Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
SingaporeChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Active
- In one paragraph
- Singapore lets personal data leave the country, and we found no industry that is forced to keep data on Singaporean soil. What you must do instead is make the person receiving the data legally bound to protect it as well as Singapore law does. There is no government list of approved or banned countries and no permission to apply for. The privacy regulator is real, staffed, and publishes decisions.
- The catch
- The open headline is about location, not about paperwork or secrecy. Banks must follow a separate rulebook before customer information goes to any outside supplier, and that rulebook was completely replaced on 11 December 2024. Company accounting records held abroad must still have summaries sent back into Singapore. And a stricter rule in any other Singapore law beats the privacy law outright.
- Does this apply to me?
- Yes. The privacy law reaches a company that has never set foot in Singapore. It defines an organisation as any body of persons whether or not formed under Singapore law and whether or not it has an office here. There is no revenue or headcount threshold to fall below, and no in-country agent to appoint. You must name at least one person responsible for compliance and publish their contact details, but that person may sit anywhere in the world.High confidence
- Can the data leave the country?
- Yes, it can leave, and this is the unusual part: we searched banking, payments, insurance, securities, health, telecoms, government, education, gaming, mapping and defence and found no rule anywhere that forces personal data to stay in Singapore. What the law asks for is protection, not location. Before data goes abroad you must make sure the recipient is under a legal duty to protect it to a standard comparable to Singapore's.High confidence
- What do I have to do to send it abroad?
- There is no list of approved countries, no list of banned countries, and no form to file. You need one thing: the recipient must be under a legally enforceable duty to protect the data to a comparable standard. Most companies do this with a contract they draft themselves, because Singapore does not publish a template. Group companies can use internal group-wide rules instead, and since 2 March 2026 a recipient holding a Global Cross-Border Privacy Rules certificate also counts.High confidence
- Who enforces this — and are they actually working?
- The Personal Data Protection Commission, which is the same body as the media and telecoms regulator wearing a different hat. It is genuinely working: it publishes batches of decisions and settlements several times a year, with the most recent batches in 2026. Financial firms answer to the central bank as well, and anyone running critical national systems answers to the Cyber Security Agency. All three are staffed and issuing instruments.High confidence
- How long must I keep it, and when must I delete it?
- Both directions apply. The ceiling: you must stop keeping personal data once the purpose is finished and there is no legal or business reason to hold it, and there is no fixed number of days attached to that. The floor: company accounting records must be kept for at least five years, tax records for at least five years from the relevant year of assessment, and employment records for the latest two years, kept one year past the date an employee leaves.High confidence
- What happens when something goes wrong?
- There are at least three separate clocks and they run at very different speeds. Privacy: once you have decided a breach is serious enough to report, you have three calendar days to tell the regulator. Finance: a bank or other supervised firm has ONE HOUR to tell the central bank about a severe incident, then fourteen days for a root cause report. Critical national systems: TWO HOURS by phone to the national cyber agency, then a fuller report within seventy-two hours.High confidence
- What's the trap?
- Five things that are not in the summary. One: an individual employee can go to prison for two years for leaking personal data, and that is separate from any fine on the company. Two: any other Singapore law beats the privacy law, so banking secrecy and similar duties override it. Three: every organisation must stop using national identity card numbers as passwords by 31 December 2026. Four: the data portability right is printed in the Act but has never been switched on. Five: the banking outsourcing rulebook everyone cites was cancelled in December 2024.High confidence
- What's about to change?
- Three real things are in flight. A new health law has been passed but not started, and it will add its own breach reporting clocks for anyone handling health records. A draft law for big data centres and big cloud providers went out for public comment on 1 July 2026 and closed on 22 July 2026; it is not law yet. And every organisation must stop using national identity numbers as passwords by 31 December 2026. Separately, watch two switches the government can flip with no consultation at all.High confidence
- Hardest industry wall
- All industries — Companies Act 1967, section 199
SpainChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
- In one paragraph
- Spain follows the normal European rule: personal data may leave the country once you have the right paperwork in place. But four named categories of data held by the Spanish state must physically stay inside the European Union, and may only travel further to a country Europe has officially approved. Spain's privacy regulator is one of the busiest in the world.
- The catch
- The relaxed headline stops being true the moment you touch the electoral roll, town-hall population registers, Spanish tax records or data about users of the Spanish national health service. For those four things a standard European transfer contract is not enough and never will be — the law allows only officially approved destinations. Online gambling, telecoms and any system sold to the Spanish public sector carry their own separate rules.
- Does this apply to me?
- Yes. A company with no office in Spain is still caught if it offers goods or services to people in Spain or watches what they do online. There is no size or revenue threshold to hide under. If you have no base anywhere in Europe you must appoint a written representative inside Europe, and Spain's regulator will happily deal with that representative instead of you.High confidence
- Can the data leave the country?
- For most businesses, yes, with paperwork — the ordinary European rules apply and nothing in Spanish law says data must sit on Spanish soil. The exception is sharp. If the data is the electoral roll, a town-hall population register, Spanish tax records, or information about users of the Spanish national health service, the computers holding it must be inside the European Union, and that data may only go outside Europe to a country Europe has officially approved. A standard European transfer contract does not work for those four things.High confidence
- What do I have to do to send it abroad?
- The model is an approved-list one, run at European level, not by Spain. You may send data outside Europe if the destination country is on Europe's approved list, or if you sign Europe's standard contract, or if your corporate group has approved internal rules. The list is real and populated. Spain adds one twist: if you want to use a home-made contract instead of the standard one, you must get written permission from the Spanish regulator first.High confidence
- Who enforces this — and are they actually working?
- The Spanish Data Protection Agency, and it is very much awake. Its public decision database held 46,925 decisions when we checked on 18 August 2026, with rulings signed as recently as 12 August 2026. Three regional authorities also enforce, covering public bodies in Catalonia, the Basque Country and Andalusia. Spain's artificial intelligence supervisor is now operating too and met the privacy agency in July 2026 to divide up the work.High confidence
- How long must I keep it, and when must I delete it?
- Both directions, and they collide. The longest floor is money laundering records: ten years, and the same law then orders you to destroy them. Business books run six years, clinical records at least five years from the end of each course of treatment, phone and internet connection records twelve months, and the taxman can come back four years. In the other direction Spain does something unusual: when someone asks you to delete their data you must not actually delete it, you must lock it away.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. Everyone has 72 hours to tell the privacy regulator about a personal data breach. Phone and internet providers have only 24 hours under a separate European rule. And if you run something the state treats as an essential service, the cyber clock says report immediately, then send an update within 24 to 48 hours if the incident is critical, or 72 hours if it is very serious, with a final report 20 or 40 days later.High confidence
- What's the trap?
- Five things that ruin weekends. One: a child can consent at fourteen in Spain, not sixteen, so your global age gate is probably wrong here. Two: 'delete my data' legally means 'lock my data away', so a hard-delete pipeline breaks the law. Three: Spain forces far more organisations to appoint a data protection officer than Europe does, including every school, university, bank, insurer, energy supplier and online gambling operator. Four: misusing someone's personal records is a crime punishable by prison, and companies themselves can be prosecuted. Five: telecoms operators can be ordered to hand over the encryption method they use.High confidence
- What's about to change?
- The biggest thing is what has not happened. Spain still has not passed the law that brings Europe's new cybersecurity rules into Spanish law, so the old 2018 regime is still what binds — expect that to change and to widen sharply who must report incidents. From 12 January 2027 no cloud provider may charge you to leave or to pull your data out. Watch three switches the government can flip with no consultation: taking over telecoms networks, ordering gambling systems into Spain, and demanding an operator's encryption method.Medium confidence
- Hardest industry wall
- None found.