Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
SingaporeChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Active
- In one paragraph
- Singapore lets personal data leave the country, and we found no industry that is forced to keep data on Singaporean soil. What you must do instead is make the person receiving the data legally bound to protect it as well as Singapore law does. There is no government list of approved or banned countries and no permission to apply for. The privacy regulator is real, staffed, and publishes decisions.
- The catch
- The open headline is about location, not about paperwork or secrecy. Banks must follow a separate rulebook before customer information goes to any outside supplier, and that rulebook was completely replaced on 11 December 2024. Company accounting records held abroad must still have summaries sent back into Singapore. And a stricter rule in any other Singapore law beats the privacy law outright.
- Does this apply to me?
- Yes. The privacy law reaches a company that has never set foot in Singapore. It defines an organisation as any body of persons whether or not formed under Singapore law and whether or not it has an office here. There is no revenue or headcount threshold to fall below, and no in-country agent to appoint. You must name at least one person responsible for compliance and publish their contact details, but that person may sit anywhere in the world.High confidence
- Can the data leave the country?
- Yes, it can leave, and this is the unusual part: we searched banking, payments, insurance, securities, health, telecoms, government, education, gaming, mapping and defence and found no rule anywhere that forces personal data to stay in Singapore. What the law asks for is protection, not location. Before data goes abroad you must make sure the recipient is under a legal duty to protect it to a standard comparable to Singapore's.High confidence
- What do I have to do to send it abroad?
- There is no list of approved countries, no list of banned countries, and no form to file. You need one thing: the recipient must be under a legally enforceable duty to protect the data to a comparable standard. Most companies do this with a contract they draft themselves, because Singapore does not publish a template. Group companies can use internal group-wide rules instead, and since 2 March 2026 a recipient holding a Global Cross-Border Privacy Rules certificate also counts.High confidence
- Who enforces this — and are they actually working?
- The Personal Data Protection Commission, which is the same body as the media and telecoms regulator wearing a different hat. It is genuinely working: it publishes batches of decisions and settlements several times a year, with the most recent batches in 2026. Financial firms answer to the central bank as well, and anyone running critical national systems answers to the Cyber Security Agency. All three are staffed and issuing instruments.High confidence
- How long must I keep it, and when must I delete it?
- Both directions apply. The ceiling: you must stop keeping personal data once the purpose is finished and there is no legal or business reason to hold it, and there is no fixed number of days attached to that. The floor: company accounting records must be kept for at least five years, tax records for at least five years from the relevant year of assessment, and employment records for the latest two years, kept one year past the date an employee leaves.High confidence
- What happens when something goes wrong?
- There are at least three separate clocks and they run at very different speeds. Privacy: once you have decided a breach is serious enough to report, you have three calendar days to tell the regulator. Finance: a bank or other supervised firm has ONE HOUR to tell the central bank about a severe incident, then fourteen days for a root cause report. Critical national systems: TWO HOURS by phone to the national cyber agency, then a fuller report within seventy-two hours.High confidence
- What's the trap?
- Five things that are not in the summary. One: an individual employee can go to prison for two years for leaking personal data, and that is separate from any fine on the company. Two: any other Singapore law beats the privacy law, so banking secrecy and similar duties override it. Three: every organisation must stop using national identity card numbers as passwords by 31 December 2026. Four: the data portability right is printed in the Act but has never been switched on. Five: the banking outsourcing rulebook everyone cites was cancelled in December 2024.High confidence
- What's about to change?
- Three real things are in flight. A new health law has been passed but not started, and it will add its own breach reporting clocks for anyone handling health records. A draft law for big data centres and big cloud providers went out for public comment on 1 July 2026 and closed on 22 July 2026; it is not law yet. And every organisation must stop using national identity numbers as passwords by 31 December 2026. Separately, watch two switches the government can flip with no consultation at all.High confidence
- Hardest industry wall
- All industries — Companies Act 1967, section 199
SlovakiaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- Slovakia has no general rule that data must stay in the country. It runs on the European rulebook: send data abroad once you have the right paperwork. Three areas break that rule. Online gambling servers must sit on Slovak soil. The most sensitive government data must stay in a Slovak data centre. And anyone who takes aerial survey pictures of Slovakia must hand a copy to a defence ministry archive.
- The catch
- The easy answer stops being true in three places. First, online gambling: the operator's server must be physically in Slovakia, with no European Economic Area alternative. Second, government cloud: a public body handling the top security category of data may only use a service that stores and processes it inside Slovakia, in a data centre within reach of the Slovak state. Third, mapping: primary aerial survey imagery and published maps must be deposited with Slovak state archives, including one run by the Ministry of Defence. Banking, payments, insurance, securities, health and telecoms have no storage-location rule that we could find.
- Does this apply to me?
- Yes. A company with no office in Slovakia is still caught if it offers goods or services to people in Slovakia, or watches what they do online. There is no minimum size, headcount or revenue below which you are safe. If you have no office anywhere in the European Union, you must name a written representative inside the Union, and you can put that person in any member state where your customers are — it does not have to be Slovakia.High confidence
- Can the data leave the country?
- In general, yes — with the standard European paperwork. Nothing in Slovak law says personal data must be kept in Slovakia, and the law says so almost in as many words: it applies to a Slovak company whether it processes data inside or outside the country. But three specific activities do force data to stay. Online gambling operators must put their server in Slovakia. The top security tier of government data must stay in a Slovak data centre. And aerial survey imagery of Slovakia must be handed to a state archive.High confidence
- What do I have to do to send it abroad?
- Slovakia uses the European model, and it is an allowlist. Data may go to a country the European Commission has approved, or to anywhere else if you sign the Commission's standard contract, use approved group-wide rules, or fit one of a few narrow exceptions. The approved list is real and populated — it includes the United Kingdom, Switzerland, Japan, South Korea, Canada for commercial bodies, and the United States only for companies signed up to the transatlantic framework. Slovakia adds nothing of its own on top.High confidence
- Who enforces this — and are they actually working?
- The Office for Personal Data Protection of the Slovak Republic. It is real, staffed and busy. In 2025 it issued 542 final fines totalling about 468,000 euros (roughly $510,000) and actually collected about 411,000 euros of that — a very high number of fines but a very small average, about 860 euros each. It has around 60 staff and got 20 extra posts in 2025. Cybersecurity incidents go to a separate body, the National Security Authority.High confidence
- How long must I keep it, and when must I delete it?
- There is no single retention rule. The general privacy rule is to delete when you no longer need the data. Against that sit long minimum-keeping duties: ten years for accounts and financial statements, and up to one hundred years after death for entries in the national health registers. Telecom companies keep far less than most people assume — Slovakia scrapped blanket call-record retention after its Constitutional Court struck it down, so operators only retain what a court order covers.High confidence
- What happens when something goes wrong?
- There are two clocks and they are different. A personal data breach goes to the privacy authority within 72 hours of you becoming aware of it, and to the affected people without undue delay if the risk to them is high. A cybersecurity incident at a regulated organisation goes to the National Security Authority twice: a first warning within 24 hours, then a fuller report within 72 hours. If you are both, you file both, to two different bodies.High confidence
- What's the trap?
- Five things that are not in the summary. Public bodies can be fined the full amount, with no discount. Mishandling personal data you got through your job is a crime, not just a fine. The age of consent for online services is 16, not 13. The rule on dead people's data changed today. And the gambling server rule has no European workaround.High confidence
- What's about to change?
- The whole national privacy law is being replaced by two new laws — one general, one for police and courts — but they are still bills and have no legal effect. Act 18/2018 was amended today, 18 August 2026, mostly to remove dead people from its scope. Public bodies face a bigger data-registration duty from 1 January 2027, and all cloud switching and data export fees across Europe must drop to zero by 12 January 2027.High confidence
- Hardest industry wall
- Online gaming — Zákon č. 30/2019 Z. z. o hazardných hrách a o zmene a doplnení niektorých zákonov, § 14 ods. 21 a 22
- Government — Metodické usmernenie č. 020775/2025/oSBATA z 11. 4. 2025 pre proces zaradenia cloudovej služby do katalógu vládnych cloudových služieb, vydané podľa § 24a zákona č. 95/2019 Z. z.
- Mapping and location — Zákon Národnej rady Slovenskej republiky č. 215/1995 Z. z. o geodézii a kartografii