Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
PolandChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Poland is a European Union country, so data may leave as long as you use one of the approved European transfer routes. We found no general Polish rule forcing data to stay in the country. The privacy regulator is fully staffed and busy, and it fines government bodies as well as companies. Finance is the sector to watch: the financial supervisor wants cloud data kept in Europe.
- The catch
- True in general, much weaker in finance. Banks, insurers, brokers and payment firms follow a supervisory notice telling them to keep cloud data in European data centres, to put critical firms' data inside Poland first where they can, and to warn the financial supervisor 14 days before any cloud project starts. That notice is a strong recommendation, not a ban — but the supervisor checks it. Classified government information sits outside all of this and is effectively locked inside Poland.
- Does this apply to me?
- Yes, it reaches you with no office in Poland. European privacy law applies to any organisation anywhere that offers goods or services to people in Poland, or that monitors their behaviour. There is no size or revenue threshold. An organisation based outside Europe normally has to name a representative inside Europe. Poland then adds one local step that foreign groups routinely miss: if you must appoint a data protection officer, you have to tell the Polish regulator that person's name and contact details within 14 days of appointing them.High confidence
- Can the data leave the country?
- Yes, with paperwork. Poland has not added a general rule of its own that keeps data inside the country, and European law actually forbids member states from imposing storage-location rules on data that is not about people, except on public-security grounds. We searched for industry walls in banking, payments, insurance, securities, health, telecoms, government cloud, mapping and gambling. The only one we could confirm from an official Polish source is in finance, and it is a firm supervisory recommendation rather than an outright ban.Medium confidence
- What do I have to do to send it abroad?
- Think of it as an approved-routes list. Personal data may go outside Europe if the destination country has been officially approved, or if you sign the standard European contract with the recipient, or if your corporate group has rules approved by a regulator. The approved-country list is real and populated — roughly sixteen countries plus one international organisation. For the United States it only covers companies that have signed up to a specific certification scheme, so you have to check the recipient, not the country.High confidence
- Who enforces this — and are they actually working?
- The Personal Data Protection Office, and it is genuinely working. It is led by Mirosław Wróblewski, it publishes news several times a week, and its public decisions database held 581 decisions when we checked on 18 August 2026, with new ones published through June and July 2026. It fines public bodies too: it penalised the Minister of Justice in June 2026 and a local social welfare centre later the same month. Three other regulators matter — the financial supervisor for banks and insurers, the electronic communications office for telecoms and post, and the Ministry of Digital Affairs for cyber security.High confidence
- How long must I keep it, and when must I delete it?
- There is a ceiling and a floor. The ceiling is European: you may not keep personal data in a form that identifies someone for longer than you need it, and you have to be able to state that period. The floor is Polish: tax, accounting, employment and medical rules force you to keep certain records for years. When the two collide, the specific keeping duty wins for those records and everything else must still be deleted on time. We could not open the official Polish texts for the exact periods on the day we checked, so treat any specific number you read elsewhere as unverified until you see the statute.Medium confidence
- What happens when something goes wrong?
- Count at least two clocks, often three. For a personal data breach you have 72 hours to tell the Polish privacy regulator, and you must warn the people affected without undue delay if the risk to them is high. Separately, Poland rewrote its cyber security law and the new version started on 3 April 2026; if you are on the new register of key or important organisations you also report to the national cyber teams, on a much shorter first clock. Financial firms add a third set of reporting duties to the financial supervisor. The overlap is what breaks people, because the same incident triggers all three with different content and different deadlines.Medium confidence
- What's the trap?
- Five things that are not in the summary. First, appointing a data protection officer is not the end of it — you have 14 days to file that person's name and contact details with the Polish regulator, and foreign groups miss this constantly. Second, the list of Polish organisations that must appoint one is wider than expected and includes the central bank and state research institutes. Third, a brand-new Polish law on data management started in July 2026 and can fine you about two million złoty, roughly $550,000, for sending protected public-sector data to the wrong country. Fourth, the financial supervisor expects to be told 14 days before a cloud project starts and wants critical firms' data inside Poland where possible. Fifth, being a public body is no shield — the regulator fined the Minister of Justice in June 2026.High confidence
- What's about to change?
- Three dated things and one live risk. Poland's new cyber security register is being phased in through 2026: self-registration opened on 7 May 2026, and organisations the ministry enters itself get six months from being served notice to complete their details. On 12 January 2027 European rules ban cloud providers from charging you anything to move your data out. On 2 April 2027 a new European regulation on how privacy regulators run cross-border cases starts to apply, which will change how Polish complaints against foreign companies are handled. The live risk is the European Union–United States data transfer arrangement, which is valid today but being challenged.High confidence
- Hardest industry wall
- None found.
IndiaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Waking up
- In one paragraph
- India's general privacy law is unusually relaxed about sending data abroad — it bans transfers only to countries on a government blacklist, and that blacklist is currently empty. But specific industries have hard walls: payments data, insurance records and telecom network data must stay inside India. The main law is passed but most of it only becomes enforceable in May 2027, and the regulator has no members yet.
- The catch
- The permissive headline is true only until you touch payments, insurance, telecom infrastructure, government cloud, public-health records or detailed mapping data. In those six areas India is one of the strictest jurisdictions in the world.
- Does this apply to me?
- Yes, it reaches you even with no office in India. The law applies to any organisation anywhere in the world that processes Indians' data in connection with offering goods or services to people in India. There is no size or revenue threshold to fall below.High confidence
- Can the data leave the country?
- In general, yes — freely. India's approach is a blacklist: the government may name countries you cannot send data to, and as of today it has named none. Six industries are the exception and are covered below.High confidence
- What do I have to do to send it abroad?
- Nothing to sign, no government approval, no standard contract. Unlike Europe, India requires no paperwork to send personal data abroad under the general law — the only question is whether the destination is on the blacklist, and nothing is. Sector rules override this completely.High confidence
- Who enforces this — and are they actually working?
- On paper, the Data Protection Board of India. In practice, nobody yet — the Board legally exists but as of August 2026 has no chairperson and no members. The government advertised the five posts in May 2026 and re-advertised in June, and they were still vacant in August. Sector regulators, by contrast, are fully active: the central bank, the insurance and securities regulators, the telecom department and the national cyber agency all enforce today.High confidence
- How long must I keep it, and when must I delete it?
- There is both a floor and a ceiling. From May 2027 every organisation must keep processing logs for at least one year. Tax records run six years, company books eight, and security logs 180 days. In the other direction, large consumer platforms must delete a user's data three years after they last engaged — with 48 hours' warning to the user first.High confidence
- What happens when something goes wrong?
- Two clocks, and this trips up almost everyone. You have SIX HOURS to report a cyber incident to India's national cyber agency — one of the shortest deadlines in the world. Separately, from May 2027, you must tell the privacy regulator and affected individuals without delay, then file a detailed report within 72 hours.High confidence
- What's the trap?
- Four things that catch people out. (1) A child is anyone under 18 — there is no lower age of digital consent as there is in Europe, and targeted advertising to under-18s is banned outright. (2) A consent manager must be an Indian company with about $2.3m of net worth, so a foreign entity cannot be one. (3) If designated a 'significant' organisation you must have a data protection officer physically based in India who answers to the board. (4) The general law expressly preserves stricter sector rules, so its liberal transfer regime gives you nothing if you touch payments, insurance or telecom.High confidence
- What's about to change?
- Three dates matter. 13 November 2026: consent managers must register. 13 May 2027: the whole law becomes enforceable, and the government has publicly refused to extend it or exempt startups. At some point before then, the Board should get its members — at which point enforcement switches on.High confidence
- Hardest industry wall
- Payments — Storage of Payment System Data
- Telecoms — Telecommunications (Authorisation) Rules, 2026
- Insurance — IRDAI (Maintenance of Information by Regulated Entities and Sharing of Information by the Authority) Regulations, 2025
- Securities — Cybersecurity and Cyber Resilience Framework, control PR.DS.S2
- All industries — Directions under section 70B(6) of the Information Technology Act, 2000