Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
SloveniaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Slovenia has no general rule that data must stay in the country. It runs on the European rulebook: send data abroad once you have the right paperwork. Three things break that. The company running the new national health record system may not store data outside Slovenia. Government bodies may cloud only their least sensitive data. And working-time records must sit at the Slovenian workplace.
The catch
The easy answer stops being true in four places. First, health: the state-owned company running the central health information system is forbidden by law from transferring or storing personal data outside Slovenian territory, and every healthcare provider in the country must plug into that system. Second, government: a state administration body may only use a public cloud for the lowest security tiers of information, and only after the ministry approves in writing. Third, employment: the record of working time and the documents behind it must be kept at the employer's registered office or at the place where the worker actually works. Fourth, gambling: only a joint-stock company registered in Slovenia can hold a concession, and its system must be wired into the tax authority's own system. Banking, payments, insurance, securities, telecoms and mapping have no storage-location rule that we could find.
Does this apply to me?
Yes. Slovenia's privacy rules reach a company with no office there. If you offer goods or services to people in Slovenia, or watch what they do online, the European rules apply to you and Slovenia's own privacy act applies alongside them. There is no size or revenue threshold that lets you out. A company with no office anywhere in Europe must appoint a written representative inside Europe.High confidence
Can the data leave the country?
In general yes, with paperwork — Slovenia adds no national storage-location rule of its own on top of the European regime. But four industries break that answer, and one of them is a hard wall. Health is the big one: the state company that runs Slovenia's central health record system is banned outright from storing or sending personal data outside Slovenia, and every healthcare provider must connect to that system. Government cloud, employment records and gambling each carry their own restriction.High confidence
What do I have to do to send it abroad?
Slovenia uses the European model, and it works like an approved-destinations list with escape hatches. Data may go to a country the European Commission has approved. If the destination is not approved, you can still send data by signing the Commission's standard contract, using approved group-wide rules, or relying on one of a few narrow exceptions. Slovenia adds nothing of its own. The old Slovenian system, where the Information Commissioner had to authorise each export, was scrapped when the current privacy act arrived in January 2023.High confidence
Who enforces this — and are they actually working?
The Information Commissioner, and it is genuinely working. In 2025 it opened 464 inspection cases from complaints plus 102 more from inspection reports, issued 134 enforcement decisions, fined in 89 of them, gave warnings in 45, and handed down what it calls its largest fine since the European rules began. It handled 153 breach reports. It is small: one commissioner and 53 staff at the end of 2025, and it says openly that it does not have enough people. Cybersecurity is enforced separately by a government office set up for the job.High confidence
How long must I keep it, and when must I delete it?
Both directions, and the floors are long. A patient's medical file must be kept for ten years after the patient dies, and other basic medical records for fifteen years. Records of who touched personal data in a computer system must be kept for two years after the end of the year, and up to five if the risk is high. Working-time records must be kept at the Slovenian workplace. In the other direction the European rule applies: delete personal data once the purpose is spent.High confidence
What happens when something goes wrong?
Count three clocks, not one. A personal data breach goes to the Information Commissioner within 72 hours. A serious cyber incident, if you are an essential or important organisation, goes to the government security office immediately and in any case within 24 hours as an early warning, then a full report within 72 hours, then a final report within one month. Telecoms operators have their own duties on top. Missing the 24-hour warning is the most common failure, because it lands while you are still working out what happened.High confidence
What's the trap?
Five things that catch people out. A child can consent at 15 in Slovenia, not 16 — one year younger than the European default. Fingerprints and face scans are banned in the private sector unless a law allows them and the Commissioner approves. Every access to a covered database must be logged and the log kept two years. Leaking personal data you got through your job is a crime, not just a fine. And working-time records must physically be at the Slovenian workplace, which no cloud contract fixes.High confidence
What's about to change?
Two dates in the next twelve months matter most. On 19 December 2026 the cybersecurity duties bite for organisations newly captured by Slovenia's 2025 Information Security Act — registration, security measures and the incident clocks. On 12 January 2027 the European Data Act bans all cloud switching and data export fees. Behind both sits the roll-out of the national health record system, whose ban on storing data outside Slovenia is already law but whose timetable we could not pin down.Medium confidence
Hardest industry wall
  • Health and social care Zakon o digitalizaciji zdravstva (ZDigZ)
  • All industries Zakon o spremembah in dopolnitvah Zakona o evidencah na področju dela in socialne varnosti (ZEPDSV-A)
GreeceChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
For most businesses Greece is a normal European country: personal data can leave, as long as you use one of the standard European transfer tools. But Greece has two hard walls that Europe does not. Phone and internet connection records must physically sit on machines inside Greece. Online gambling operators must keep their records on a server inside Greece too. The privacy regulator is fully staffed and fining companies today.
The catch
The relaxed European headline stops being true the moment you touch three things. Telecoms connection records must be stored on physical media inside Greek territory for twelve months. Online gambling records must sit on a server or safe inside Greece for ten years. And Greek public bodies must run their central systems on the Greek state's own clouds, not on a commercial cloud of their choosing. Outside those three, plus the health and public sectors, Greece imposes no storage-location rule of its own.
Does this apply to me?
Yes, it reaches a foreign company with no office in Greece. The European privacy rules apply to anyone anywhere who offers goods or services to people in Greece, or who watches what they do online. The Greek national law adds that it also covers anyone processing data on Greek soil. There is no size or revenue threshold that lets you off. If you have no establishment anywhere in Europe, you must appoint a written representative inside the European Union.High confidence
Can the data leave the country?
In general, yes. Greece adds no storage-location rule of its own to the European baseline, so ordinary business data can be sent abroad once you have the right European transfer paperwork. Three industries break that rule completely. Telecoms companies must keep their connection records on machines physically inside Greece. Online gambling operators must keep their records on a server inside Greece. And Greek government bodies must run their main systems on state-operated clouds. Health, banking and insurance have extra hoops but no location rule.High confidence
What do I have to do to send it abroad?
You need one of the standard European transfer tools before data leaves Europe. The simplest is sending it to a country the European Commission has already approved. If the destination is not approved, you sign the European Commission's standard contract with the recipient, or use approved group-wide internal rules, and you write down why you think the data will still be safe there. Greece adds no extra permission, filing or fee of its own.High confidence
Who enforces this — and are they actually working?
Six bodies, and all six are genuinely working. The Hellenic Data Protection Authority is the main privacy regulator and is issuing numbered decisions and fines every month — its most recent published decisions run to July 2026 and include fines on a bank and an electricity supplier. A separate constitutional authority polices the secrecy of communications. There is also a national cybersecurity authority, a telecoms regulator, the central bank for finance and insurance, and a gambling regulator. This is not a paper regime.High confidence
How long must I keep it, and when must I delete it?
Both directions apply, and they collide. Business books must be kept five years. Medical files must be kept ten years in a private practice and twenty years everywhere else. Online gambling records must be kept ten years. Telecoms connection records must be kept exactly twelve months and then automatically deleted. In the other direction, the European rule says you must not keep personal data longer than you need it. When a specific keeping rule and the general deleting rule clash, the specific keeping rule wins.High confidence
What happens when something goes wrong?
Count three clocks, not one. If personal data is lost or exposed, you have 72 hours to tell the privacy regulator. If you run important infrastructure, you have only 24 hours to send a first warning to the national cybersecurity authority, then 72 hours for a fuller report and one month for the final one. If you are a phone or internet provider, you have 24 hours to report a personal data breach and a separate duty to tell the communications secrecy authority. Missing the 24-hour clocks is the most common failure.High confidence
What's the trap?
Five things that will cost you a weekend. First, a child in Greece can consent to an online service at fifteen, not sixteen — so an age gate built to the European default is set wrong. Second, misusing personal data is a crime here, with prison time, not just a fine. Third, several articles of the Greek privacy law are printed in the statute but the regulator has formally said they must not be applied, because they clash with European law. Fourth, telecoms connection records must physically stay in Greece. Fifth, government bodies cannot simply pick a commercial cloud.High confidence
What's about to change?
Three dated changes. Electronic invoicing between businesses became compulsory for large Greek companies on 2 March 2026 and becomes compulsory for everyone else on 1 October 2026. Greece's new artificial intelligence law took effect on 22 July 2026 and forces public bodies to register every artificial intelligence system before switching it on. And from 12 January 2027 European law bans cloud providers from charging you to move your data out.High confidence
Hardest industry wall
  • Telecoms Νόμος 3917/2011 — Διατήρηση δεδομένων που παράγονται ή υποβάλλονται σε επεξεργασία σε συνάρτηση με την παροχή υπηρεσιών ηλεκτρονικών επικοινωνιών
  • Online gaming Νόμος 4002/2011 — Ρύθμιση της αγοράς παιγνίων, άρθρο 47, και Κανονισμοί Παιγνίων (ΥΑ 79305/2020 και 79835/2020)
  • Government Νόμος 4727/2020 — Ψηφιακή Διακυβέρνηση, άρθρο 87 (Κυβερνητικά νέφη)