Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
SingaporeChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Active
In one paragraph
Singapore lets personal data leave the country, and we found no industry that is forced to keep data on Singaporean soil. What you must do instead is make the person receiving the data legally bound to protect it as well as Singapore law does. There is no government list of approved or banned countries and no permission to apply for. The privacy regulator is real, staffed, and publishes decisions.
The catch
The open headline is about location, not about paperwork or secrecy. Banks must follow a separate rulebook before customer information goes to any outside supplier, and that rulebook was completely replaced on 11 December 2024. Company accounting records held abroad must still have summaries sent back into Singapore. And a stricter rule in any other Singapore law beats the privacy law outright.
Does this apply to me?
Yes. The privacy law reaches a company that has never set foot in Singapore. It defines an organisation as any body of persons whether or not formed under Singapore law and whether or not it has an office here. There is no revenue or headcount threshold to fall below, and no in-country agent to appoint. You must name at least one person responsible for compliance and publish their contact details, but that person may sit anywhere in the world.High confidence
Can the data leave the country?
Yes, it can leave, and this is the unusual part: we searched banking, payments, insurance, securities, health, telecoms, government, education, gaming, mapping and defence and found no rule anywhere that forces personal data to stay in Singapore. What the law asks for is protection, not location. Before data goes abroad you must make sure the recipient is under a legal duty to protect it to a standard comparable to Singapore's.High confidence
What do I have to do to send it abroad?
There is no list of approved countries, no list of banned countries, and no form to file. You need one thing: the recipient must be under a legally enforceable duty to protect the data to a comparable standard. Most companies do this with a contract they draft themselves, because Singapore does not publish a template. Group companies can use internal group-wide rules instead, and since 2 March 2026 a recipient holding a Global Cross-Border Privacy Rules certificate also counts.High confidence
Who enforces this — and are they actually working?
The Personal Data Protection Commission, which is the same body as the media and telecoms regulator wearing a different hat. It is genuinely working: it publishes batches of decisions and settlements several times a year, with the most recent batches in 2026. Financial firms answer to the central bank as well, and anyone running critical national systems answers to the Cyber Security Agency. All three are staffed and issuing instruments.High confidence
How long must I keep it, and when must I delete it?
Both directions apply. The ceiling: you must stop keeping personal data once the purpose is finished and there is no legal or business reason to hold it, and there is no fixed number of days attached to that. The floor: company accounting records must be kept for at least five years, tax records for at least five years from the relevant year of assessment, and employment records for the latest two years, kept one year past the date an employee leaves.High confidence
What happens when something goes wrong?
There are at least three separate clocks and they run at very different speeds. Privacy: once you have decided a breach is serious enough to report, you have three calendar days to tell the regulator. Finance: a bank or other supervised firm has ONE HOUR to tell the central bank about a severe incident, then fourteen days for a root cause report. Critical national systems: TWO HOURS by phone to the national cyber agency, then a fuller report within seventy-two hours.High confidence
What's the trap?
Five things that are not in the summary. One: an individual employee can go to prison for two years for leaking personal data, and that is separate from any fine on the company. Two: any other Singapore law beats the privacy law, so banking secrecy and similar duties override it. Three: every organisation must stop using national identity card numbers as passwords by 31 December 2026. Four: the data portability right is printed in the Act but has never been switched on. Five: the banking outsourcing rulebook everyone cites was cancelled in December 2024.High confidence
What's about to change?
Three real things are in flight. A new health law has been passed but not started, and it will add its own breach reporting clocks for anyone handling health records. A draft law for big data centres and big cloud providers went out for public comment on 1 July 2026 and closed on 22 July 2026; it is not law yet. And every organisation must stop using national identity numbers as passwords by 31 December 2026. Separately, watch two switches the government can flip with no consultation at all.High confidence
Hardest industry wall
  • All industries Companies Act 1967, section 199
MaltaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
In one paragraph
Malta runs on the European rulebook. Data may go abroad once the right paperwork is in place, and there is no general rule that it must stay on the island. Two things break that. Online gaming companies must keep their core systems inside Europe. And any Maltese company that keeps its books abroad must still keep a copy of its accounts in Malta.
The catch
The easy answer stops being true in three places. First, online gaming, which is Malta's biggest regulated industry: a licensed operator's 'key technical setup' — including the player database, the financial database and the control system — must sit in Malta or another European Economic Area country, unless the Malta Gaming Authority approves another location one case at a time. The same operator must also run a live mirror of its essential regulatory data that the Authority can reach at any moment, including physically. Second, company law: if a company keeps its accounting records outside Malta, it must still send to Malta, and keep in Malta, accounts and returns good enough to show the financial position at least every six months. Third, government: the public administration's own cloud policy says cloud services should as a rule be inside the European Union or European Economic Area, and anything classified must go on the government's own cloud. Banking, payments, insurance, securities, health, education and mapping have no storage-location rule that we could find, checked 18 August 2026.
Does this apply to me?
Yes. Malta's Data Protection Act reaches a company with no office in Malta if it offers goods or services to people in Malta, or watches their behaviour in Malta. There is no size or revenue threshold. There is no extra Maltese representative to appoint beyond the one the European rules already require of companies based outside Europe.High confidence
Can the data leave the country?
In general, yes. Malta has no law saying personal data must be stored on the island. It follows the European Union rules: send data outside Europe once you have an approved destination or the right contract. Three areas override that. Online gaming is the big one, and it is Malta's flagship industry.High confidence
What do I have to do to send it abroad?
Use the European toolkit. Send data to a country the European Commission has approved, or sign the European standard contract, or use approved group-wide rules. Malta adds nothing on top. Malta's own minister has a power to restrict transfers of named categories of data, but has never used it, so the list of Maltese restrictions is empty today.High confidence
Who enforces this — and are they actually working?
The Information and Data Protection Commissioner. It is real, staffed and issuing decisions: its public register shows around nineteen decisions published in 2026 and thirty-eight in 2025. The fines are small by European standards — most sit between about 2,000 and 20,000 euros (roughly $2,300 to $23,000). The gaming regulator is the harder one, and it cancels licences.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling. The floor: company accounting records for ten years, tax and value-added-tax records for at least six years, and anti-money-laundering records for five years. The ceiling: the European rule that you delete personal data once you no longer need it. Where they clash, the specific Maltese law that orders you to keep something wins, because keeping it is then a legal duty.High confidence
What happens when something goes wrong?
Count three clocks, and they do not line up. Seventy-two hours to tell the privacy regulator about a personal data breach. Twenty-four hours to send a first warning about a serious cyber incident, then seventy-two hours for the full report and one month for the final one. Phone and internet companies have their own separate duty to report straight away.High confidence
What's the trap?
Five things that are not in the summary. A child in Malta is thirteen, not sixteen. Health and biometric research needs the regulator's written permission before you start, not just a risk assessment. Copying someone's identity card is restricted. Leaking a client secret can be a crime, not a fine. And the gaming regulator can keep personal data forever, in a law that says so out loud.High confidence
What's about to change?
Three dated changes. On 1 January 2027 a new law stops insurers, banks and employers asking about a cancer diagnosis once enough time has passed since treatment. On 12 January 2027 European rules make cloud switching and data export fees free. And Malta's artificial intelligence rules started phasing in on 2 August 2026, with the privacy regulator now policing the market.High confidence
Hardest industry wall
  • All industries Att dwar il-Kumpaniji (Kap. 386), artikolu 163