Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
Saudi ArabiaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Saudi Arabia, but never for free. You need a purpose the law allows, a written safeguard such as the government's own standard contract, and a written risk assessment that asks whether the transfer could harm the Kingdom itself. Banks need the central bank's written permission before anything goes abroad. The privacy regulator is fully set up but publishes no fines.
- The catch
- The 'paperwork and you can send it' answer is true for an ordinary business. It is false for banks and finance companies, where the central bank must give written no-objection first and cloud is expected to sit inside the country. It is also unsettled for government bodies and critical national infrastructure: the old rule forcing them to host inside Saudi Arabia was deleted in 2024 and replaced by a duty to ask a government office for a decision, and that office has published no replacement rule.
- Does this apply to me?
- Yes. The law reaches a company anywhere in the world with no office in Saudi Arabia, as long as it handles the data of people living in the Kingdom. There is no size, revenue or headcount threshold to fall below. There is no general duty to appoint a local representative, but many organisations must register on the government's data platform and some must name a data protection officer.High confidence
- Can the data leave the country?
- Yes, with real paperwork. First the reason for sending it has to be on the government's short list of allowed purposes. Then you need a safeguard: the government's own standard contract, approved group-wide rules, or a certificate from a licensed body. Then you must write a risk assessment that includes whether the transfer could damage the Kingdom's vital interests. Two industries are much harder. Banks and finance companies must get the central bank's written no-objection before any data goes to an overseas supplier, and the central bank's rules say cloud services should sit inside Saudi Arabia unless it approves otherwise. For government bodies and critical national infrastructure the picture changed in 2024 and is now genuinely unclear.High confidence
- What do I have to do to send it abroad?
- The model is an approved-destination list, and the list is empty. The law says data may go to a country the regulator has judged good enough, but no such list has been published, so in practice nobody uses that route. Instead almost everyone relies on the escape hatches: sign the government's word-for-word standard contract, or get approved group-wide rules for a multinational, or send to a body holding a certificate from a licensed Saudi accreditation body. On top of that you must run a written risk assessment before the data moves.High confidence
- Who enforces this — and are they actually working?
- The Saudi Data and Artificial Intelligence Authority is the privacy regulator, and it is genuinely up and running. Its National Data Governance Platform is live and takes registrations, self-assessments, breach reports and complaints, and it has published the rulebook for the panels that hear violations and issue fines. What we could not find is a single published fine or named decision, so how hard it bites is still unknown. The financial regulator and the cybersecurity authority, by contrast, have supervised their sectors for years.Medium confidence
- How long must I keep it, and when must I delete it?
- Both directions apply, and the floor wins when they clash. The ceiling: you must destroy personal data without undue delay once the reason you collected it has gone, and also when someone asks, when they withdraw the only consent you relied on, or when you learn you processed it unlawfully. Destruction must reach backups too. The floor: your written record of processing activities must be kept for five years after the activity ends. If another law sets a keeping period, the law says keep the data until whichever is longer.High confidence
- What happens when something goes wrong?
- The main clock is 72 hours. If personal data is breached, lost or accessed unlawfully and that could harm the people involved, you must tell the privacy regulator within 72 hours of finding out, through the government's data platform — and you have to be registered on that platform before you can use the service. You must also tell the affected people without undue delay, in plain language. A second, separate clock runs for government bodies and critical national infrastructure, which owe cyber incident reports to the national cybersecurity authority under its own rules. Suppliers owe you notice without undue delay so you can meet your own deadline.High confidence
- What's the trap?
- Five things that are not in the summary. One: sending data abroad is not only about protecting the individual — you must also assess whether the transfer could harm the Kingdom's own vital interests, and there is a government guide telling you how. Two: the standard contract must be copied word for word, and changing it is itself a breach of the law, while the overseas recipient has to accept Saudi courts. Three: leaking or publishing sensitive data to hurt someone or to profit can put a person in prison for up to two years — this is a criminal charge, not a fine. Four: your supplier contract must go beyond a normal data processing agreement and say whether the supplier is subject to foreign laws and how that affects its compliance. Five: the widely quoted rule that all government and critical infrastructure data must be hosted inside Saudi Arabia was deleted in 2024, and quoting it today is wrong.High confidence
- What's about to change?
- Nothing is scheduled to commence on a fixed date in the next twelve months — the law and all its main regulations are already fully in force. The risk is the opposite kind: several switches the government already holds and can flip with no consultation. The biggest is the approved-country list, which the regulator is legally required to publish and has not; the day it appears, every transfer plan in the country needs rechecking. The second biggest is the missing localisation rule for government and critical infrastructure, which one office was handed in 2024 and has not yet written.Medium confidence
- Hardest industry wall
- None found.
IndiaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Waking up
- In one paragraph
- India's general privacy law is unusually relaxed about sending data abroad — it bans transfers only to countries on a government blacklist, and that blacklist is currently empty. But specific industries have hard walls: payments data, insurance records and telecom network data must stay inside India. The main law is passed but most of it only becomes enforceable in May 2027, and the regulator has no members yet.
- The catch
- The permissive headline is true only until you touch payments, insurance, telecom infrastructure, government cloud, public-health records or detailed mapping data. In those six areas India is one of the strictest jurisdictions in the world.
- Does this apply to me?
- Yes, it reaches you even with no office in India. The law applies to any organisation anywhere in the world that processes Indians' data in connection with offering goods or services to people in India. There is no size or revenue threshold to fall below.High confidence
- Can the data leave the country?
- In general, yes — freely. India's approach is a blacklist: the government may name countries you cannot send data to, and as of today it has named none. Six industries are the exception and are covered below.High confidence
- What do I have to do to send it abroad?
- Nothing to sign, no government approval, no standard contract. Unlike Europe, India requires no paperwork to send personal data abroad under the general law — the only question is whether the destination is on the blacklist, and nothing is. Sector rules override this completely.High confidence
- Who enforces this — and are they actually working?
- On paper, the Data Protection Board of India. In practice, nobody yet — the Board legally exists but as of August 2026 has no chairperson and no members. The government advertised the five posts in May 2026 and re-advertised in June, and they were still vacant in August. Sector regulators, by contrast, are fully active: the central bank, the insurance and securities regulators, the telecom department and the national cyber agency all enforce today.High confidence
- How long must I keep it, and when must I delete it?
- There is both a floor and a ceiling. From May 2027 every organisation must keep processing logs for at least one year. Tax records run six years, company books eight, and security logs 180 days. In the other direction, large consumer platforms must delete a user's data three years after they last engaged — with 48 hours' warning to the user first.High confidence
- What happens when something goes wrong?
- Two clocks, and this trips up almost everyone. You have SIX HOURS to report a cyber incident to India's national cyber agency — one of the shortest deadlines in the world. Separately, from May 2027, you must tell the privacy regulator and affected individuals without delay, then file a detailed report within 72 hours.High confidence
- What's the trap?
- Four things that catch people out. (1) A child is anyone under 18 — there is no lower age of digital consent as there is in Europe, and targeted advertising to under-18s is banned outright. (2) A consent manager must be an Indian company with about $2.3m of net worth, so a foreign entity cannot be one. (3) If designated a 'significant' organisation you must have a data protection officer physically based in India who answers to the board. (4) The general law expressly preserves stricter sector rules, so its liberal transfer regime gives you nothing if you touch payments, insurance or telecom.High confidence
- What's about to change?
- Three dates matter. 13 November 2026: consent managers must register. 13 May 2027: the whole law becomes enforceable, and the government has publicly refused to extend it or exempt startups. At some point before then, the Board should get its members — at which point enforcement switches on.High confidence
- Hardest industry wall
- Payments — Storage of Payment System Data
- Telecoms — Telecommunications (Authorisation) Rules, 2026
- Insurance — IRDAI (Maintenance of Information by Regulated Entities and Sharing of Information by the Authority) Regulations, 2025
- Securities — Cybersecurity and Cyber Resilience Framework, control PR.DS.S2
- All industries — Directions under section 70B(6) of the Information Technology Act, 2000