Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
ThailandChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
In one paragraph
Thailand does not make you keep personal data inside the country, but data cannot leave until you have picked and documented a legal route. The regulator never published a list of approved destination countries, so consent and written safeguards do all the work. A foreign company selling into Thailand needs a named representative living there. Getting it wrong can mean fines, double damages, and in the worst cases jail.
The catch
The permissive headline is about residency only. The burden is high and the pain is elsewhere: a person in Thailand who answers for you personally, parental consent for anyone under twenty in many cases, 90-day traffic logs that catch any business offering guest wi-fi, compensation owed even when you were not careless, and a technology-crime regime that forces banks and telecoms companies to hand customer data into a government-run exchange. Payments, government workloads and digital platforms each add their own regulator gate on top.
Does this apply to me?
Yes. The privacy law reaches a company with no office in Thailand if it offers goods or services to people who are in Thailand, or if it tracks what those people do. Payment is irrelevant — a free service counts. There is no revenue or headcount floor to fall below. A foreign company caught this way must appoint, in writing, a representative who is physically in Thailand and who can be held answerable with no cap on liability.High confidence
Can the data leave the country?
Yes, in most cases. Thailand does not make companies keep a copy of personal data inside the country. But data cannot simply leave: you must first have a legal route, and the regulator has never published a list of approved destination countries, so the 'this country is safe enough' route is unusable in practice. Everyone falls back on informed consent, contract necessity, approved group-wide rules, or their own written safeguards. Several industries add a second gate on top, described below.High confidence
What do I have to do to send it abroad?
There is no permission slip to apply for and no banned-country list. You pick a route and document it before the data moves. The routes are: the destination is judged to have good enough protection; one of six statutory exceptions such as informed consent; group-wide rules certified by the regulator; or your own written safeguards that a person in Thailand could actually enforce. The 'good enough country' route is dead on arrival because the regulator has published no approved list, so in practice the safeguards route and consent do all the work.Medium confidence
Who enforces this — and are they actually working?
The Office of the Personal Data Protection Committee, usually shortened to PDPC, sits under the Ministry of Digital Economy and Society. It is real and staffed: it has a serving Secretary-General, it runs walk-in complaint centres in five provinces and opened another in Ubon Ratchathani on 17 August 2026, and it is executing Cabinet-level instructions on data breaches. Complaints are decided by an Expert Committee that can order you to stop, order you to fix things, and impose fines itself. Other regulators run their own lanes: the cyber-security agency for critical infrastructure, the central bank for payments, and the electronic transactions agency for digital platforms.Medium confidence
How long must I keep it, and when must I delete it?
Thailand pushes in both directions at once. The floor: anyone who provides a computer or internet service to other people must keep traffic logs for at least 90 days, and an official can order that stretched to as much as two years. The ceiling: the privacy law makes you build a system that actually deletes personal data once your stated retention period runs out or the data is no longer needed. When the two collide, the keep-it duty wins, because the delete duty has a written carve-out for complying with law and for defending legal claims.High confidence
What happens when something goes wrong?
Count three clocks, not one. First: tell the privacy regulator about a personal data breach without delay and within 72 hours of becoming aware, unless the breach carries no risk to people; if the risk to people is high you must also tell the affected individuals, with advice on what to do, without delay. Second: if you run critical information infrastructure, a significant cyber threat must be reported to the national cyber-security agency and to your own sector regulator, and silence without good reason is itself an offence. Third: if you are a bank or a telecoms operator and you suspect technology crime, you must push customer account and transaction data into a shared government-run system immediately.High confidence
What's the trap?
Five things that are not in the brochure. Children: Thailand needs a parent's consent for a child aged ten or under, and for older teenagers too unless the act is one the law lets a minor do alone — and a person is a minor in Thailand until twenty. Jail is on the table for misusing sensitive data. You owe compensation even if you were not careless, and a court can add up to double on top. A foreign company must put a named human in Thailand with unlimited authority. And the 90-day log rule catches ordinary businesses that just offer guest wi-fi.High confidence
What's about to change?
Nothing in the next twelve months looks like a new statute. What is moving is enforcement reach. The privacy regulator is opening walk-in centres in eight provinces during 2026 to cover all five regions, which means more complaints will actually get filed. The Cabinet decided on 11 August 2026 to require multi-factor login protection across government to stop leaked passwords turning into data breaches, and the ministry is pushing the same expectation across all twenty ministries. The bigger risk is not new law but switches the government already holds and can flip without warning.Medium confidence
Hardest industry wall
None found.
JapanChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Active
In one paragraph
Japan lets personal data leave the country, but you need paperwork. Only Europe and the United Kingdom are pre-approved. For anywhere else you either sign a contract that binds the recipient to Japanese-standard protection, or you get the person's consent after telling them which country the data goes to. There is no general rule forcing data to stay in Japan.
The catch
Two things break the calm headline. If you sell to the Japanese government, the data must physically sit in Japanese data centres. And if you run a website, an app or any online service used from Japan, the telecoms law reaches you even with no office here, requires a representative in Japan, and makes leaking a communication a criminal offence rather than a fine.
Does this apply to me?
Yes. Japan's privacy law reaches a foreign company with no office and no staff in Japan, as long as it handles the personal information of people in Japan while supplying them goods or services. There is no size, revenue or headcount threshold to fall below. Unlike Europe, the privacy law does not make you appoint a representative in Japan — but the telecoms law does, if your service counts as a telecommunications service.High confidence
Can the data leave the country?
Yes, with paperwork. Japan's general rating is conditional: personal data may go abroad once you have one of three things in place. There is no across-the-board law keeping data in Japan, and no financial, insurance, securities or health localisation rule of the kind India or China have — we searched for one and did not find it. The real wall is government work: anything running on the national Government Cloud must sit in data centres inside Japan.High confidence
What do I have to do to send it abroad?
The model is an allowlist, and the list has exactly two entries: the European Union and the United Kingdom. Send data there and it is treated almost like a domestic transfer. For every other destination you need one of two things instead. Either the recipient is contractually bound to protect the data to Japanese standards and you keep checking that it does, or you get the person's consent after first telling them the destination country, what its privacy law is like, and what the recipient will do to protect the data.High confidence
Who enforces this — and are they actually working?
The Personal Information Protection Commission, and it is genuinely working. It has a chair, eight commissioners and a staff ceiling of 231 people. In the year to March 2025 it handled just over 19,000 breach reports, gave 395 pieces of formal guidance and made one recommendation. In the first six months of the following year it sharpened up: two recommendations and its first emergency order, against a company misusing personal information. What it cannot do yet is fine you — Japan has no administrative money penalty for privacy breaches until the 2026 amendment starts.High confidence
How long must I keep it, and when must I delete it?
The floor is firm and the ceiling is soft. Tax law makes you keep books and records for seven years, stretching to ten if you carry a loss forward. Company accounting books run ten years. Against that, the privacy law only asks you to try to delete personal data once you no longer need it — it is a best-efforts duty, not a hard deadline. So when the two collide, the keep-it rule wins in practice.Medium confidence
What happens when something goes wrong?
Count three clocks. For a personal data breach you file a first report to the privacy regulator within three to five days of finding out, and a full report within 30 days — 60 days if someone did it on purpose. You must also tell the people affected. Critical infrastructure operators have a separate cyber incident duty with a report to the government within 30 days. Telecoms operators report leaks of communications to the communications ministry on their own timetable.High confidence
What's the trap?
Five. (1) Putting data on a foreign server is often not a 'transfer' at all — if the provider is contractually barred from touching it — but you then have to work out that country's privacy law and publish the country's name to your users. Most people miss this. (2) The privacy law has no fines: the sanctions are criminal, and a company can be fined about $650,000 for a staff member stealing a customer database. (3) Leaking a communication is a crime punishable with prison, and telecoms staff face a longer term than outsiders. (4) The telecoms rules catch ordinary websites and apps, not just phone companies, and reach foreign operators with no office in Japan. (5) Consent to send data 'overseas' is not valid — you have to name the country.High confidence
What's about to change?
The big one has already passed. On 17 July 2026 Japan published a large amendment to its privacy law. It introduces the country's first money penalty for privacy breaches, sets 16 as the age below which a guardian must be involved, adds rules for face and other biometric data, and raises the criminal penalties. It is not in force yet: the government has up to two years to switch it on by order, and no date has been announced. The other thing to watch is the new cyber defence law, which is being switched on in stages through 2027.High confidence
Hardest industry wall
  • Government デジタル庁におけるガバメントクラウド等の整備のためのクラウドサービスの提供 — 令和8年度募集 調達仕様書