Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
SingaporeChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Active
In one paragraph
Singapore lets personal data leave the country, and we found no industry that is forced to keep data on Singaporean soil. What you must do instead is make the person receiving the data legally bound to protect it as well as Singapore law does. There is no government list of approved or banned countries and no permission to apply for. The privacy regulator is real, staffed, and publishes decisions.
The catch
The open headline is about location, not about paperwork or secrecy. Banks must follow a separate rulebook before customer information goes to any outside supplier, and that rulebook was completely replaced on 11 December 2024. Company accounting records held abroad must still have summaries sent back into Singapore. And a stricter rule in any other Singapore law beats the privacy law outright.
Does this apply to me?
Yes. The privacy law reaches a company that has never set foot in Singapore. It defines an organisation as any body of persons whether or not formed under Singapore law and whether or not it has an office here. There is no revenue or headcount threshold to fall below, and no in-country agent to appoint. You must name at least one person responsible for compliance and publish their contact details, but that person may sit anywhere in the world.High confidence
Can the data leave the country?
Yes, it can leave, and this is the unusual part: we searched banking, payments, insurance, securities, health, telecoms, government, education, gaming, mapping and defence and found no rule anywhere that forces personal data to stay in Singapore. What the law asks for is protection, not location. Before data goes abroad you must make sure the recipient is under a legal duty to protect it to a standard comparable to Singapore's.High confidence
What do I have to do to send it abroad?
There is no list of approved countries, no list of banned countries, and no form to file. You need one thing: the recipient must be under a legally enforceable duty to protect the data to a comparable standard. Most companies do this with a contract they draft themselves, because Singapore does not publish a template. Group companies can use internal group-wide rules instead, and since 2 March 2026 a recipient holding a Global Cross-Border Privacy Rules certificate also counts.High confidence
Who enforces this — and are they actually working?
The Personal Data Protection Commission, which is the same body as the media and telecoms regulator wearing a different hat. It is genuinely working: it publishes batches of decisions and settlements several times a year, with the most recent batches in 2026. Financial firms answer to the central bank as well, and anyone running critical national systems answers to the Cyber Security Agency. All three are staffed and issuing instruments.High confidence
How long must I keep it, and when must I delete it?
Both directions apply. The ceiling: you must stop keeping personal data once the purpose is finished and there is no legal or business reason to hold it, and there is no fixed number of days attached to that. The floor: company accounting records must be kept for at least five years, tax records for at least five years from the relevant year of assessment, and employment records for the latest two years, kept one year past the date an employee leaves.High confidence
What happens when something goes wrong?
There are at least three separate clocks and they run at very different speeds. Privacy: once you have decided a breach is serious enough to report, you have three calendar days to tell the regulator. Finance: a bank or other supervised firm has ONE HOUR to tell the central bank about a severe incident, then fourteen days for a root cause report. Critical national systems: TWO HOURS by phone to the national cyber agency, then a fuller report within seventy-two hours.High confidence
What's the trap?
Five things that are not in the summary. One: an individual employee can go to prison for two years for leaking personal data, and that is separate from any fine on the company. Two: any other Singapore law beats the privacy law, so banking secrecy and similar duties override it. Three: every organisation must stop using national identity card numbers as passwords by 31 December 2026. Four: the data portability right is printed in the Act but has never been switched on. Five: the banking outsourcing rulebook everyone cites was cancelled in December 2024.High confidence
What's about to change?
Three real things are in flight. A new health law has been passed but not started, and it will add its own breach reporting clocks for anyone handling health records. A draft law for big data centres and big cloud providers went out for public comment on 1 July 2026 and closed on 22 July 2026; it is not law yet. And every organisation must stop using national identity numbers as passwords by 31 December 2026. Separately, watch two switches the government can flip with no consultation at all.High confidence
Hardest industry wall
  • All industries Companies Act 1967, section 199
GeorgiaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Georgia copied the European model in 2023: data can leave the country, but only to a destination the supervisor has approved, or with a permit, or under a narrow exception. There is no general rule forcing data to stay. The big change is who is in charge — on 2 March 2026 the independent privacy watchdog was replaced by the State Audit Office, and we could not verify that it has issued a single decision since.
The catch
Two things break the calm headline. Telephone and internet connection records are copied into a state-held database inside Georgia, so telecoms cannot treat that data as ordinary business data. And the same State Audit Office that now polices privacy also runs the public register of foreign-funded organisations.
Does this apply to me?
Yes. The law catches a company with no office in Georgia if it uses technical means located in Georgia to handle people's data. There is no revenue or headcount threshold to duck under. Worse, a foreign company in that position must appoint a representative in Georgia and register that person with the supervisor BEFORE it starts processing — the only escape is being based in the European Union or in a country the European Union has already approved.High confidence
Can the data leave the country?
Yes, with paperwork. Data may go abroad if the destination country has been judged to give good enough protection, or if the supervisor grants a permit for the contract you have signed, or under a short list of narrow exceptions such as the person's written consent after being told the risks. Nothing in the general law forces data to stay in Georgia. The one place data really does stay is telecoms: a copy of who called whom, and when, sits in a state-run database inside the country.High confidence
What do I have to do to send it abroad?
The model is an approved-destinations list, with a permit as the back-up. The supervisor decides which countries offer good enough protection and publishes that decision as a formal act; if your destination is not on it, you need a permit for your contract, or you fall back on a narrow exception such as written consent. We could not find the current published list, so we cannot tell you today which countries are on it — treat that as the single biggest open question in this record.Medium confidence
Who enforces this — and are they actually working?
This is where Georgia surprises people. Until 1 March 2026 the job belonged to the Personal Data Protection Service, an independent watchdog. From 2 March 2026 the law hands the same job to the State Audit Office — the body that audits government spending — and its head, the Auditor General, now signs the privacy rules. We can prove the handover happened, because the Auditor General reissued two of the privacy rulebooks at the end of March 2026. We could not find a single enforcement decision published since the handover.Medium confidence
How long must I keep it, and when must I delete it?
The ceiling is clear: keep personal data only as long as you need it for the purpose you collected it for, then erase, destroy or strip out the identifying parts, unless another law tells you to keep it. The floors are scattered across tax, accounting and sector laws that we could not open on an official site today. In telecoms the direction is reversed — the content of a call or message must be destroyed at once, while the record of who contacted whom can be copied into a state database and kept for a period set by a separate law.Medium confidence
What happens when something goes wrong?
Two clocks. If personal data is lost, leaked or wrongly handled, you have 72 hours from spotting it to tell the supervisor, and you must keep your own record of the incident and what you did about it. If you run a system the government has listed as critical to the country, you must tell the national computer emergency response team immediately — no fixed number of hours, which in practice means the same day. If both apply to you, both run at once.High confidence
What's the trap?
Five. First, the regulator changed identity on 2 March 2026, so a privacy notice or contract naming the Personal Data Protection Service now points at a body the law no longer mentions. Second, a foreign company must register a representative in Georgia before it starts, not after. Third, a child is anyone under 16, so a European sign-up flow tuned to 13 will be wrong here. Fourth, direct marketing always needs consent, even if you bought the list lawfully. Fifth, the same State Audit Office that now polices privacy also runs the public register of foreign-funded organisations, which must publish detailed information about themselves.Medium confidence
What's about to change?
Nothing new is scheduled to start in the privacy law itself — we checked the current text on 18 August 2026 and found no provisions waiting on a future date. The live story is the handover: the Auditor General is reissuing the four rulebooks inherited from the old watchdog, and two of the four were reissued in March 2026. The rest of the risk sits in switches the government can already flip without a new law.Medium confidence
Hardest industry wall
  • Telecoms საქართველოს კანონი ელექტრონული კომუნიკაციების შესახებ