Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
RussiaChecked 18 August 2026
A copy must stayWork: Very highEnforcement: Active
- In one paragraph
- If you collect personal data from people in Russia, the database you collect it into must sit inside Russia. You may then send a copy abroad, but only after you tell the regulator first and only to a country on its approved list. The United States is not on that list. Breaking the storage rule costs up to 6 million roubles, about $75,000, and leaking data can now put a person in prison.
- The catch
- The 'copy may go abroad' part disappears in several industries. Payments, electronic money, biometrics, telecoms, internet messaging services, government systems and detailed mapping are hard walls: the data must stay in Russia and no copy may leave. Since 1 September 2025 any company running 'significant' critical infrastructure — which includes most banks, telecoms operators and large energy and health providers — must also run Russian-registered software on those systems.
- Does this apply to me?
- Yes. The law reaches a foreign company with no office in Russia. It applies whenever you process the personal data of Russian citizens under a contract with them, under any other agreement with them, or on the basis of their consent. There is no size or revenue threshold. Almost every organisation must also file a notice with the regulator before it starts processing, and file a second, separate notice before any data leaves the country.High confidence
- Can the data leave the country?
- A copy can leave, but the original must stay. When you collect personal data about Russian citizens, the database you record, store, update or retrieve it from has to be physically in Russia. Since 1 July 2025 the law says this as a flat ban on using databases outside Russia for those steps. After that, sending a copy abroad is a separate question with its own paperwork. Several industries are stricter still and allow no copy out at all.High confidence
- What do I have to do to send it abroad?
- Russia runs an approved-destinations list, so a transfer is banned unless the destination is on it. Before any data leaves you must send the regulator a separate written notice naming the countries, the data and the recipients, and you must first collect written assurances from the recipient about how it will protect the data. If the destination is on the approved list you may start as soon as the notice is sent. If it is not, you must wait, and in practice you will be refused. The United States is not on the list.High confidence
- Who enforces this — and are they actually working?
- Roskomnadzor, the federal communications and media supervisor, is the data protection regulator. It is a long-established federal service, fully staffed, and it is still issuing binding orders — its most recent inspection check-list order was published on the state legal portal in December 2025. It is not the only enforcer. The security service runs the national cyber-attack reporting system, the technical regulator FSTEC sets security requirements for government and critical systems, and the Bank of Russia supervises banks and payment firms.Medium confidence
- How long must I keep it, and when must I delete it?
- Both directions apply and they collide. Personal data must be destroyed within 30 days of the purpose being achieved, or within 30 days of consent being withdrawn, and within 10 working days if the processing was unlawful. Against that, staff records must be kept for 50 years, telecoms and messaging metadata for three years, and message content for up to six months. Where a statute sets a minimum, the minimum wins and you keep the data.High confidence
- What happens when something goes wrong?
- There are at least three clocks and they run at once. You have 24 hours to tell the data regulator that personal data has leaked, and 72 hours to give it the results of your internal investigation. Separately, if the leak came from a computer attack you must report it to the security service's national attack-detection system. Banks and payment firms report to the Bank of Russia as well. Missing the 24-hour notice is itself a fine of up to 3 million roubles, about $37,000.High confidence
- What's the trap?
- Five things catch people out. First, leaking data is now a crime, and doing it across a border carries up to eight years in prison. Second, repeat leaks are fined as a share of worldwide-style annual revenue, between 1 and 3 percent, with a floor of 20 million roubles, about $250,000. Third, staff files must be kept 50 years, which flatly conflicts with the 30-day deletion duty. Fourth, biometric data can only be handled by a Russian-controlled company using databases in Russia. Fifth, refusing to serve a customer because they will not give biometrics is itself a fine.High confidence
- What's about to change?
- One dated change is already fixed: from 1 September 2027, Moscow's public bodies move onto a single city technology platform, which will pull a large volume of citizen data into one place. Much more important are the switches the government already holds and can flip with no consultation. The approved-country list can be cut by a single regulator order. Any transfer can be banned outright on security or economic grounds. And the rules for foreign use of Russian mapping technology have been written into the law but never issued.High confidence
- Hardest industry wall
- All industries — Федеральный закон от 27.07.2006 № 152-ФЗ «О персональных данных», статья 18 часть 5
- All industries — Федеральный закон № 152-ФЗ, статья 21 часть 3.1 и статья 19 часть 12
- All industries — Уголовный кодекс Российской Федерации, статья 272.1
- Payments — Федеральный закон от 27.06.2011 № 161-ФЗ «О национальной платежной системе», статьи 12 и 16
- All industries — Федеральный закон от 29.12.2022 № 572-ФЗ об идентификации и аутентификации с использованием биометрических персональных данных
- Telecoms — Федеральный закон от 07.07.2003 № 126-ФЗ «О связи», статья 64; Федеральный закон от 27.07.2006 № 149-ФЗ, статья 10.1
- Government — Приказ ФСТЭК России от 11.04.2025 № 117; Указ Президента РФ от 30.03.2022 № 166; Указ Президента РФ от 01.05.2022 № 250; Федеральный закон от 07.04.2025 № 58-ФЗ
- Mapping and location — Федеральный закон от 30.12.2015 № 431-ФЗ «О геодезии, картографии и пространственных данных», статьи 23 и 24
- Health and social care — Федеральный закон от 21.11.2011 № 323-ФЗ «Об основах охраны здоровья граждан в Российской Федерации», статья 13
- Social media and online platforms — Федеральный закон от 01.07.2021 № 236-ФЗ «О деятельности иностранных лиц в информационно-телекоммуникационной сети «Интернет» на территории Российской Федерации»
HungaryChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Hungary has no general rule that data must stay in the country. It runs on the European rulebook: you may send data abroad if you have the right legal paperwork in place. Hungary used to force state registers to be processed on Hungarian soil, but that rule was scrapped in April 2024. The privacy regulator is real, staffed and issuing decisions, though its fines are small by European standards.
- The catch
- Two things break the easy answer. Since January 2025 a large slice of the economy — energy, transport, banking, health, water, digital infrastructure, waste, manufacturing and most of the public sector — may only use a shared cloud or process data outside Hungary after completing a formal data classification under the cybersecurity law. And an online casino serving Hungarian players must keep its game server inside the European Economic Area, full stop.
- Does this apply to me?
- Yes. A company with no office in Hungary is still caught if it offers goods or services to people in Hungary or watches their behaviour, because the European privacy rules reach outside Europe. There is no revenue or headcount threshold to hide under. If you have no establishment anywhere in Europe you must appoint a written representative inside Europe, and Hungary is a perfectly ordinary place to put one.High confidence
- Can the data leave the country?
- Yes, on the normal European terms — nothing in general Hungarian law says data must be stored in Hungary. This is a change worth noticing: the rule that state registers could only be processed on Hungarian soil was repealed with effect from 1 April 2024, and the law that replaced it has no territorial restriction at all. Two sectors override this. An online casino must keep its game server inside the European Economic Area. And any company or public body inside the scope of Hungary's cybersecurity law must finish a formal data classification before it uses a shared cloud service or processes data abroad.Medium confidence
- What do I have to do to send it abroad?
- You need a European transfer tool before the data leaves, and Hungary adds no extra permit, filing or fee on top. The model is an approved-list one: you may send data to a country the European Commission has declared safe, or you sign the standard European contract clauses and write down a risk assessment of the destination. There is no Hungarian government sign-off, and no Hungarian list of banned countries. For police, security and other work outside the European privacy rules, Hungary's own Info Act sets the conditions instead.High confidence
- Who enforces this — and are they actually working?
- The National Authority for Data Protection and Freedom of Information, known by its Hungarian initials NAIH, and it is genuinely working. It has published decisions right through to May 2026, released its report on 2025 activity on 30 March 2026, and issued public statements in July and August 2026. Its president is Dr Attila Peterfalvi. The catch is size, not activity: a typical fine is small — two million forint, roughly six thousand dollars, in an April 2025 data-security case.High confidence
- How long must I keep it, and when must I delete it?
- Hungary pushes hard in both directions. The floor is long: accounting records and vouchers must be kept for eight years, and health records for decades — the health data law works in periods of thirty years and more. The ceiling is the European rule that you delete personal data once the purpose is spent. When the two collide, the specific statutory keep-period wins, so a deletion request does not empty your ledgers or a hospital's files.Medium confidence
- What happens when something goes wrong?
- Count at least two clocks, and three if you are a bank. A personal data breach goes to the privacy regulator within 72 hours. A cyber incident at a company or public body covered by the cybersecurity law goes to the national incident response centre, and the European rules that Hungary is copying use a 24-hour first alert followed by a fuller report at 72 hours. Financial firms have a separate and faster set of deadlines under the European operational resilience rules.Medium confidence
- What's the trap?
- Five things that are not in the summary. One: mishandling personal data is a crime in Hungary, not just a fine — up to one year in prison, two years for sensitive data, three years for public officials. Two: the old rule forcing state data to stay in Hungary is dead, so quoting it makes you look out of date, while the new cybersecurity classification gate is very much alive and most checklists miss it. Three: several cybersecurity deadlines have already passed, so newly in-scope companies are late on day one. Four: an online casino's game server must sit in the European Economic Area. Five: Hungary's freedom-of-information regime can make your contract with a state body public.High confidence
- What's about to change?
- Three dated items. The Court of Justice will rule on Hungary's sovereignty protection law; the court's adviser said on 12 February 2026 that it breaks European law, and the judgment could land any time. From 12 January 2027 cloud providers across Europe, Hungary included, must charge nothing to move your data out. And Hungary's cybersecurity supervision moves from paperwork to inspections now that the first audit deadline of 30 June 2026 has passed.Medium confidence
- Hardest industry wall
- Online gaming — 1991. evi XXXIV. torveny a szerencsejatek szervezeserol es a vegrehajtasi rendeletei (online kaszinojatek engedelyezesi feltetelei)
- Government — 2021. evi XCI. torveny a nemzeti adatvagyonrol, 13. §