Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
RussiaChecked 18 August 2026
A copy must stayWork: Very highEnforcement: Active
In one paragraph
If you collect personal data from people in Russia, the database you collect it into must sit inside Russia. You may then send a copy abroad, but only after you tell the regulator first and only to a country on its approved list. The United States is not on that list. Breaking the storage rule costs up to 6 million roubles, about $75,000, and leaking data can now put a person in prison.
The catch
The 'copy may go abroad' part disappears in several industries. Payments, electronic money, biometrics, telecoms, internet messaging services, government systems and detailed mapping are hard walls: the data must stay in Russia and no copy may leave. Since 1 September 2025 any company running 'significant' critical infrastructure — which includes most banks, telecoms operators and large energy and health providers — must also run Russian-registered software on those systems.
Does this apply to me?
Yes. The law reaches a foreign company with no office in Russia. It applies whenever you process the personal data of Russian citizens under a contract with them, under any other agreement with them, or on the basis of their consent. There is no size or revenue threshold. Almost every organisation must also file a notice with the regulator before it starts processing, and file a second, separate notice before any data leaves the country.High confidence
Can the data leave the country?
A copy can leave, but the original must stay. When you collect personal data about Russian citizens, the database you record, store, update or retrieve it from has to be physically in Russia. Since 1 July 2025 the law says this as a flat ban on using databases outside Russia for those steps. After that, sending a copy abroad is a separate question with its own paperwork. Several industries are stricter still and allow no copy out at all.High confidence
What do I have to do to send it abroad?
Russia runs an approved-destinations list, so a transfer is banned unless the destination is on it. Before any data leaves you must send the regulator a separate written notice naming the countries, the data and the recipients, and you must first collect written assurances from the recipient about how it will protect the data. If the destination is on the approved list you may start as soon as the notice is sent. If it is not, you must wait, and in practice you will be refused. The United States is not on the list.High confidence
Who enforces this — and are they actually working?
Roskomnadzor, the federal communications and media supervisor, is the data protection regulator. It is a long-established federal service, fully staffed, and it is still issuing binding orders — its most recent inspection check-list order was published on the state legal portal in December 2025. It is not the only enforcer. The security service runs the national cyber-attack reporting system, the technical regulator FSTEC sets security requirements for government and critical systems, and the Bank of Russia supervises banks and payment firms.Medium confidence
How long must I keep it, and when must I delete it?
Both directions apply and they collide. Personal data must be destroyed within 30 days of the purpose being achieved, or within 30 days of consent being withdrawn, and within 10 working days if the processing was unlawful. Against that, staff records must be kept for 50 years, telecoms and messaging metadata for three years, and message content for up to six months. Where a statute sets a minimum, the minimum wins and you keep the data.High confidence
What happens when something goes wrong?
There are at least three clocks and they run at once. You have 24 hours to tell the data regulator that personal data has leaked, and 72 hours to give it the results of your internal investigation. Separately, if the leak came from a computer attack you must report it to the security service's national attack-detection system. Banks and payment firms report to the Bank of Russia as well. Missing the 24-hour notice is itself a fine of up to 3 million roubles, about $37,000.High confidence
What's the trap?
Five things catch people out. First, leaking data is now a crime, and doing it across a border carries up to eight years in prison. Second, repeat leaks are fined as a share of worldwide-style annual revenue, between 1 and 3 percent, with a floor of 20 million roubles, about $250,000. Third, staff files must be kept 50 years, which flatly conflicts with the 30-day deletion duty. Fourth, biometric data can only be handled by a Russian-controlled company using databases in Russia. Fifth, refusing to serve a customer because they will not give biometrics is itself a fine.High confidence
What's about to change?
One dated change is already fixed: from 1 September 2027, Moscow's public bodies move onto a single city technology platform, which will pull a large volume of citizen data into one place. Much more important are the switches the government already holds and can flip with no consultation. The approved-country list can be cut by a single regulator order. Any transfer can be banned outright on security or economic grounds. And the rules for foreign use of Russian mapping technology have been written into the law but never issued.High confidence
Hardest industry wall
  • All industries Федеральный закон от 27.07.2006 № 152-ФЗ «О персональных данных», статья 18 часть 5
  • All industries Федеральный закон № 152-ФЗ, статья 21 часть 3.1 и статья 19 часть 12
  • All industries Уголовный кодекс Российской Федерации, статья 272.1
  • Payments Федеральный закон от 27.06.2011 № 161-ФЗ «О национальной платежной системе», статьи 12 и 16
  • All industries Федеральный закон от 29.12.2022 № 572-ФЗ об идентификации и аутентификации с использованием биометрических персональных данных
  • Telecoms Федеральный закон от 07.07.2003 № 126-ФЗ «О связи», статья 64; Федеральный закон от 27.07.2006 № 149-ФЗ, статья 10.1
  • Government Приказ ФСТЭК России от 11.04.2025 № 117; Указ Президента РФ от 30.03.2022 № 166; Указ Президента РФ от 01.05.2022 № 250; Федеральный закон от 07.04.2025 № 58-ФЗ
  • Mapping and location Федеральный закон от 30.12.2015 № 431-ФЗ «О геодезии, картографии и пространственных данных», статьи 23 и 24
  • Health and social care Федеральный закон от 21.11.2011 № 323-ФЗ «Об основах охраны здоровья граждан в Российской Федерации», статья 13
  • Social media and online platforms Федеральный закон от 01.07.2021 № 236-ФЗ «О деятельности иностранных лиц в информационно-телекоммуникационной сети «Интернет» на территории Российской Федерации»
IcelandChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Iceland follows Europe's privacy rulebook, so personal data can leave the country once the right paperwork is in place. Two local rules surprise people: a company's accounting records must physically be kept in Iceland, and health record systems can only be hosted by a certified provider. The privacy regulator is small but genuinely busy, and it fines public bodies too.
The catch
The relaxed answer is true for personal data only. Iceland's bookkeeping law says a company's books, invoices and receipts must be kept in Iceland for seven years, and only lets you hold them abroad for up to six months — and breaking the bookkeeping law is a crime, not a fine from the privacy regulator. Health record hosting has its own certification wall. Separately, three European laws that people assume apply here — the Data Act, the cybersecurity law known as NIS2, and the Artificial Intelligence Act — have NOT yet been brought into Icelandic law, so the rights and deadlines they create do not exist in Iceland today.
Does this apply to me?
Yes, it reaches you with no office in Iceland. Iceland applies Europe's General Data Protection Regulation through the European Economic Area agreement, so the rules cover any organisation anywhere in the world that offers goods or services to people in Iceland, or that watches what they do. There is no size or revenue threshold to duck under. If your organisation has no establishment anywhere in Europe, you normally have to name a representative inside Europe who people and the regulator can contact.High confidence
Can the data leave the country?
For personal data, yes — it can leave once you have the right paperwork. Two Icelandic rules cut across that headline. First, your company's accounting books, invoices and receipts must be kept in Iceland for seven years; the law only lets you hold them abroad for up to six months. Second, a health record system can sit with an outside host only if that host holds a recognised security certificate and the normal rules for sending data out of Europe are met.Medium confidence
What do I have to do to send it abroad?
You use one of the standard European routes. Send the data to a country Europe has officially approved, or sign the European Commission's standard contract with the recipient, or use group-wide rules a regulator has approved. Narrow one-off exceptions exist, such as the person's explicit consent, but they are not for routine or bulk transfers. One Icelandic wrinkle catches people out: an approval of a foreign country only takes effect in Iceland once the Icelandic minister confirms it and publishes a notice in the official gazette.Medium confidence
Who enforces this — and are they actually working?
Persónuvernd, the Icelandic Data Protection Authority. It is genuinely operational, not a name on paper: it registered 2,124 new cases in 2025 and closed 2,232, it opens its own investigations without waiting for a complaint, and it fines public bodies as well as private companies. It is also small — about 17 staff and a budget of roughly 379 million krónur (about $2.8 million) — and it says in its own annual report that it cannot cover every task the law gives it.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and they point in opposite directions. The floor: accounting books, invoices and receipts must be kept for seven years — and kept in Iceland. The ceiling: under the European rules you must delete personal data once you no longer need it for the purpose you collected it for. When the two clash, the keeping duty wins; a person cannot force you to delete records the bookkeeping and tax law requires you to hold.High confidence
What happens when something goes wrong?
Count at least two clocks, and three if you are a financial firm. You have 72 hours to report a personal data breach to Persónuvernd, and you must tell the people affected without delay where the risk to them is high. Separately, operators of critical services — banks, hospitals, energy, water, transport and digital infrastructure — must alert Iceland's national cyber security team as soon as possible under a 2019 law, and serious breaches of that law can lead to prosecution. Financial firms have a further, tighter reporting duty to the Central Bank under the European operational resilience rules.Medium confidence
What's the trap?
Five things that are not in the summary. (1) A child in Iceland is anyone under 13 for online consent, not 16 as in much of Europe — so a design built for a 16-year-old threshold is wrong here. (2) Your accounting records must sit in Iceland, and bookkeeping offences are criminal: fines, and up to six years in prison for serious cases, investigated by the district prosecutor and the tax investigators, not by the privacy regulator. (3) Public bodies can be fined in Iceland — the law says so expressly, unlike several European countries. (4) Some processing needs a licence from Persónuvernd before you start, which is unusual under the European regime. (5) Three European laws you may assume apply here do not yet: the Data Act, the cybersecurity law known as NIS2, and the Artificial Intelligence Act have not been brought into the European Economic Area agreement.High confidence
What's about to change?
The main thing to watch is not an Icelandic bill but the queue of European laws waiting to be pulled into Icelandic law. The Data Act, the cybersecurity law known as NIS2 and the Artificial Intelligence Act are all still outside the European Economic Area agreement as of 18 August 2026, and each will land when a joint committee decides — with no Icelandic public consultation and often at short notice. The financial resilience regulation already landed this way on 1 July 2025, more than five months after it started applying in the European Union.High confidence
Hardest industry wall
  • All industries Lög um bókhald