Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
Saudi ArabiaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Data can leave Saudi Arabia, but never for free. You need a purpose the law allows, a written safeguard such as the government's own standard contract, and a written risk assessment that asks whether the transfer could harm the Kingdom itself. Banks need the central bank's written permission before anything goes abroad. The privacy regulator is fully set up but publishes no fines.
The catch
The 'paperwork and you can send it' answer is true for an ordinary business. It is false for banks and finance companies, where the central bank must give written no-objection first and cloud is expected to sit inside the country. It is also unsettled for government bodies and critical national infrastructure: the old rule forcing them to host inside Saudi Arabia was deleted in 2024 and replaced by a duty to ask a government office for a decision, and that office has published no replacement rule.
Does this apply to me?
Yes. The law reaches a company anywhere in the world with no office in Saudi Arabia, as long as it handles the data of people living in the Kingdom. There is no size, revenue or headcount threshold to fall below. There is no general duty to appoint a local representative, but many organisations must register on the government's data platform and some must name a data protection officer.High confidence
Can the data leave the country?
Yes, with real paperwork. First the reason for sending it has to be on the government's short list of allowed purposes. Then you need a safeguard: the government's own standard contract, approved group-wide rules, or a certificate from a licensed body. Then you must write a risk assessment that includes whether the transfer could damage the Kingdom's vital interests. Two industries are much harder. Banks and finance companies must get the central bank's written no-objection before any data goes to an overseas supplier, and the central bank's rules say cloud services should sit inside Saudi Arabia unless it approves otherwise. For government bodies and critical national infrastructure the picture changed in 2024 and is now genuinely unclear.High confidence
What do I have to do to send it abroad?
The model is an approved-destination list, and the list is empty. The law says data may go to a country the regulator has judged good enough, but no such list has been published, so in practice nobody uses that route. Instead almost everyone relies on the escape hatches: sign the government's word-for-word standard contract, or get approved group-wide rules for a multinational, or send to a body holding a certificate from a licensed Saudi accreditation body. On top of that you must run a written risk assessment before the data moves.High confidence
Who enforces this — and are they actually working?
The Saudi Data and Artificial Intelligence Authority is the privacy regulator, and it is genuinely up and running. Its National Data Governance Platform is live and takes registrations, self-assessments, breach reports and complaints, and it has published the rulebook for the panels that hear violations and issue fines. What we could not find is a single published fine or named decision, so how hard it bites is still unknown. The financial regulator and the cybersecurity authority, by contrast, have supervised their sectors for years.Medium confidence
How long must I keep it, and when must I delete it?
Both directions apply, and the floor wins when they clash. The ceiling: you must destroy personal data without undue delay once the reason you collected it has gone, and also when someone asks, when they withdraw the only consent you relied on, or when you learn you processed it unlawfully. Destruction must reach backups too. The floor: your written record of processing activities must be kept for five years after the activity ends. If another law sets a keeping period, the law says keep the data until whichever is longer.High confidence
What happens when something goes wrong?
The main clock is 72 hours. If personal data is breached, lost or accessed unlawfully and that could harm the people involved, you must tell the privacy regulator within 72 hours of finding out, through the government's data platform — and you have to be registered on that platform before you can use the service. You must also tell the affected people without undue delay, in plain language. A second, separate clock runs for government bodies and critical national infrastructure, which owe cyber incident reports to the national cybersecurity authority under its own rules. Suppliers owe you notice without undue delay so you can meet your own deadline.High confidence
What's the trap?
Five things that are not in the summary. One: sending data abroad is not only about protecting the individual — you must also assess whether the transfer could harm the Kingdom's own vital interests, and there is a government guide telling you how. Two: the standard contract must be copied word for word, and changing it is itself a breach of the law, while the overseas recipient has to accept Saudi courts. Three: leaking or publishing sensitive data to hurt someone or to profit can put a person in prison for up to two years — this is a criminal charge, not a fine. Four: your supplier contract must go beyond a normal data processing agreement and say whether the supplier is subject to foreign laws and how that affects its compliance. Five: the widely quoted rule that all government and critical infrastructure data must be hosted inside Saudi Arabia was deleted in 2024, and quoting it today is wrong.High confidence
What's about to change?
Nothing is scheduled to commence on a fixed date in the next twelve months — the law and all its main regulations are already fully in force. The risk is the opposite kind: several switches the government already holds and can flip with no consultation. The biggest is the approved-country list, which the regulator is legally required to publish and has not; the day it appears, every transfer plan in the country needs rechecking. The second biggest is the missing localisation rule for government and critical infrastructure, which one office was handed in 2024 and has not yet written.Medium confidence
Hardest industry wall
None found.
Hong Kong SARChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
In one paragraph
Hong Kong's privacy law contains a cross-border transfer ban that has never been switched on. It was written in 1995 and, thirty years later, still has no start date. So under the general law you can send personal data anywhere with no paperwork at all. The privacy regulator is busy and prosecutes people, but it cannot fine you directly.
The catch
The free-for-all stops at three doors. Licensed securities and futures firms need written permission from the markets regulator before their records live only on servers outside Hong Kong. Government departments are told not to put sensitive or personal information on public cloud at all. And data coming the other way, from mainland China into Hong Kong, is tightly controlled by mainland law, not by Hong Kong law - that is the wall most companies actually hit.
Does this apply to me?
Yes, it can reach you with no office in Hong Kong. The privacy law bites on whoever controls the collection, holding, use or processing of personal data in or from Hong Kong, so a foreign company running a Hong Kong-facing service is caught. There is no revenue or headcount threshold to fall below, no register to join, and no requirement to appoint a local representative. The anti-doxxing powers go further still: the regulator can order an overseas platform to take material down.High confidence
Can the data leave the country?
Under the general privacy law, yes - freely, with nothing to sign. The one section that would have restricted transfers abroad was written into the law in 1995 and has never been brought into operation, so today there is no legal control on personal data leaving Hong Kong. Industry rules are where the real limits sit, and there are fewer of them than people expect: the securities regulator is the main one, and government departments have their own restriction.High confidence
What do I have to do to send it abroad?
Nothing. There is no approval to seek, no standard contract to sign and no government list to check before personal data leaves Hong Kong. The model on paper is an allowlist - the regulator would publish a list of approved destinations - but because the section was never switched on, that list has never been issued and is empty. The regulator does publish a voluntary guide and encourages firms to build the safeguards now, but that is advice, not law.High confidence
Who enforces this — and are they actually working?
The Privacy Commissioner for Personal Data, and it is genuinely busy. By the end of December 2025 it had issued 2,104 orders to 57 online platforms to take down 33,743 doxxing messages, opened 519 criminal investigations and arrested 81 people. But there is a catch that changes the risk picture completely: the Commissioner cannot impose a fine for breaking the privacy principles. It serves a notice telling you to fix the problem, and only ignoring that notice is a crime.High confidence
How long must I keep it, and when must I delete it?
There is a hard ceiling and almost no floor in the privacy law itself. You must erase personal data once it is no longer needed for the purpose you collected it for, and failing to do so is a criminal offence carrying a fine of up to HK$10,000 (about $1,300). The privacy law sets no minimum keeping periods; those come from tax, company and anti-money-laundering law instead. Where the two pull against each other, the specific keeping duty in the other law wins, and you delete once it expires.Medium confidence
What happens when something goes wrong?
For a normal data breach there is no deadline, because there is no duty. Telling the Privacy Commissioner about a breach is voluntary in Hong Kong - the regulator asks you to do it as good practice and gives you a form, but no law compels it. That is unusual and it is changing: since 1 January 2026 operators of designated critical infrastructure must report computer-system security incidents, so those firms now have a real clock while everyone else has none.High confidence
What's the trap?
Five things that catch people out. First, marketing mistakes are crimes here, not fines - using someone's data for direct marketing without the right consent can mean five years in prison. Second, the regulator cannot fine you, so people assume the risk is low and miss the criminal exposure entirely. Third, Hong Kong sets no age at which a child can consent, so there is no simple number to code into a sign-up flow. Fourth, licensed securities firms need written permission before their records live only on overseas servers, and two named people who live in Hong Kong must be able to unlock them. Fifth, the dormant transfer section, if ever switched on, would also catch data moving between two foreign countries when a Hong Kong company controls it.Medium confidence
What's about to change?
Nothing is scheduled to land in the next twelve months that we could confirm. The critical infrastructure security law already started on 1 January 2026, and the government's guideline for generative artificial intelligence was revised in December 2025. The thing to watch is not a new bill. It is a switch the government has held for thirty years: the cross-border transfer section can be brought into force by a simple commencement notice, with no consultation and no new vote.Medium confidence
Hardest industry wall
None found.