Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
SwedenChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Sweden has no general law forcing data to stay in the country. Personal data leaves under the ordinary European rules. But four walls override that: gambling systems must sit in Sweden, telecoms records kept for the police may never leave the European Union, classified material needs a state-to-state deal, and accounting books stay in Sweden unless you tell the tax agency.
The catch
The relaxed headline stops being true the moment you touch online gambling, telecoms records held for law enforcement, security-sensitive activity, detailed maps and sea-depth data, a public authority's secret files, or a Swedish company's accounting books. In those six areas Sweden is far stricter than its reputation suggests, and two of them carry prison sentences rather than fines.
Does this apply to me?
Yes. Sweden applies the European privacy rules, so a company anywhere in the world is caught if it offers goods or services to people in Sweden or watches what they do. There is no size or revenue floor to duck under. Sweden's own top-up law adds Swedish-only duties on top, and those apply to anyone processing data under Swedish law, not just Swedish companies. If you are outside Europe and caught, you normally have to name a representative inside Europe.High confidence
Can the data leave the country?
In general, yes. Sweden has no law that says personal data must physically stay in Sweden, and European law actually bans Sweden from imposing storage rules on non-personal data except for national security reasons. The exceptions are what matter. Online gambling systems must be placed in Sweden. Telephone and internet records that operators keep for the police may not be stored outside the European Union. Security-classified material cannot go to a foreign body without a government-to-government agreement. And a Swedish company's accounting records must be kept in Sweden unless it tells the tax agency where they are instead.High confidence
What do I have to do to send it abroad?
Sweden adds nothing of its own here — it uses the European toolkit unchanged. The model is an allowlist of approved destinations, and that list is well populated: the United Kingdom, Switzerland, Japan, South Korea, Canada, Brazil and about a dozen others are approved. For everywhere else you sign the European Commission's standard contract, or use group-wide rules approved by a regulator, and you write down why you think the data will still be safe. United States transfers work only if the receiving company has signed up to the European Union–United States Data Privacy Framework, and that arrangement is under legal pressure.High confidence
Who enforces this — and are they actually working?
The main privacy regulator is the Swedish Authority for Privacy Protection, and it is fully staffed and working. It published supervisory decisions in May, June and July 2026, including a reprimand to a large security company over filming its own staff, and in June 2026 it was also made Sweden's market surveillance authority for the European artificial intelligence rules. Other regulators matter just as much in their own lanes: the financial supervisor, the telecoms and post authority, the gambling authority, the Security Service and the Armed Forces.High confidence
How long must I keep it, and when must I delete it?
Sweden has a hard floor and a soft ceiling, and they pull in opposite directions. You must keep company accounting records for seven years after the end of the year they relate to, and patient records for at least ten years after the last entry. Against that, European privacy law says you must delete personal data once you no longer need it. Sweden resolves the clash the same way most of Europe does: a specific legal duty to keep something beats the general duty to delete it, so you keep it, lock it down and use it for nothing else.High confidence
What happens when something goes wrong?
Count at least three clocks, and they do not agree. For a personal data breach you have 72 hours to tell the privacy regulator, and you must tell the affected people without undue delay if the risk to them is high. Since 15 January 2026, organisations in important sectors must send an early warning to their cybersecurity supervisor within 24 hours of noticing a significant incident, then a fuller report within 72 hours — but trust service providers get only 24 hours for the full report. Financial firms have a fourth clock under the European digital resilience rules. The 24-hour warning is the one that catches people out.High confidence
What's the trap?
Five things that are not in any summary. One: a child can consent from age 13 in Sweden, the youngest age Europe allows, so a global default of 16 is wrong here. Two: you may only use a person's Swedish identity number without their consent when it is clearly justified — a Swedish-only rule with no European equivalent. Three: anything you send to a Swedish public authority can become a public document that any member of the public, including a competitor or a journalist, can demand a copy of. Four: giving a supplier access to a public authority's secret files is allowed only for purely technical processing or storage, and only if it is not inappropriate in the circumstances — the ordinary supplier contract is not enough. Five: mapping and sea-depth data is criminal law, not paperwork — spreading it without a permit can mean up to a year in prison.High confidence
What's about to change?
Two dated items. On 1 January 2027 a new law on the resilience of critical operators is proposed to start, covering eleven sectors and adding another 24-hour incident report. Also on 12 January 2027, European rules make it illegal for cloud providers to charge you to move your data out. Watch the government's national cloud policy, adopted on 28 May 2026: today it is only advice with no penalties, but it is the obvious vehicle for a future rule that public bodies must use European providers.High confidence
Hardest industry wall
  • Telecoms Förordning (2022:511) om elektronisk kommunikation, 9 kap. 4 §
  • Online gaming Spellagen (2018:1138), 16 kap. 2 §
  • Defence Säkerhetsskyddslagen (2018:585) och Säkerhetsskyddsförordningen (2021:955)
IrelandChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
In one paragraph
Ireland follows Europe's rules, so personal data can leave the country once you have the right paperwork in place. But a handful of Irish laws force certain records to be kept physically in Ireland, and breaking those is a crime rather than a fine. Ireland's privacy regulator is one of the toughest in Europe: in 2025 it fined TikTok 530 million euro and ordered it to stop sending data to China.
The catch
The relaxed headline stops being true in four places. Trust and company service providers, and cheque-cashing firms, must keep their anti-money-laundering records at premises inside Ireland for six years, and failing to do so is a criminal offence carrying up to five years in prison. Every Irish company must keep accounting information and returns at a place in Ireland even when the books themselves sit on a foreign server. Health records and telephone and internet connection records each have their own separate rules on top.
Does this apply to me?
Yes. Ireland's data protection law reaches a company with no office in Ireland whenever it offers goods or services to people in Europe or watches what they do online. There is no revenue or headcount threshold to duck under. A company based outside Europe normally has to name a representative inside Europe who regulators and members of the public can write to.High confidence
Can the data leave the country?
In general, yes, with paperwork. Ireland does not have a general rule saying personal data must stay in the country. Sending it outside Europe is allowed once you use one of the approved legal routes. But several Irish laws quietly demand that particular records sit on Irish soil, and those override the friendly headline.High confidence
What do I have to do to send it abroad?
Ireland uses the European model. A destination outside Europe is off limits unless it is on the European Commission's approved list, or you put an approved safeguard in place first. The approved list is real and populated: it currently covers seventeen destinations, including the United Kingdom, Japan, South Korea, Switzerland and Brazil. The United States counts only for companies that have signed up to the European Union to United States Data Privacy Framework.High confidence
Who enforces this — and are they actually working?
The Data Protection Commission, and it is very much awake. It has three commissioners in post — Des Hogan as chairperson, Dale Sunderland and Niamh Sweeney — and it published its 2025 annual report on 30 June 2026. In 2025 it finished four large inquiries and imposed fines of just over 530 million euro (about 580 million US dollars), almost all of it on TikTok, which it also ordered to stop sending European user data to China.High confidence
How long must I keep it, and when must I delete it?
Both directions apply, and Ireland's floors are longer than most people expect. Anti-money-laundering customer records must be kept for at least five years. Company accounting records and returns must be kept for at least six years. Trust and company service providers and cheque-cashing firms must keep their records for six years and keep them in Ireland. Telephone and internet providers must keep subscriber details for one year.High confidence
What happens when something goes wrong?
Count three clocks, not one. You have 72 hours to tell the Data Protection Commission about a personal data breach that puts people at risk, and you must tell the affected people without delay if the risk is high. Telephone and internet providers report through a separate channel under separate rules. And if the police send you an order to take down terrorist content, you have one hour.High confidence
What's the trap?
Five things that cost people their weekend. First, Ireland's famous ban on advertising to children has never actually switched on. Second, the official copy of the law on the government's own statute website can be out of date and misleading. Third, a child in Ireland is anyone under 16 for consent purposes, not 13. Fourth, some record-keeping failures are crimes, not fines. Fifth, the regulator can only fine a public body up to 1 million euro (about 1.1 million US dollars), so it uses stop orders instead.High confidence
What's about to change?
Three things land in the next year. Ireland's new health records law is switching on in stages, and the parts that let doctors share your file and that allow sharing with countries outside Europe are still switched off. Europe's cloud switching rules make all data exit fees zero on 12 January 2027. And Ireland still has not written the European cybersecurity directive into Irish law, almost two years past the deadline.High confidence
Hardest industry wall
  • Finance Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 106
  • Payments Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 108I
  • All industries Companies Act 2014, sections 283 and 285