Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
RussiaChecked 18 August 2026
A copy must stayWork: Very highEnforcement: Active
- In one paragraph
- If you collect personal data from people in Russia, the database you collect it into must sit inside Russia. You may then send a copy abroad, but only after you tell the regulator first and only to a country on its approved list. The United States is not on that list. Breaking the storage rule costs up to 6 million roubles, about $75,000, and leaking data can now put a person in prison.
- The catch
- The 'copy may go abroad' part disappears in several industries. Payments, electronic money, biometrics, telecoms, internet messaging services, government systems and detailed mapping are hard walls: the data must stay in Russia and no copy may leave. Since 1 September 2025 any company running 'significant' critical infrastructure — which includes most banks, telecoms operators and large energy and health providers — must also run Russian-registered software on those systems.
- Does this apply to me?
- Yes. The law reaches a foreign company with no office in Russia. It applies whenever you process the personal data of Russian citizens under a contract with them, under any other agreement with them, or on the basis of their consent. There is no size or revenue threshold. Almost every organisation must also file a notice with the regulator before it starts processing, and file a second, separate notice before any data leaves the country.High confidence
- Can the data leave the country?
- A copy can leave, but the original must stay. When you collect personal data about Russian citizens, the database you record, store, update or retrieve it from has to be physically in Russia. Since 1 July 2025 the law says this as a flat ban on using databases outside Russia for those steps. After that, sending a copy abroad is a separate question with its own paperwork. Several industries are stricter still and allow no copy out at all.High confidence
- What do I have to do to send it abroad?
- Russia runs an approved-destinations list, so a transfer is banned unless the destination is on it. Before any data leaves you must send the regulator a separate written notice naming the countries, the data and the recipients, and you must first collect written assurances from the recipient about how it will protect the data. If the destination is on the approved list you may start as soon as the notice is sent. If it is not, you must wait, and in practice you will be refused. The United States is not on the list.High confidence
- Who enforces this — and are they actually working?
- Roskomnadzor, the federal communications and media supervisor, is the data protection regulator. It is a long-established federal service, fully staffed, and it is still issuing binding orders — its most recent inspection check-list order was published on the state legal portal in December 2025. It is not the only enforcer. The security service runs the national cyber-attack reporting system, the technical regulator FSTEC sets security requirements for government and critical systems, and the Bank of Russia supervises banks and payment firms.Medium confidence
- How long must I keep it, and when must I delete it?
- Both directions apply and they collide. Personal data must be destroyed within 30 days of the purpose being achieved, or within 30 days of consent being withdrawn, and within 10 working days if the processing was unlawful. Against that, staff records must be kept for 50 years, telecoms and messaging metadata for three years, and message content for up to six months. Where a statute sets a minimum, the minimum wins and you keep the data.High confidence
- What happens when something goes wrong?
- There are at least three clocks and they run at once. You have 24 hours to tell the data regulator that personal data has leaked, and 72 hours to give it the results of your internal investigation. Separately, if the leak came from a computer attack you must report it to the security service's national attack-detection system. Banks and payment firms report to the Bank of Russia as well. Missing the 24-hour notice is itself a fine of up to 3 million roubles, about $37,000.High confidence
- What's the trap?
- Five things catch people out. First, leaking data is now a crime, and doing it across a border carries up to eight years in prison. Second, repeat leaks are fined as a share of worldwide-style annual revenue, between 1 and 3 percent, with a floor of 20 million roubles, about $250,000. Third, staff files must be kept 50 years, which flatly conflicts with the 30-day deletion duty. Fourth, biometric data can only be handled by a Russian-controlled company using databases in Russia. Fifth, refusing to serve a customer because they will not give biometrics is itself a fine.High confidence
- What's about to change?
- One dated change is already fixed: from 1 September 2027, Moscow's public bodies move onto a single city technology platform, which will pull a large volume of citizen data into one place. Much more important are the switches the government already holds and can flip with no consultation. The approved-country list can be cut by a single regulator order. Any transfer can be banned outright on security or economic grounds. And the rules for foreign use of Russian mapping technology have been written into the law but never issued.High confidence
- Hardest industry wall
- All industries — Федеральный закон от 27.07.2006 № 152-ФЗ «О персональных данных», статья 18 часть 5
- All industries — Федеральный закон № 152-ФЗ, статья 21 часть 3.1 и статья 19 часть 12
- All industries — Уголовный кодекс Российской Федерации, статья 272.1
- Payments — Федеральный закон от 27.06.2011 № 161-ФЗ «О национальной платежной системе», статьи 12 и 16
- All industries — Федеральный закон от 29.12.2022 № 572-ФЗ об идентификации и аутентификации с использованием биометрических персональных данных
- Telecoms — Федеральный закон от 07.07.2003 № 126-ФЗ «О связи», статья 64; Федеральный закон от 27.07.2006 № 149-ФЗ, статья 10.1
- Government — Приказ ФСТЭК России от 11.04.2025 № 117; Указ Президента РФ от 30.03.2022 № 166; Указ Президента РФ от 01.05.2022 № 250; Федеральный закон от 07.04.2025 № 58-ФЗ
- Mapping and location — Федеральный закон от 30.12.2015 № 431-ФЗ «О геодезии, картографии и пространственных данных», статьи 23 и 24
- Health and social care — Федеральный закон от 21.11.2011 № 323-ФЗ «Об основах охраны здоровья граждан в Российской Федерации», статья 13
- Social media and online platforms — Федеральный закон от 01.07.2021 № 236-ФЗ «О деятельности иностранных лиц в информационно-телекоммуникационной сети «Интернет» на территории Российской Федерации»
LithuaniaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- Lithuania has no general rule that data must stay in the country. Private companies follow the European rulebook: data can go abroad once the right paperwork is in place. The wall is in government. The data behind the state's most important computer systems must sit in Lithuanian state data centres — and a copy of the most critical state data must be kept abroad on purpose.
- The catch
- The easy answer stops being true the moment you sell computing to the Lithuanian state. State information resources are graded into four importance levels. The top two must be held in state data centres inside Lithuania. The bottom two may sit in a foreign or private data centre, but a copy must still be kept in a Lithuanian state data centre — and the government has only approved data centres in European Union, European Economic Area and NATO countries. Lithuania also runs a 'digital embassy': copies of the most critical state data are deliberately stored outside Lithuania so the state survives an invasion. Banking, payments, insurance, securities, telecoms and online gambling have no storage-location rule that we could find. Health records are not walled off by a location rule, but almost all of them flow into a state health system that lives inside that government wall.
- Does this apply to me?
- Yes. A company with no office in Lithuania is still caught if it offers goods or services to people in Lithuania, or watches what they do online. There is no size or revenue threshold to hide under — a two-person company is covered exactly like a bank. If you have no office anywhere in the European Union, you must appoint a representative inside the Union who can be contacted by regulators and by the public.High confidence
- Can the data leave the country?
- For an ordinary business, yes. Lithuania has not added a national storage-location rule on top of the European rules, so data can leave once you have the standard European paperwork. The exception is government. If a computer system counts as a state information resource, Lithuania grades it by importance, and the two top grades must be held in state data centres inside Lithuania. The two lower grades can sit abroad, but a copy must still be kept in a Lithuanian state data centre. Lithuania also forces the opposite move for its most critical state data: a copy must be kept outside the country, in what it calls a digital embassy.Medium confidence
- What do I have to do to send it abroad?
- Lithuania uses the European model: a destination is off-limits unless you have an approved route out. The easiest route is an approved-country list, which is populated and currently includes the United Kingdom, Switzerland, Japan, South Korea, Canada, Brazil and others, plus United States companies signed up to the European Union–United States Data Privacy Framework. If your destination is not on the list, the normal answer is a set of standard contract clauses published by the European Commission. Lithuania adds one local step: if you want to use your own custom contract wording instead of the standard clauses, you need written permission from the Lithuanian regulator first.High confidence
- Who enforces this — and are they actually working?
- The main regulator is the State Data Protection Inspectorate, and it is genuinely working. In 2025 it received 2,081 complaints, up 48 percent on the year before, ran 26 inspections and had 54 staff. By 31 July 2026 it had already published 122 decisions for the year. But the fines are small: it issued only five fines in the whole of 2025, the largest being 9,000 euros (about 9,800 US dollars). Lithuania also has a second, less well known data regulator for journalism, and a separate cyber regulator inside the defence ministry.High confidence
- How long must I keep it, and when must I delete it?
- Both directions apply and they pull against each other. The ceiling comes from Europe: you must delete personal data once you no longer need it for the purpose you collected it for. The floors come from Lithuanian sector rules and from retention tables issued by the Chief Archivist. Some floors are very long. Health records in the state e-health system are kept for the patient's whole life plus three years, then archived for 75 years. Online gambling systems must keep their logs for at least 90 days. When a floor and the ceiling clash, the floor wins for as long as it lasts, because keeping the data is then a legal duty.Medium confidence
- What happens when something goes wrong?
- Count at least two clocks, and they do not agree. If personal data is exposed, you have 72 hours to tell the State Data Protection Inspectorate. If you are covered by the Cybersecurity Law, a serious cyber incident must be reported to the National Cyber Security Centre within 24 hours — a full day earlier — with a fuller assessment at 72 hours and a final report within one month. Other incidents get 72 hours. Financial firms have a third clock under European digital resilience rules. Lithuanian organisations are visibly bad at the first clock: only 63 percent of breach reports in 2025 arrived on time.High confidence
- What's the trap?
- Five things that are not in the summary. Children can consent for themselves at 14 in Lithuania, not 16, so an age gate built for the European default is wrong here. You may never publish a Lithuanian personal identification number, and you may never use one for marketing. Complaining about a government body is worth less than you think, because fines on public institutions are capped at 30,000 or 60,000 euros. There are two data regulators, and journalism goes to the other one. And if you sell cloud services to the Lithuanian state, your data centre may simply be ineligible.High confidence
- What's about to change?
- Two dated changes matter in the next twelve months, and both are European. From 12 January 2027 every cloud provider must let customers move their data out for free — no exit fees at all. Around the same period, the technical security requirements of Lithuania's cyber law start biting for organisations registered in April 2025, roughly two years after registration. The bigger Lithuanian risk is not a new law at all: the government can change where state data must live by resolution, without going to parliament and without consulting anyone.Medium confidence
- Hardest industry wall
- Government — Lietuvos Respublikos valstybes informaciniu istekliu valdymo istatymas, 45 straipsnis
- Government — Lietuvos Respublikos valstybes informaciniu istekliu valdymo istatymas — vidutines ir mazos svarbos istekliai
- Government — Skaitmenine ambasada — Vyriausybes nutarimas ir Valstybes informaciniu istekliu valdymo istatymo pakeitimai