Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
ThailandChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
In one paragraph
Thailand does not make you keep personal data inside the country, but data cannot leave until you have picked and documented a legal route. The regulator never published a list of approved destination countries, so consent and written safeguards do all the work. A foreign company selling into Thailand needs a named representative living there. Getting it wrong can mean fines, double damages, and in the worst cases jail.
The catch
The permissive headline is about residency only. The burden is high and the pain is elsewhere: a person in Thailand who answers for you personally, parental consent for anyone under twenty in many cases, 90-day traffic logs that catch any business offering guest wi-fi, compensation owed even when you were not careless, and a technology-crime regime that forces banks and telecoms companies to hand customer data into a government-run exchange. Payments, government workloads and digital platforms each add their own regulator gate on top.
Does this apply to me?
Yes. The privacy law reaches a company with no office in Thailand if it offers goods or services to people who are in Thailand, or if it tracks what those people do. Payment is irrelevant — a free service counts. There is no revenue or headcount floor to fall below. A foreign company caught this way must appoint, in writing, a representative who is physically in Thailand and who can be held answerable with no cap on liability.High confidence
Can the data leave the country?
Yes, in most cases. Thailand does not make companies keep a copy of personal data inside the country. But data cannot simply leave: you must first have a legal route, and the regulator has never published a list of approved destination countries, so the 'this country is safe enough' route is unusable in practice. Everyone falls back on informed consent, contract necessity, approved group-wide rules, or their own written safeguards. Several industries add a second gate on top, described below.High confidence
What do I have to do to send it abroad?
There is no permission slip to apply for and no banned-country list. You pick a route and document it before the data moves. The routes are: the destination is judged to have good enough protection; one of six statutory exceptions such as informed consent; group-wide rules certified by the regulator; or your own written safeguards that a person in Thailand could actually enforce. The 'good enough country' route is dead on arrival because the regulator has published no approved list, so in practice the safeguards route and consent do all the work.Medium confidence
Who enforces this — and are they actually working?
The Office of the Personal Data Protection Committee, usually shortened to PDPC, sits under the Ministry of Digital Economy and Society. It is real and staffed: it has a serving Secretary-General, it runs walk-in complaint centres in five provinces and opened another in Ubon Ratchathani on 17 August 2026, and it is executing Cabinet-level instructions on data breaches. Complaints are decided by an Expert Committee that can order you to stop, order you to fix things, and impose fines itself. Other regulators run their own lanes: the cyber-security agency for critical infrastructure, the central bank for payments, and the electronic transactions agency for digital platforms.Medium confidence
How long must I keep it, and when must I delete it?
Thailand pushes in both directions at once. The floor: anyone who provides a computer or internet service to other people must keep traffic logs for at least 90 days, and an official can order that stretched to as much as two years. The ceiling: the privacy law makes you build a system that actually deletes personal data once your stated retention period runs out or the data is no longer needed. When the two collide, the keep-it duty wins, because the delete duty has a written carve-out for complying with law and for defending legal claims.High confidence
What happens when something goes wrong?
Count three clocks, not one. First: tell the privacy regulator about a personal data breach without delay and within 72 hours of becoming aware, unless the breach carries no risk to people; if the risk to people is high you must also tell the affected individuals, with advice on what to do, without delay. Second: if you run critical information infrastructure, a significant cyber threat must be reported to the national cyber-security agency and to your own sector regulator, and silence without good reason is itself an offence. Third: if you are a bank or a telecoms operator and you suspect technology crime, you must push customer account and transaction data into a shared government-run system immediately.High confidence
What's the trap?
Five things that are not in the brochure. Children: Thailand needs a parent's consent for a child aged ten or under, and for older teenagers too unless the act is one the law lets a minor do alone — and a person is a minor in Thailand until twenty. Jail is on the table for misusing sensitive data. You owe compensation even if you were not careless, and a court can add up to double on top. A foreign company must put a named human in Thailand with unlimited authority. And the 90-day log rule catches ordinary businesses that just offer guest wi-fi.High confidence
What's about to change?
Nothing in the next twelve months looks like a new statute. What is moving is enforcement reach. The privacy regulator is opening walk-in centres in eight provinces during 2026 to cover all five regions, which means more complaints will actually get filed. The Cabinet decided on 11 August 2026 to require multi-factor login protection across government to stop leaked passwords turning into data breaches, and the ministry is pushing the same expectation across all twenty ministries. The bigger risk is not new law but switches the government already holds and can flip without warning.Medium confidence
Hardest industry wall
None found.
ItalyChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Aggressive
In one paragraph
Italy does not make ordinary business data stay in Italy. European rules decide when data may leave Europe, and Italy layers its own rules on top. But the moment you sell to the Italian state — a ministry, a town hall, a hospital, a school — the picture changes completely. The most sensitive government data has to sit on machines inside Italy, run from Italy.
The catch
"Italy has no data localisation" holds right up until your customer is a public body. Italian government data is sorted into ordinary, critical and strategic. Strategic data belongs on Italian soil under Italian operational control; critical data may not go on a public cloud outside Europe. On top of that, a cloud provider needs a licence from the national cyber agency before any public body is allowed to buy from it at all. Separately, telecoms companies must keep call and connection records for years, and the government can attach storage-location conditions to fifth-generation mobile and cloud contracts case by case.
Does this apply to me?
Yes, it reaches you with no office in Italy. European law applies to any organisation anywhere that offers goods or services to people in Italy, or that monitors what they do online. There is no size or revenue threshold to duck under. If you have no branch anywhere in Europe, you must appoint a written representative based in Europe, and people and regulators can go to that representative instead of chasing you abroad.High confidence
Can the data leave the country?
For a normal private company, yes — with paperwork, exactly as anywhere else in Europe. Italy has no general law saying personal data must be stored in Italy. The real walls are in one place: anything sold to or run by the Italian public sector. Government data is graded ordinary, critical or strategic, and the top two grades cannot sit on a public cloud outside Europe, with strategic data confined to infrastructure inside Italy and operated from Italy.High confidence
What do I have to do to send it abroad?
Three routes, and they are European rather than Italian. Best case, the destination is on Europe's official approved list and you need nothing extra. Otherwise you sign Europe's standard contract with the recipient, or get group-wide internal rules approved by a regulator. With the last two you must also write down an assessment of whether the destination country's surveillance laws would undermine the protection. Italy adds no extra permission step, but it does add a criminal offence for getting it badly wrong.High confidence
Who enforces this — and are they actually working?
The Italian data protection authority, known as the Garante, and it is one of the busiest and boldest regulators in Europe. In 2025 alone it took 807 decisions, of which 506 were corrective or punitive, ran 130 inspections and collected more than 37 million euros (about 41 million dollars) in fines. It was the first regulator in the world to order a temporary halt to a major chatbot service, and it has since blocked or restricted several artificial intelligence products. Cybersecurity is enforced by a separate agency.High confidence
How long must I keep it, and when must I delete it?
Both directions, and they pull hard against each other. The floors: telephone records must be kept 24 months, internet connection records 12 months, unanswered calls 30 days, and a separate six-year rule applies for terrorism and serious crime. Health records in the national system are erased 30 years after the patient dies. The ceiling is much tighter than people expect: the regulator says the technical logs behind staff email may normally be kept for no more than 21 days.High confidence
What happens when something goes wrong?
Count at least three clocks, and they run at the same time. A personal data breach goes to the Garante within 72 hours, and to the people affected without delay where the risk to them is high. If you are in scope of Italy's network security regime, a first warning goes to the national cyber agency within 24 hours, a fuller notification within 72 hours, and a final report within a month. Organisations inside the national cyber perimeter have a much shorter fuse, reported as six hours.Medium confidence
What's the trap?
Five. One: staff email logs may normally be kept only 21 days, and a regional government was punished in 2025 for keeping 90. Two: before you install any tool that could monitor employees, you need a union agreement or a labour inspectorate permit, and skipping it is a criminal matter, not a fine. Three: some data offences in Italy carry prison, not just penalties. Four: children can consent at 14 in Italy, not 16. Five: the widely reported rule forcing public-sector artificial intelligence onto Italian servers was deleted before the law passed, so citing it is wrong.High confidence
What's about to change?
Two firm dates and one open wound. By 31 October 2026 organisations in Italy's network security regime must have their basic security measures in place and evidenced. From 12 January 2027 every cloud provider must charge nothing for switching away or pulling data out. The open wound is the Italian regulator itself: one of four board seats has been empty since January 2026 and Parliament has not filled it.Medium confidence
Hardest industry wall
  • Government Regolamento unico per le infrastrutture e i servizi cloud per la PA — Determinazione ACN n. 21007/24