Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
RussiaChecked 18 August 2026
A copy must stayWork: Very highEnforcement: Active
- In one paragraph
- If you collect personal data from people in Russia, the database you collect it into must sit inside Russia. You may then send a copy abroad, but only after you tell the regulator first and only to a country on its approved list. The United States is not on that list. Breaking the storage rule costs up to 6 million roubles, about $75,000, and leaking data can now put a person in prison.
- The catch
- The 'copy may go abroad' part disappears in several industries. Payments, electronic money, biometrics, telecoms, internet messaging services, government systems and detailed mapping are hard walls: the data must stay in Russia and no copy may leave. Since 1 September 2025 any company running 'significant' critical infrastructure — which includes most banks, telecoms operators and large energy and health providers — must also run Russian-registered software on those systems.
- Does this apply to me?
- Yes. The law reaches a foreign company with no office in Russia. It applies whenever you process the personal data of Russian citizens under a contract with them, under any other agreement with them, or on the basis of their consent. There is no size or revenue threshold. Almost every organisation must also file a notice with the regulator before it starts processing, and file a second, separate notice before any data leaves the country.High confidence
- Can the data leave the country?
- A copy can leave, but the original must stay. When you collect personal data about Russian citizens, the database you record, store, update or retrieve it from has to be physically in Russia. Since 1 July 2025 the law says this as a flat ban on using databases outside Russia for those steps. After that, sending a copy abroad is a separate question with its own paperwork. Several industries are stricter still and allow no copy out at all.High confidence
- What do I have to do to send it abroad?
- Russia runs an approved-destinations list, so a transfer is banned unless the destination is on it. Before any data leaves you must send the regulator a separate written notice naming the countries, the data and the recipients, and you must first collect written assurances from the recipient about how it will protect the data. If the destination is on the approved list you may start as soon as the notice is sent. If it is not, you must wait, and in practice you will be refused. The United States is not on the list.High confidence
- Who enforces this — and are they actually working?
- Roskomnadzor, the federal communications and media supervisor, is the data protection regulator. It is a long-established federal service, fully staffed, and it is still issuing binding orders — its most recent inspection check-list order was published on the state legal portal in December 2025. It is not the only enforcer. The security service runs the national cyber-attack reporting system, the technical regulator FSTEC sets security requirements for government and critical systems, and the Bank of Russia supervises banks and payment firms.Medium confidence
- How long must I keep it, and when must I delete it?
- Both directions apply and they collide. Personal data must be destroyed within 30 days of the purpose being achieved, or within 30 days of consent being withdrawn, and within 10 working days if the processing was unlawful. Against that, staff records must be kept for 50 years, telecoms and messaging metadata for three years, and message content for up to six months. Where a statute sets a minimum, the minimum wins and you keep the data.High confidence
- What happens when something goes wrong?
- There are at least three clocks and they run at once. You have 24 hours to tell the data regulator that personal data has leaked, and 72 hours to give it the results of your internal investigation. Separately, if the leak came from a computer attack you must report it to the security service's national attack-detection system. Banks and payment firms report to the Bank of Russia as well. Missing the 24-hour notice is itself a fine of up to 3 million roubles, about $37,000.High confidence
- What's the trap?
- Five things catch people out. First, leaking data is now a crime, and doing it across a border carries up to eight years in prison. Second, repeat leaks are fined as a share of worldwide-style annual revenue, between 1 and 3 percent, with a floor of 20 million roubles, about $250,000. Third, staff files must be kept 50 years, which flatly conflicts with the 30-day deletion duty. Fourth, biometric data can only be handled by a Russian-controlled company using databases in Russia. Fifth, refusing to serve a customer because they will not give biometrics is itself a fine.High confidence
- What's about to change?
- One dated change is already fixed: from 1 September 2027, Moscow's public bodies move onto a single city technology platform, which will pull a large volume of citizen data into one place. Much more important are the switches the government already holds and can flip with no consultation. The approved-country list can be cut by a single regulator order. Any transfer can be banned outright on security or economic grounds. And the rules for foreign use of Russian mapping technology have been written into the law but never issued.High confidence
- Hardest industry wall
- All industries — Федеральный закон от 27.07.2006 № 152-ФЗ «О персональных данных», статья 18 часть 5
- All industries — Федеральный закон № 152-ФЗ, статья 21 часть 3.1 и статья 19 часть 12
- All industries — Уголовный кодекс Российской Федерации, статья 272.1
- Payments — Федеральный закон от 27.06.2011 № 161-ФЗ «О национальной платежной системе», статьи 12 и 16
- All industries — Федеральный закон от 29.12.2022 № 572-ФЗ об идентификации и аутентификации с использованием биометрических персональных данных
- Telecoms — Федеральный закон от 07.07.2003 № 126-ФЗ «О связи», статья 64; Федеральный закон от 27.07.2006 № 149-ФЗ, статья 10.1
- Government — Приказ ФСТЭК России от 11.04.2025 № 117; Указ Президента РФ от 30.03.2022 № 166; Указ Президента РФ от 01.05.2022 № 250; Федеральный закон от 07.04.2025 № 58-ФЗ
- Mapping and location — Федеральный закон от 30.12.2015 № 431-ФЗ «О геодезии, картографии и пространственных данных», статьи 23 и 24
- Health and social care — Федеральный закон от 21.11.2011 № 323-ФЗ «Об основах охраны здоровья граждан в Российской Федерации», статья 13
- Social media and online platforms — Федеральный закон от 01.07.2021 № 236-ФЗ «О деятельности иностранных лиц в информационно-телекоммуникационной сети «Интернет» на территории Российской Федерации»
SwedenChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- Sweden has no general law forcing data to stay in the country. Personal data leaves under the ordinary European rules. But four walls override that: gambling systems must sit in Sweden, telecoms records kept for the police may never leave the European Union, classified material needs a state-to-state deal, and accounting books stay in Sweden unless you tell the tax agency.
- The catch
- The relaxed headline stops being true the moment you touch online gambling, telecoms records held for law enforcement, security-sensitive activity, detailed maps and sea-depth data, a public authority's secret files, or a Swedish company's accounting books. In those six areas Sweden is far stricter than its reputation suggests, and two of them carry prison sentences rather than fines.
- Does this apply to me?
- Yes. Sweden applies the European privacy rules, so a company anywhere in the world is caught if it offers goods or services to people in Sweden or watches what they do. There is no size or revenue floor to duck under. Sweden's own top-up law adds Swedish-only duties on top, and those apply to anyone processing data under Swedish law, not just Swedish companies. If you are outside Europe and caught, you normally have to name a representative inside Europe.High confidence
- Can the data leave the country?
- In general, yes. Sweden has no law that says personal data must physically stay in Sweden, and European law actually bans Sweden from imposing storage rules on non-personal data except for national security reasons. The exceptions are what matter. Online gambling systems must be placed in Sweden. Telephone and internet records that operators keep for the police may not be stored outside the European Union. Security-classified material cannot go to a foreign body without a government-to-government agreement. And a Swedish company's accounting records must be kept in Sweden unless it tells the tax agency where they are instead.High confidence
- What do I have to do to send it abroad?
- Sweden adds nothing of its own here — it uses the European toolkit unchanged. The model is an allowlist of approved destinations, and that list is well populated: the United Kingdom, Switzerland, Japan, South Korea, Canada, Brazil and about a dozen others are approved. For everywhere else you sign the European Commission's standard contract, or use group-wide rules approved by a regulator, and you write down why you think the data will still be safe. United States transfers work only if the receiving company has signed up to the European Union–United States Data Privacy Framework, and that arrangement is under legal pressure.High confidence
- Who enforces this — and are they actually working?
- The main privacy regulator is the Swedish Authority for Privacy Protection, and it is fully staffed and working. It published supervisory decisions in May, June and July 2026, including a reprimand to a large security company over filming its own staff, and in June 2026 it was also made Sweden's market surveillance authority for the European artificial intelligence rules. Other regulators matter just as much in their own lanes: the financial supervisor, the telecoms and post authority, the gambling authority, the Security Service and the Armed Forces.High confidence
- How long must I keep it, and when must I delete it?
- Sweden has a hard floor and a soft ceiling, and they pull in opposite directions. You must keep company accounting records for seven years after the end of the year they relate to, and patient records for at least ten years after the last entry. Against that, European privacy law says you must delete personal data once you no longer need it. Sweden resolves the clash the same way most of Europe does: a specific legal duty to keep something beats the general duty to delete it, so you keep it, lock it down and use it for nothing else.High confidence
- What happens when something goes wrong?
- Count at least three clocks, and they do not agree. For a personal data breach you have 72 hours to tell the privacy regulator, and you must tell the affected people without undue delay if the risk to them is high. Since 15 January 2026, organisations in important sectors must send an early warning to their cybersecurity supervisor within 24 hours of noticing a significant incident, then a fuller report within 72 hours — but trust service providers get only 24 hours for the full report. Financial firms have a fourth clock under the European digital resilience rules. The 24-hour warning is the one that catches people out.High confidence
- What's the trap?
- Five things that are not in any summary. One: a child can consent from age 13 in Sweden, the youngest age Europe allows, so a global default of 16 is wrong here. Two: you may only use a person's Swedish identity number without their consent when it is clearly justified — a Swedish-only rule with no European equivalent. Three: anything you send to a Swedish public authority can become a public document that any member of the public, including a competitor or a journalist, can demand a copy of. Four: giving a supplier access to a public authority's secret files is allowed only for purely technical processing or storage, and only if it is not inappropriate in the circumstances — the ordinary supplier contract is not enough. Five: mapping and sea-depth data is criminal law, not paperwork — spreading it without a permit can mean up to a year in prison.High confidence
- What's about to change?
- Two dated items. On 1 January 2027 a new law on the resilience of critical operators is proposed to start, covering eleven sectors and adding another 24-hour incident report. Also on 12 January 2027, European rules make it illegal for cloud providers to charge you to move your data out. Watch the government's national cloud policy, adopted on 28 May 2026: today it is only advice with no penalties, but it is the obvious vehicle for a future rule that public bodies must use European providers.High confidence
- Hardest industry wall
- Telecoms — Förordning (2022:511) om elektronisk kommunikation, 9 kap. 4 §
- Online gaming — Spellagen (2018:1138), 16 kap. 2 §
- Defence — Säkerhetsskyddslagen (2018:585) och Säkerhetsskyddsförordningen (2021:955)