Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
RomaniaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Romania follows the European rulebook. For almost every business, data may leave the country and leave Europe, as long as you use one of the approved European transfer routes. Two areas break that pattern: online gambling companies must keep the master copy of player and betting records on servers physically in Romania, and public bodies are being moved onto a state-run cloud. The privacy regulator works and publishes decisions, but its fines are small.
- The catch
- The relaxed headline stops being true in two places. If you run online gambling for Romanian players, a 'safety server' and a 'mirror server' holding player identity, bets, winnings and money movements must sit on Romanian soil and hold that data for at least six years, and you also need a representative with a Romanian address. If you sell systems to Romanian public bodies, the state is consolidating them into its own government cloud run by state agencies inside the country. Separately, Romania has had no telecoms data retention law at all since its Constitutional Court struck the old one down in 2014, so historic call and location records you might expect to exist often do not.
- Does this apply to me?
- Yes. Romania has no separate test of its own. The European Union's General Data Protection Regulation decides who is caught, and it catches any company anywhere in the world that offers goods or services to people in Romania, or that monitors what they do here. There is no revenue floor and no headcount floor. If your business has no establishment anywhere in the European Union you must appoint a representative inside the Union, though that person does not have to be in Romania.High confidence
- Can the data leave the country?
- For nearly every business, yes. Romania has passed no law telling ordinary companies to keep data inside the country, and European Union law actually forbids member states from doing that for non-personal data except on national security grounds. The exception that bites hardest is online gambling: the authoritative copy of player and betting records must sit on servers in Romania. Public-sector systems are the other exception, because the state is moving them into its own cloud.High confidence
- What do I have to do to send it abroad?
- Use one of the European routes and Romania asks for nothing extra. There is no Romanian registration, no notification, and no permit for sending personal data abroad. The routes are: the destination country is on the European Commission's approved list, or you sign the European Union's standard contract clauses, or you have approved binding corporate rules, or you fall inside one of the narrow one-off exceptions. Anything you write yourself still needs the regulator's sign-off.High confidence
- Who enforces this — and are they actually working?
- The National Supervisory Authority for Personal Data Processing, and it genuinely works. It publishes sanction decisions most months, and it was still doing so in August 2026. It also takes the lead in cross-border cases handed to it by other European regulators. The catch is size: typical fines run from about 1,000 to 11,000 euros, roughly 1,200 to 13,000 dollars, so the deterrent is reputational more than financial. Cyber security, telecoms, banking, insurance and gambling each have their own separate regulator.High confidence
- How long must I keep it, and when must I delete it?
- Both directions apply, and they can pull against each other. The floor: accounting books and the paperwork behind them must be kept ten years, annual accounts ten years, and payroll registers fifty years. Online gambling records must sit on the Romanian safety server for at least six years. The ceiling: recordings and logs from monitoring staff at work must not be kept longer than thirty days.Medium confidence
- What happens when something goes wrong?
- There are up to four clocks and they do not line up. Every organisation has 72 hours to tell the privacy regulator about a personal data breach. Telecoms and internet providers have a second, faster duty under a separate law and a separate form. Companies classed as essential or important for cyber security must send a first alert within 24 hours, a fuller report within 72 hours, and a final report within a month. Banks, insurers and investment firms have their own financial-sector reporting on top.Medium confidence
- What's the trap?
- Five things that are not in the summary. One: recordings from monitoring staff at work must be deleted after thirty days. Two: if you use a person's national identification number and your reason is your own business interest, you are legally required to appoint a data protection officer, even if nothing else in European law would force one. Three: Romanian public bodies get a warning first and can only be fined about 45,000 dollars, so suing or complaining about a state body rarely produces a big result. Four: Romania has no telecoms data retention law, so old call records may simply not exist. Five: online gambling has a hard in-country server rule and a Romanian representative requirement.High confidence
- What's about to change?
- Three dated items. Financial firms have been exposed to Romanian penalties for the European digital resilience rules since 11 March 2026, with fines reaching 10 percent of yearly turnover. Cyber security enforcement is ramping up after registration and the two implementing orders of August 2025. And on 12 January 2027 a European rule makes cloud switching and data export fees zero, which will change every cloud contract you have.Medium confidence
- Hardest industry wall
- Online gaming — Hotararea Guvernului nr. 111/2016 - Norme metodologice de punere in aplicare a OUG nr. 77/2009 privind organizarea si exploatarea jocurilor de noroc
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
- The catch
- The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
- Does this apply to me?
- Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
- Can the data leave the country?
- Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
- What do I have to do to send it abroad?
- The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
- Who enforces this — and are they actually working?
- The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
- What happens when something goes wrong?
- There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
- What's the trap?
- Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
- What's about to change?
- Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
- Hardest industry wall
- Telecoms — Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
- E-commerce — Loi n° 18-05 relative au commerce electronique
- Government — Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees