Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
SloveniaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- Slovenia has no general rule that data must stay in the country. It runs on the European rulebook: send data abroad once you have the right paperwork. Three things break that. The company running the new national health record system may not store data outside Slovenia. Government bodies may cloud only their least sensitive data. And working-time records must sit at the Slovenian workplace.
- The catch
- The easy answer stops being true in four places. First, health: the state-owned company running the central health information system is forbidden by law from transferring or storing personal data outside Slovenian territory, and every healthcare provider in the country must plug into that system. Second, government: a state administration body may only use a public cloud for the lowest security tiers of information, and only after the ministry approves in writing. Third, employment: the record of working time and the documents behind it must be kept at the employer's registered office or at the place where the worker actually works. Fourth, gambling: only a joint-stock company registered in Slovenia can hold a concession, and its system must be wired into the tax authority's own system. Banking, payments, insurance, securities, telecoms and mapping have no storage-location rule that we could find.
- Does this apply to me?
- Yes. Slovenia's privacy rules reach a company with no office there. If you offer goods or services to people in Slovenia, or watch what they do online, the European rules apply to you and Slovenia's own privacy act applies alongside them. There is no size or revenue threshold that lets you out. A company with no office anywhere in Europe must appoint a written representative inside Europe.High confidence
- Can the data leave the country?
- In general yes, with paperwork — Slovenia adds no national storage-location rule of its own on top of the European regime. But four industries break that answer, and one of them is a hard wall. Health is the big one: the state company that runs Slovenia's central health record system is banned outright from storing or sending personal data outside Slovenia, and every healthcare provider must connect to that system. Government cloud, employment records and gambling each carry their own restriction.High confidence
- What do I have to do to send it abroad?
- Slovenia uses the European model, and it works like an approved-destinations list with escape hatches. Data may go to a country the European Commission has approved. If the destination is not approved, you can still send data by signing the Commission's standard contract, using approved group-wide rules, or relying on one of a few narrow exceptions. Slovenia adds nothing of its own. The old Slovenian system, where the Information Commissioner had to authorise each export, was scrapped when the current privacy act arrived in January 2023.High confidence
- Who enforces this — and are they actually working?
- The Information Commissioner, and it is genuinely working. In 2025 it opened 464 inspection cases from complaints plus 102 more from inspection reports, issued 134 enforcement decisions, fined in 89 of them, gave warnings in 45, and handed down what it calls its largest fine since the European rules began. It handled 153 breach reports. It is small: one commissioner and 53 staff at the end of 2025, and it says openly that it does not have enough people. Cybersecurity is enforced separately by a government office set up for the job.High confidence
- How long must I keep it, and when must I delete it?
- Both directions, and the floors are long. A patient's medical file must be kept for ten years after the patient dies, and other basic medical records for fifteen years. Records of who touched personal data in a computer system must be kept for two years after the end of the year, and up to five if the risk is high. Working-time records must be kept at the Slovenian workplace. In the other direction the European rule applies: delete personal data once the purpose is spent.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. A personal data breach goes to the Information Commissioner within 72 hours. A serious cyber incident, if you are an essential or important organisation, goes to the government security office immediately and in any case within 24 hours as an early warning, then a full report within 72 hours, then a final report within one month. Telecoms operators have their own duties on top. Missing the 24-hour warning is the most common failure, because it lands while you are still working out what happened.High confidence
- What's the trap?
- Five things that catch people out. A child can consent at 15 in Slovenia, not 16 — one year younger than the European default. Fingerprints and face scans are banned in the private sector unless a law allows them and the Commissioner approves. Every access to a covered database must be logged and the log kept two years. Leaking personal data you got through your job is a crime, not just a fine. And working-time records must physically be at the Slovenian workplace, which no cloud contract fixes.High confidence
- What's about to change?
- Two dates in the next twelve months matter most. On 19 December 2026 the cybersecurity duties bite for organisations newly captured by Slovenia's 2025 Information Security Act — registration, security measures and the incident clocks. On 12 January 2027 the European Data Act bans all cloud switching and data export fees. Behind both sits the roll-out of the national health record system, whose ban on storing data outside Slovenia is already law but whose timetable we could not pin down.Medium confidence
- Hardest industry wall
- Health and social care — Zakon o digitalizaciji zdravstva (ZDigZ)
- All industries — Zakon o spremembah in dopolnitvah Zakona o evidencah na področju dela in socialne varnosti (ZEPDSV-A)
ItalyChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
- In one paragraph
- Italy does not make ordinary business data stay in Italy. European rules decide when data may leave Europe, and Italy layers its own rules on top. But the moment you sell to the Italian state — a ministry, a town hall, a hospital, a school — the picture changes completely. The most sensitive government data has to sit on machines inside Italy, run from Italy.
- The catch
- "Italy has no data localisation" holds right up until your customer is a public body. Italian government data is sorted into ordinary, critical and strategic. Strategic data belongs on Italian soil under Italian operational control; critical data may not go on a public cloud outside Europe. On top of that, a cloud provider needs a licence from the national cyber agency before any public body is allowed to buy from it at all. Separately, telecoms companies must keep call and connection records for years, and the government can attach storage-location conditions to fifth-generation mobile and cloud contracts case by case.
- Does this apply to me?
- Yes, it reaches you with no office in Italy. European law applies to any organisation anywhere that offers goods or services to people in Italy, or that monitors what they do online. There is no size or revenue threshold to duck under. If you have no branch anywhere in Europe, you must appoint a written representative based in Europe, and people and regulators can go to that representative instead of chasing you abroad.High confidence
- Can the data leave the country?
- For a normal private company, yes — with paperwork, exactly as anywhere else in Europe. Italy has no general law saying personal data must be stored in Italy. The real walls are in one place: anything sold to or run by the Italian public sector. Government data is graded ordinary, critical or strategic, and the top two grades cannot sit on a public cloud outside Europe, with strategic data confined to infrastructure inside Italy and operated from Italy.High confidence
- What do I have to do to send it abroad?
- Three routes, and they are European rather than Italian. Best case, the destination is on Europe's official approved list and you need nothing extra. Otherwise you sign Europe's standard contract with the recipient, or get group-wide internal rules approved by a regulator. With the last two you must also write down an assessment of whether the destination country's surveillance laws would undermine the protection. Italy adds no extra permission step, but it does add a criminal offence for getting it badly wrong.High confidence
- Who enforces this — and are they actually working?
- The Italian data protection authority, known as the Garante, and it is one of the busiest and boldest regulators in Europe. In 2025 alone it took 807 decisions, of which 506 were corrective or punitive, ran 130 inspections and collected more than 37 million euros (about 41 million dollars) in fines. It was the first regulator in the world to order a temporary halt to a major chatbot service, and it has since blocked or restricted several artificial intelligence products. Cybersecurity is enforced by a separate agency.High confidence
- How long must I keep it, and when must I delete it?
- Both directions, and they pull hard against each other. The floors: telephone records must be kept 24 months, internet connection records 12 months, unanswered calls 30 days, and a separate six-year rule applies for terrorism and serious crime. Health records in the national system are erased 30 years after the patient dies. The ceiling is much tighter than people expect: the regulator says the technical logs behind staff email may normally be kept for no more than 21 days.High confidence
- What happens when something goes wrong?
- Count at least three clocks, and they run at the same time. A personal data breach goes to the Garante within 72 hours, and to the people affected without delay where the risk to them is high. If you are in scope of Italy's network security regime, a first warning goes to the national cyber agency within 24 hours, a fuller notification within 72 hours, and a final report within a month. Organisations inside the national cyber perimeter have a much shorter fuse, reported as six hours.Medium confidence
- What's the trap?
- Five. One: staff email logs may normally be kept only 21 days, and a regional government was punished in 2025 for keeping 90. Two: before you install any tool that could monitor employees, you need a union agreement or a labour inspectorate permit, and skipping it is a criminal matter, not a fine. Three: some data offences in Italy carry prison, not just penalties. Four: children can consent at 14 in Italy, not 16. Five: the widely reported rule forcing public-sector artificial intelligence onto Italian servers was deleted before the law passed, so citing it is wrong.High confidence
- What's about to change?
- Two firm dates and one open wound. By 31 October 2026 organisations in Italy's network security regime must have their basic security measures in place and evidenced. From 12 January 2027 every cloud provider must charge nothing for switching away or pulling data out. The open wound is the Italian regulator itself: one of four board seats has been empty since January 2026 and Parliament has not filled it.Medium confidence
- Hardest industry wall
- Government — Regolamento unico per le infrastrutture e i servizi cloud per la PA — Determinazione ACN n. 21007/24