Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
PolandChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Poland is a European Union country, so data may leave as long as you use one of the approved European transfer routes. We found no general Polish rule forcing data to stay in the country. The privacy regulator is fully staffed and busy, and it fines government bodies as well as companies. Finance is the sector to watch: the financial supervisor wants cloud data kept in Europe.
- The catch
- True in general, much weaker in finance. Banks, insurers, brokers and payment firms follow a supervisory notice telling them to keep cloud data in European data centres, to put critical firms' data inside Poland first where they can, and to warn the financial supervisor 14 days before any cloud project starts. That notice is a strong recommendation, not a ban — but the supervisor checks it. Classified government information sits outside all of this and is effectively locked inside Poland.
- Does this apply to me?
- Yes, it reaches you with no office in Poland. European privacy law applies to any organisation anywhere that offers goods or services to people in Poland, or that monitors their behaviour. There is no size or revenue threshold. An organisation based outside Europe normally has to name a representative inside Europe. Poland then adds one local step that foreign groups routinely miss: if you must appoint a data protection officer, you have to tell the Polish regulator that person's name and contact details within 14 days of appointing them.High confidence
- Can the data leave the country?
- Yes, with paperwork. Poland has not added a general rule of its own that keeps data inside the country, and European law actually forbids member states from imposing storage-location rules on data that is not about people, except on public-security grounds. We searched for industry walls in banking, payments, insurance, securities, health, telecoms, government cloud, mapping and gambling. The only one we could confirm from an official Polish source is in finance, and it is a firm supervisory recommendation rather than an outright ban.Medium confidence
- What do I have to do to send it abroad?
- Think of it as an approved-routes list. Personal data may go outside Europe if the destination country has been officially approved, or if you sign the standard European contract with the recipient, or if your corporate group has rules approved by a regulator. The approved-country list is real and populated — roughly sixteen countries plus one international organisation. For the United States it only covers companies that have signed up to a specific certification scheme, so you have to check the recipient, not the country.High confidence
- Who enforces this — and are they actually working?
- The Personal Data Protection Office, and it is genuinely working. It is led by Mirosław Wróblewski, it publishes news several times a week, and its public decisions database held 581 decisions when we checked on 18 August 2026, with new ones published through June and July 2026. It fines public bodies too: it penalised the Minister of Justice in June 2026 and a local social welfare centre later the same month. Three other regulators matter — the financial supervisor for banks and insurers, the electronic communications office for telecoms and post, and the Ministry of Digital Affairs for cyber security.High confidence
- How long must I keep it, and when must I delete it?
- There is a ceiling and a floor. The ceiling is European: you may not keep personal data in a form that identifies someone for longer than you need it, and you have to be able to state that period. The floor is Polish: tax, accounting, employment and medical rules force you to keep certain records for years. When the two collide, the specific keeping duty wins for those records and everything else must still be deleted on time. We could not open the official Polish texts for the exact periods on the day we checked, so treat any specific number you read elsewhere as unverified until you see the statute.Medium confidence
- What happens when something goes wrong?
- Count at least two clocks, often three. For a personal data breach you have 72 hours to tell the Polish privacy regulator, and you must warn the people affected without undue delay if the risk to them is high. Separately, Poland rewrote its cyber security law and the new version started on 3 April 2026; if you are on the new register of key or important organisations you also report to the national cyber teams, on a much shorter first clock. Financial firms add a third set of reporting duties to the financial supervisor. The overlap is what breaks people, because the same incident triggers all three with different content and different deadlines.Medium confidence
- What's the trap?
- Five things that are not in the summary. First, appointing a data protection officer is not the end of it — you have 14 days to file that person's name and contact details with the Polish regulator, and foreign groups miss this constantly. Second, the list of Polish organisations that must appoint one is wider than expected and includes the central bank and state research institutes. Third, a brand-new Polish law on data management started in July 2026 and can fine you about two million złoty, roughly $550,000, for sending protected public-sector data to the wrong country. Fourth, the financial supervisor expects to be told 14 days before a cloud project starts and wants critical firms' data inside Poland where possible. Fifth, being a public body is no shield — the regulator fined the Minister of Justice in June 2026.High confidence
- What's about to change?
- Three dated things and one live risk. Poland's new cyber security register is being phased in through 2026: self-registration opened on 7 May 2026, and organisations the ministry enters itself get six months from being served notice to complete their details. On 12 January 2027 European rules ban cloud providers from charging you anything to move your data out. On 2 April 2027 a new European regulation on how privacy regulators run cross-border cases starts to apply, which will change how Polish complaints against foreign companies are handled. The live risk is the European Union–United States data transfer arrangement, which is valid today but being challenged.High confidence
- Hardest industry wall
- None found.
UkraineChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Ukraine still runs its 2010 privacy law, not a European-style one. Personal data may leave the country only to a country the law treats as safe — that means Europe and the 50-odd countries that signed a Council of Europe data treaty. The United States is not on that list. Fines are tiny, but the human rights Commissioner really does inspect, and misusing data can be a crime.
- The catch
- The general picture changes completely once government is involved. If a Ukrainian state body is the organisation deciding how personal data is used, only a Ukrainian state-owned or municipal company may process that data for it — a private or foreign supplier cannot. State systems, defence data and critical infrastructure also carry hard location rules, and several of the current permissions exist only because the country is under martial law.
- Does this apply to me?
- Probably not, if you have nothing in Ukraine. The 2010 law simply says it covers the processing of personal data by automated means or in structured paper files. It contains no clause reaching foreign companies that only sell into Ukraine from abroad, and it does not make you appoint a local representative. There is no size or revenue threshold either — a corner shop and a bank are treated the same.Medium confidence
- Can the data leave the country?
- Yes, but only to countries Ukraine already treats as safe. Those are the European Economic Area countries plus every country that has signed the Council of Europe's data protection treaty — roughly 55 states. The United States has signed neither, so routine transfers to American servers do not fit the safe-country route and need one of the narrow exceptions instead. Whole sectors then override this: government, defence and critical infrastructure are far tighter, and securities firms are unusually looser.High confidence
- What do I have to do to send it abroad?
- There is no form to file and no government permission to obtain. You either send the data to a country the law already treats as safe, or you rely on one of five narrow exceptions. Those are: the person's clear consent, necessity for a contract made for that person's benefit, protecting someone's life, an important public interest or a legal claim, and the sender giving guarantees that private and family life will not be interfered with. That last one is a catch-all that a lot of Ukrainian practice leans on.High confidence
- Who enforces this — and are they actually working?
- The Ukrainian Parliament Commissioner for Human Rights — the national ombudsman — is the data protection regulator, and it is genuinely working. It publishes a fresh inspection programme every three months; the one for July to September 2026 went up on 2 July 2026. It also publishes what it found, including a run of checks on the national electronic health system. The catch is the money: the regulator cannot fine anyone itself, it writes up a case and sends it to a court, and the maximum penalty is about $800.High confidence
- How long must I keep it, and when must I delete it?
- The floor comes from tax law. Companies must keep primary accounting documents and financial statements for 1,825 days — five years. Papers needed for transfer pricing checks run to 2,555 days, which is seven years. Everything else the tax authority may ask for runs 1,095 days, three years. The ceiling comes from the privacy law: you must delete personal data when the agreed storage period runs out, or when your relationship with the person ends, unless another law tells you to keep it.High confidence
- What happens when something goes wrong?
- This is the biggest surprise in Ukrainian law: if you lose personal data, there is no duty to tell the regulator and no duty to tell the people affected. The 2010 privacy law simply has no breach reporting clause. The only mandatory clocks sit in the cyber security regime, and they only bite if you run a state system or a piece of critical information infrastructure. Even there the law does not set the hours — it leaves the deadline to an order of the cyber agency.Medium confidence
- What's the trap?
- Five. (1) If a Ukrainian government body is the one deciding how personal data is used, only a Ukrainian state-owned or municipal company may handle that data for it — a private or foreign supplier is not allowed at all. (2) Misusing personal data is a crime, not just a fine, and repeat offences carry up to five years in prison. (3) The fines are aimed at named individuals and sole traders, not at companies. (4) Posting anything that shows where Ukrainian troops are carries five to eight years in prison. (5) Martial law lets the government limit the constitutional right to privacy that the whole system rests on.High confidence
- What's about to change?
- The date to watch is not a new law — it is the end of the war. Martial law was extended again on 13 July 2026 and now runs from 2 August 2026 for 90 days, so to about 31 October 2026. Several of today's permissions exist only while it lasts, and they die six months after it ends. A European-style replacement privacy law has been discussed for years and has still not been passed, so nothing about the current regime should be planned around its arrival.High confidence
- Hardest industry wall
- Government — Закон України "Про захист персональних даних", частина третя статті 4
- Government — Закон України "Про захист інформації в інформаційно-комунікаційних системах"
- Defence — Закон України "Про хмарні послуги"
- Mapping and location — Кримінальний кодекс України, стаття 114-2