corporate papers to do it. Bank deposit secrecy is a separate criminal law that a data-processing contract does not fix. And government files cannot go off site in bulk at all.High confidence
What's about to change?
Nothing forces data to stay in the Philippines in the next twelve months, as far as we can see. The regulator is the busy one: it issued new guidance on data scraping in April 2026, changed how breaches are reported in May 2026, and was consulting in August 2026 on updated risk-assessment guidelines. A bill to strengthen the privacy law has been circulating in Congress for years and is still only a proposal. Treat the regulator's power to issue binding circulars as the switch that can flip fastest.Medium confidence
Hardest industry wall
None found.
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
The catch
The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
Does this apply to me?
Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
Can the data leave the country?
Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
What do I have to do to send it abroad?
The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
Who enforces this — and are they actually working?
The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
What happens when something goes wrong?
There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
What's the trap?
Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
What's about to change?
Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
Hardest industry wall
  • Telecoms Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
  • E-commerce Loi n° 18-05 relative au commerce electronique
  • Government Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees