Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
SingaporeChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Active
- In one paragraph
- Singapore lets personal data leave the country, and we found no industry that is forced to keep data on Singaporean soil. What you must do instead is make the person receiving the data legally bound to protect it as well as Singapore law does. There is no government list of approved or banned countries and no permission to apply for. The privacy regulator is real, staffed, and publishes decisions.
- The catch
- The open headline is about location, not about paperwork or secrecy. Banks must follow a separate rulebook before customer information goes to any outside supplier, and that rulebook was completely replaced on 11 December 2024. Company accounting records held abroad must still have summaries sent back into Singapore. And a stricter rule in any other Singapore law beats the privacy law outright.
- Does this apply to me?
- Yes. The privacy law reaches a company that has never set foot in Singapore. It defines an organisation as any body of persons whether or not formed under Singapore law and whether or not it has an office here. There is no revenue or headcount threshold to fall below, and no in-country agent to appoint. You must name at least one person responsible for compliance and publish their contact details, but that person may sit anywhere in the world.High confidence
- Can the data leave the country?
- Yes, it can leave, and this is the unusual part: we searched banking, payments, insurance, securities, health, telecoms, government, education, gaming, mapping and defence and found no rule anywhere that forces personal data to stay in Singapore. What the law asks for is protection, not location. Before data goes abroad you must make sure the recipient is under a legal duty to protect it to a standard comparable to Singapore's.High confidence
- What do I have to do to send it abroad?
- There is no list of approved countries, no list of banned countries, and no form to file. You need one thing: the recipient must be under a legally enforceable duty to protect the data to a comparable standard. Most companies do this with a contract they draft themselves, because Singapore does not publish a template. Group companies can use internal group-wide rules instead, and since 2 March 2026 a recipient holding a Global Cross-Border Privacy Rules certificate also counts.High confidence
- Who enforces this — and are they actually working?
- The Personal Data Protection Commission, which is the same body as the media and telecoms regulator wearing a different hat. It is genuinely working: it publishes batches of decisions and settlements several times a year, with the most recent batches in 2026. Financial firms answer to the central bank as well, and anyone running critical national systems answers to the Cyber Security Agency. All three are staffed and issuing instruments.High confidence
- How long must I keep it, and when must I delete it?
- Both directions apply. The ceiling: you must stop keeping personal data once the purpose is finished and there is no legal or business reason to hold it, and there is no fixed number of days attached to that. The floor: company accounting records must be kept for at least five years, tax records for at least five years from the relevant year of assessment, and employment records for the latest two years, kept one year past the date an employee leaves.High confidence
- What happens when something goes wrong?
- There are at least three separate clocks and they run at very different speeds. Privacy: once you have decided a breach is serious enough to report, you have three calendar days to tell the regulator. Finance: a bank or other supervised firm has ONE HOUR to tell the central bank about a severe incident, then fourteen days for a root cause report. Critical national systems: TWO HOURS by phone to the national cyber agency, then a fuller report within seventy-two hours.High confidence
- What's the trap?
- Five things that are not in the summary. One: an individual employee can go to prison for two years for leaking personal data, and that is separate from any fine on the company. Two: any other Singapore law beats the privacy law, so banking secrecy and similar duties override it. Three: every organisation must stop using national identity card numbers as passwords by 31 December 2026. Four: the data portability right is printed in the Act but has never been switched on. Five: the banking outsourcing rulebook everyone cites was cancelled in December 2024.High confidence
- What's about to change?
- Three real things are in flight. A new health law has been passed but not started, and it will add its own breach reporting clocks for anyone handling health records. A draft law for big data centres and big cloud providers went out for public comment on 1 July 2026 and closed on 22 July 2026; it is not law yet. And every organisation must stop using national identity numbers as passwords by 31 December 2026. Separately, watch two switches the government can flip with no consultation at all.High confidence
- Hardest industry wall
- All industries — Companies Act 1967, section 199
NetherlandsChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
- In one paragraph
- For most businesses the Netherlands follows the ordinary European rules: data may leave the country once you have the right paperwork in place. Two areas are much harder. Online gambling firms must keep their regulator-facing database physically in the Netherlands, and central government now has to keep all its information inside Europe. The Dutch privacy regulator hands out some of the largest transfer fines in Europe.
- The catch
- The relaxed headline stops being true the moment you touch online gambling, central government work, health records or a regulated financial firm. An online gambling licence forces one database onto Dutch soil. Central government contracts now bar storage outside Europe. And a brand-new cybersecurity law switched on three days ago, on 15 August 2026, with a 24-hour incident alarm most companies have not built yet.
- Does this apply to me?
- Yes, it reaches you with no Dutch office. Europe's privacy law applies to any organisation anywhere that offers goods or services to people in the Netherlands or watches what they do online, and there is no size or revenue floor. Separately, the new Dutch cybersecurity law says that if you are a cloud provider, data centre, managed service provider, online marketplace, search engine or social network based outside Europe but selling into the Netherlands, you must appoint a representative inside the European Union.High confidence
- Can the data leave the country?
- In general yes, with paperwork, because the Netherlands is an EU country and European rules govern transfers. But three Dutch walls override that. An online gambling licence holder must physically place its regulator-facing control database in the Netherlands. Central government must keep all its information inside the European Economic Area plus Switzerland. And a healthcare provider, bank or insurer can put data abroad only if the supervisor can still see and audit it.High confidence
- What do I have to do to send it abroad?
- The model is an allowlist run at European level, not a Dutch one. You may send personal data outside Europe only if the destination has been officially approved, or you sign the standard European contract, or you use approved group-wide rules. The approved list is full and active. The Netherlands adds no national approval step and keeps no blocklist of its own.High confidence
- Who enforces this — and are they actually working?
- The Dutch Data Protection Authority, and it is very much operational and very much willing to fine. It has a full three-person board, and a new chair, Geert Potjewijd, took office on 1 August 2026. It has issued two of the largest cross-border transfer fines in Europe: 290 million euros against Uber in 2024 and 100 million euros against a taxi app in May 2026. Cybersecurity is enforced separately, by sector ministries and inspectorates, and that machinery is only now being assembled.High confidence
- How long must I keep it, and when must I delete it?
- There is a firm floor and a soft ceiling. You must keep your books and tax records for seven years, and money-laundering records for five years after the relationship or transaction ends. Against that, privacy law says you must delete personal data once you no longer need it, and there is no fixed number. When the two collide, the legal duty to keep wins for as long as it lasts, and deletion follows immediately after.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. For a personal data breach you have 72 hours to tell the Dutch Data Protection Authority. If you are covered by the new cybersecurity law that started on 15 August 2026, you must raise an early warning within 24 hours, file a full report within 72 hours, and deliver a final report within one month. Telecom operators have a fourth clock and must tell the privacy regulator without delay.High confidence
- What's the trap?
- Five things that are not in the summary. Your works council can block an HR or monitoring system. Breaking a professional secrecy duty is a crime, not a fine. The telecom retention duty printed in the law cannot be enforced. Children need a parent's permission until they turn sixteen. And the new cybersecurity law started on 15 August 2026 with a phased exception for universities that most checklists miss.High confidence
- What's about to change?
- Three dated changes. On 1 September 2026 an amendment act tidies up the Dutch privacy law and adds new rules for handing over health files, but one part of it has deliberately been left switched off. Registration and incident duties under the cybersecurity law that started on 15 August 2026 are being phased in now. And by 12 January 2027 every cloud provider must drop switching and data export charges to zero across Europe.High confidence
- Hardest industry wall
- Online gaming — Besluit kansspelen op afstand, artikel 4.42, tweede lid
- Government — Herziening rijksbreed cloudbeleid 2026