Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
PortugalChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- Portugal follows the normal European rule: personal data may leave once you have the right paperwork in place. Two Portuguese walls override that. Online betting data must sit inside Portugal for ten years. Tax and invoicing records must stay in Portugal or the rest of Europe unless the tax office gives you written permission first. The privacy regulator is busy but almost never fines.
- The catch
- The relaxed headline stops being true in two places. First, online gambling: the system that logs Portuguese players must be installed in Portugal, and ten years of betting data must be stored in Portugal. Second, tax paperwork: paper accounting archives must be kept at premises inside Portugal, and moving an electronic archive or your invoicing software outside Europe needs written permission from the Portuguese tax office, plus live access to the system from screens inside Portugal. Your invoicing software also has to be on the tax office's approved list.
- Does this apply to me?
- Yes. Europe's General Data Protection Regulation reaches any company that offers goods or services to people in Portugal, even with no office and no staff here. There is no revenue or headcount threshold to hide behind. If your company has no base anywhere in Europe you must appoint a representative inside Europe, though that person does not have to be in Portugal. Portugal's own version of the law tried to add its own rule about who is covered, and the regulator publicly refuses to apply that part.High confidence
- Can the data leave the country?
- In general yes, with paperwork, exactly as anywhere else in Europe. Storage outside Portugal but inside Europe is free. Two Portuguese industries break that pattern. Online gambling firms must install the system that registers Portuguese players inside Portugal and must store ten years of betting data inside Portugal. Every business in Portugal must keep its tax and invoicing records in Portugal or the rest of Europe unless the tax office approves a move further afield.High confidence
- What do I have to do to send it abroad?
- For personal data leaving Europe, Portugal uses the standard European toolkit: send it to an approved country, or sign the European Commission's standard contract, or use approved group-wide rules, and write down why the destination is safe. For tax and invoicing archives the extra step is Portuguese: you ask the tax office for permission before the archive or the billing software moves outside Europe. Portugal's regulator has already fined a public body for relying on the standard contract alone.High confidence
- Who enforces this — and are they actually working?
- The National Data Protection Commission enforces the privacy rules. It is real, staffed and working: in 2025 it opened 3,201 new files, took 262 final decisions and handled 472 reported data breaches. But it issued only two fines that year, worth 47,000 euro in total (about 51,000 United States dollars), down from 90 fines the year before, and its own annual report blames a shortage of staff. It also runs with five of its seven seats filled. Other regulators police the sector rules and are fully operational.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling and they pull in opposite directions. The floor: tax books, invoices and supporting documents must be kept for ten calendar years, and online betting data for ten years inside Portugal. The ceiling: Europe's rule says delete personal data once the purpose is spent, and the telecoms law says connection data must be erased or made anonymous as soon as it is no longer needed to carry the call or message. Where the two collide, the specific legal duty to keep a record wins for that record only.High confidence
- What happens when something goes wrong?
- Count at least two clocks, and three if you run critical infrastructure. Privacy breaches go to the National Data Protection Commission within 72 hours, and to affected people without undue delay when the risk to them is high. Telecoms providers have their own European duty to report within 24 hours. Under Portugal's new cybersecurity law, important and essential organisations warn the National Cybersecurity Centre early, then file a fuller report, on the pattern set by Europe's network security directive.Medium confidence
- What's the trap?
- Five things that cost people their weekend. A child can consent from 13 in Portugal, not 16. Every look at a patient's health record must be traceable and the patient must be told. Misusing or peeking at personal data is a crime here, not just a fine, and it attaches to the individual. Your invoicing software must be on the tax office's approved list, and moving it or the archive outside Europe needs permission first. And nine chunks of the Portuguese privacy statute are printed in the law but the regulator refuses to apply them.High confidence
- What's about to change?
- Three things land in the next year or so. Public bodies must sort their data and systems by importance under the sovereign cloud plan, with the sorting due by the middle of 2027. The new cybersecurity regime is being switched on, with registration and incident duties for many more organisations. And the privacy regulator is hiring, so the near-zero fine count of 2025 is unlikely to last. Separately, Europe's rule that cloud switching must be free of charge starts in January 2027.Medium confidence
- Hardest industry wall
- Online gaming — Regime Jurídico dos Jogos e Apostas Online, aprovado pelo Decreto-Lei n.º 66/2015, de 29 de abril
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
- The catch
- The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
- Does this apply to me?
- Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
- Can the data leave the country?
- Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
- What do I have to do to send it abroad?
- The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
- Who enforces this — and are they actually working?
- The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
- What happens when something goes wrong?
- There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
- What's the trap?
- Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
- What's about to change?
- Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
- Hardest industry wall
- Telecoms — Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
- E-commerce — Loi n° 18-05 relative au commerce electronique
- Government — Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees