Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
PolandChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Poland is a European Union country, so data may leave as long as you use one of the approved European transfer routes. We found no general Polish rule forcing data to stay in the country. The privacy regulator is fully staffed and busy, and it fines government bodies as well as companies. Finance is the sector to watch: the financial supervisor wants cloud data kept in Europe.
- The catch
- True in general, much weaker in finance. Banks, insurers, brokers and payment firms follow a supervisory notice telling them to keep cloud data in European data centres, to put critical firms' data inside Poland first where they can, and to warn the financial supervisor 14 days before any cloud project starts. That notice is a strong recommendation, not a ban — but the supervisor checks it. Classified government information sits outside all of this and is effectively locked inside Poland.
- Does this apply to me?
- Yes, it reaches you with no office in Poland. European privacy law applies to any organisation anywhere that offers goods or services to people in Poland, or that monitors their behaviour. There is no size or revenue threshold. An organisation based outside Europe normally has to name a representative inside Europe. Poland then adds one local step that foreign groups routinely miss: if you must appoint a data protection officer, you have to tell the Polish regulator that person's name and contact details within 14 days of appointing them.High confidence
- Can the data leave the country?
- Yes, with paperwork. Poland has not added a general rule of its own that keeps data inside the country, and European law actually forbids member states from imposing storage-location rules on data that is not about people, except on public-security grounds. We searched for industry walls in banking, payments, insurance, securities, health, telecoms, government cloud, mapping and gambling. The only one we could confirm from an official Polish source is in finance, and it is a firm supervisory recommendation rather than an outright ban.Medium confidence
- What do I have to do to send it abroad?
- Think of it as an approved-routes list. Personal data may go outside Europe if the destination country has been officially approved, or if you sign the standard European contract with the recipient, or if your corporate group has rules approved by a regulator. The approved-country list is real and populated — roughly sixteen countries plus one international organisation. For the United States it only covers companies that have signed up to a specific certification scheme, so you have to check the recipient, not the country.High confidence
- Who enforces this — and are they actually working?
- The Personal Data Protection Office, and it is genuinely working. It is led by Mirosław Wróblewski, it publishes news several times a week, and its public decisions database held 581 decisions when we checked on 18 August 2026, with new ones published through June and July 2026. It fines public bodies too: it penalised the Minister of Justice in June 2026 and a local social welfare centre later the same month. Three other regulators matter — the financial supervisor for banks and insurers, the electronic communications office for telecoms and post, and the Ministry of Digital Affairs for cyber security.High confidence
- How long must I keep it, and when must I delete it?
- There is a ceiling and a floor. The ceiling is European: you may not keep personal data in a form that identifies someone for longer than you need it, and you have to be able to state that period. The floor is Polish: tax, accounting, employment and medical rules force you to keep certain records for years. When the two collide, the specific keeping duty wins for those records and everything else must still be deleted on time. We could not open the official Polish texts for the exact periods on the day we checked, so treat any specific number you read elsewhere as unverified until you see the statute.Medium confidence
- What happens when something goes wrong?
- Count at least two clocks, often three. For a personal data breach you have 72 hours to tell the Polish privacy regulator, and you must warn the people affected without undue delay if the risk to them is high. Separately, Poland rewrote its cyber security law and the new version started on 3 April 2026; if you are on the new register of key or important organisations you also report to the national cyber teams, on a much shorter first clock. Financial firms add a third set of reporting duties to the financial supervisor. The overlap is what breaks people, because the same incident triggers all three with different content and different deadlines.Medium confidence
- What's the trap?
- Five things that are not in the summary. First, appointing a data protection officer is not the end of it — you have 14 days to file that person's name and contact details with the Polish regulator, and foreign groups miss this constantly. Second, the list of Polish organisations that must appoint one is wider than expected and includes the central bank and state research institutes. Third, a brand-new Polish law on data management started in July 2026 and can fine you about two million złoty, roughly $550,000, for sending protected public-sector data to the wrong country. Fourth, the financial supervisor expects to be told 14 days before a cloud project starts and wants critical firms' data inside Poland where possible. Fifth, being a public body is no shield — the regulator fined the Minister of Justice in June 2026.High confidence
- What's about to change?
- Three dated things and one live risk. Poland's new cyber security register is being phased in through 2026: self-registration opened on 7 May 2026, and organisations the ministry enters itself get six months from being served notice to complete their details. On 12 January 2027 European rules ban cloud providers from charging you anything to move your data out. On 2 April 2027 a new European regulation on how privacy regulators run cross-border cases starts to apply, which will change how Polish complaints against foreign companies are handled. The live risk is the European Union–United States data transfer arrangement, which is valid today but being challenged.High confidence
- Hardest industry wall
- None found.
ChinaChecked 18 August 2026
Yes, with paperworkWork: Very highEnforcement: Active
- In one paragraph
- Data can leave China, but only through one of three official gates: a government security review, a government-written contract you file with the regulator, or a certificate from an approved body. Which gate you need depends on how many people's data you move, not on where you send it. Small exporters are exempt. Several industries are walled off entirely.
- The catch
- The 'paperwork, then it can go' answer is only true for ordinary companies. Payment firms, credit bureaus, hospitals, genetic labs, online map services, telecom and industrial operators, and anything the government labels critical national infrastructure must keep the data in China. In those areas a copy staying behind is not optional.
- Does this apply to me?
- Yes. China's privacy law reaches a company with no office and no staff in China if it offers goods or services to people in China, or analyses their behaviour. There is no revenue or headcount threshold that lets you out. If you are caught this way, you must set up a dedicated office in China or name a representative there, and give the regulator their details.High confidence
- Can the data leave the country?
- In general yes, once you clear the right gate — but the gate is set by volume, not by destination. China has no list of banned or approved countries. Below 100,000 people a year you can usually send data abroad with no filing at all. Above that you need a contract filed with the regulator or a certificate; above a million people, or if you hold data the state calls 'important', you need a full government security review. Then come the industry walls, which override all of this.High confidence
- What do I have to do to send it abroad?
- Three routes, and you do not get to pick freely — your volume picks for you. Route one is a government security review, run by the national internet regulator through your provincial office; an approval lasts three years and only covers the exact purpose, scope and method you declared. Route two is China's own standard contract, which you sign with the overseas recipient and file with the provincial regulator along with a risk assessment. Route three is a certificate from an accredited body, which since 1 March 2026 has a national standard behind it. You also need each person's separate, specific consent before their data goes abroad.High confidence
- Who enforces this — and are they actually working?
- The Cyberspace Administration of China leads, and it is fully staffed and busy. It runs a nationwide enforcement campaign every year, tests apps itself and publishes the names of the ones that fail, and puts out batches of worked enforcement cases. Police, the industry ministry and the market regulator enforce alongside it, and finance, health, mapping and securities regulators run their own rules. Fines are usually modest and paired with an order to fix things; the eye-watering penalties in the statute are rarely used.High confidence
- How long must I keep it, and when must I delete it?
- Both directions apply, and they pull against each other. The floor: network logs must be kept for at least six months, and accounting records have their own long minimum periods set by a national schedule. The ceiling: personal data may only be kept for the shortest time needed for the purpose you collected it for, and must be deleted once that purpose is met, the service ends, or consent is withdrawn. Where a law sets a minimum, that minimum wins over the delete duty — you keep the record and stop using it for anything else.High confidence
- What happens when something goes wrong?
- Three clocks, and they overlap. If you run critical national infrastructure you have ONE HOUR to report a serious incident to your supervising department and the police. Everyone else has four hours to tell the provincial internet office. On top of that, a network data incident that could harm national security or the public interest must be reported within 24 hours. You must also tell affected people immediately, by phone, text, message, email or public notice.High confidence
- What's the trap?
- Five things that ruin weekends. (1) Sending data abroad needs each person's separate, specific consent — a line buried in a global privacy notice will not do. (2) A child is anyone under 14, and their data is treated as sensitive, so you need a parent's consent and a separate set of processing rules. (3) You may not hand data stored in China to a foreign court, police force or regulator without Chinese government approval — this catches routine legal discovery and overseas audit requests. (4) You have to work out for yourself whether you hold 'important data' and report it, because the official catalogues are incomplete. (5) The widely repeated claim that all personal financial data must be stored in China does not appear where people think it does.High confidence
- What's about to change?
- The next twelve months are about size-based rules. A draft published on 7 August 2026 would create a heavy new tier for any company holding data on ten million people or more: store it in China, appoint a chief privacy officer, set up an outside supervision committee, publish an annual report and honour data portability requests within 30 working days. Comments closed on 7 September 2026 and it is not law yet. A companion draft going the other way would simplify life for small processors. Watch the dormant switches — several can flip with no consultation at all.High confidence
- Hardest industry wall
- All industries — 中华人民共和国网络安全法(2025年修正)
- Payments — 非银行支付机构监督管理条例
- Finance — 征信业务管理办法
- Banking — 中国人民银行业务领域数据安全管理办法
- Securities — 关于加强境内企业境外发行证券和上市相关保密和档案管理工作的规定
- Health and social care — 国家健康医疗大数据标准、安全和服务管理办法(试行)
- Mapping and location — 地图管理条例
- Telecoms — 工业和信息化领域数据安全管理办法(试行)