Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
ThailandChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
- In one paragraph
- Thailand does not make you keep personal data inside the country, but data cannot leave until you have picked and documented a legal route. The regulator never published a list of approved destination countries, so consent and written safeguards do all the work. A foreign company selling into Thailand needs a named representative living there. Getting it wrong can mean fines, double damages, and in the worst cases jail.
- The catch
- The permissive headline is about residency only. The burden is high and the pain is elsewhere: a person in Thailand who answers for you personally, parental consent for anyone under twenty in many cases, 90-day traffic logs that catch any business offering guest wi-fi, compensation owed even when you were not careless, and a technology-crime regime that forces banks and telecoms companies to hand customer data into a government-run exchange. Payments, government workloads and digital platforms each add their own regulator gate on top.
- Does this apply to me?
- Yes. The privacy law reaches a company with no office in Thailand if it offers goods or services to people who are in Thailand, or if it tracks what those people do. Payment is irrelevant — a free service counts. There is no revenue or headcount floor to fall below. A foreign company caught this way must appoint, in writing, a representative who is physically in Thailand and who can be held answerable with no cap on liability.High confidence
- Can the data leave the country?
- Yes, in most cases. Thailand does not make companies keep a copy of personal data inside the country. But data cannot simply leave: you must first have a legal route, and the regulator has never published a list of approved destination countries, so the 'this country is safe enough' route is unusable in practice. Everyone falls back on informed consent, contract necessity, approved group-wide rules, or their own written safeguards. Several industries add a second gate on top, described below.High confidence
- What do I have to do to send it abroad?
- There is no permission slip to apply for and no banned-country list. You pick a route and document it before the data moves. The routes are: the destination is judged to have good enough protection; one of six statutory exceptions such as informed consent; group-wide rules certified by the regulator; or your own written safeguards that a person in Thailand could actually enforce. The 'good enough country' route is dead on arrival because the regulator has published no approved list, so in practice the safeguards route and consent do all the work.Medium confidence
- Who enforces this — and are they actually working?
- The Office of the Personal Data Protection Committee, usually shortened to PDPC, sits under the Ministry of Digital Economy and Society. It is real and staffed: it has a serving Secretary-General, it runs walk-in complaint centres in five provinces and opened another in Ubon Ratchathani on 17 August 2026, and it is executing Cabinet-level instructions on data breaches. Complaints are decided by an Expert Committee that can order you to stop, order you to fix things, and impose fines itself. Other regulators run their own lanes: the cyber-security agency for critical infrastructure, the central bank for payments, and the electronic transactions agency for digital platforms.Medium confidence
- How long must I keep it, and when must I delete it?
- Thailand pushes in both directions at once. The floor: anyone who provides a computer or internet service to other people must keep traffic logs for at least 90 days, and an official can order that stretched to as much as two years. The ceiling: the privacy law makes you build a system that actually deletes personal data once your stated retention period runs out or the data is no longer needed. When the two collide, the keep-it duty wins, because the delete duty has a written carve-out for complying with law and for defending legal claims.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. First: tell the privacy regulator about a personal data breach without delay and within 72 hours of becoming aware, unless the breach carries no risk to people; if the risk to people is high you must also tell the affected individuals, with advice on what to do, without delay. Second: if you run critical information infrastructure, a significant cyber threat must be reported to the national cyber-security agency and to your own sector regulator, and silence without good reason is itself an offence. Third: if you are a bank or a telecoms operator and you suspect technology crime, you must push customer account and transaction data into a shared government-run system immediately.High confidence
- What's the trap?
- Five things that are not in the brochure. Children: Thailand needs a parent's consent for a child aged ten or under, and for older teenagers too unless the act is one the law lets a minor do alone — and a person is a minor in Thailand until twenty. Jail is on the table for misusing sensitive data. You owe compensation even if you were not careless, and a court can add up to double on top. A foreign company must put a named human in Thailand with unlimited authority. And the 90-day log rule catches ordinary businesses that just offer guest wi-fi.High confidence
- What's about to change?
- Nothing in the next twelve months looks like a new statute. What is moving is enforcement reach. The privacy regulator is opening walk-in centres in eight provinces during 2026 to cover all five regions, which means more complaints will actually get filed. The Cabinet decided on 11 August 2026 to require multi-factor login protection across government to stop leaked passwords turning into data breaches, and the ministry is pushing the same expectation across all twenty ministries. The bigger risk is not new law but switches the government already holds and can flip without warning.Medium confidence
- Hardest industry wall
- None found.
United StatesChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- In general the United States lets data go anywhere. There is no national privacy law and no permit is needed to move data abroad. Two things bite hard. Six countries are effectively off limits for large amounts of sensitive data, with prison sentences attached. And anything connected to government work must physically stay on American soil.
- The catch
- The open headline stops the moment you touch one of six areas: government contracting, police records, federal tax records, defence technical data, telecom licences, and bulk sensitive data flowing to China, Russia, Iran, North Korea, Cuba or Venezuela. Also note that the rule that actually binds you is almost always a state law or an industry regulator's rule, not a national privacy act. There isn't one.
- Does this apply to me?
- Yes. American rules reach a foreign company with no office in the country. California's privacy law applies to any for-profit business that 'does business in California' and crosses one of three thresholds, and physical presence is not one of them. The children's rule covers foreign websites aimed at American children. No state and no federal law requires you to appoint a local representative — a real difference from Europe.High confidence
- Can the data leave the country?
- It depends entirely on your industry, so the single national answer is misleading. For ordinary consumer or employee data, yes — send it anywhere, no paperwork. But six sectors have hard walls. Government contracting, police data, federal tax data and defence work require the data to physically stay in the United States. Telecom licences restrict which foreign staff may even look at records. And for anyone, sending large volumes of sensitive data to six named countries is now a crime.High confidence
- What do I have to do to send it abroad?
- For ordinary data, nothing. No standard contract, no government approval, no destination approval list. The model is a blocklist and it is now populated: six countries are named. Before you move large volumes of sensitive data, your only real job is to work out whether a country of concern, or a company or person they control, could end up with access — including through a vendor, an investor or an employee.High confidence
- Who enforces this — and are they actually working?
- Nobody, and everybody. There is no national privacy regulator. Instead the consumer protection regulator, the health department, the securities regulator, the communications regulator, the Justice Department, all fifty state attorneys general and one dedicated state privacy agency each enforce a slice. Almost all of them are visibly working right now. The one exception is the new national data transfer programme: it is staffed and issuing guidance but has published no enforcement action yet.High confidence
- How long must I keep it, and when must I delete it?
- There is a strong floor and a weak but growing ceiling. Investment firms must keep some books for six years and most others for three, with the first two years easy to reach. Health providers keep their paperwork for six years. In the other direction, state privacy laws now force you to publish how long you keep each type of data and to stop keeping it longer than you said, and since April 2026 children's data may no longer be kept indefinitely. Where a keep-it rule and a delete-it rule collide, the keep-it rule wins: every state law carves out data you are required by law to retain.High confidence
- What happens when something goes wrong?
- Count the clocks — there are at least seven, and they disagree. New York financial firms: 72 hours to the state regulator, and only 24 hours to report paying a ransom. Telecom carriers: seven working days to the police agencies and the communications regulator, and you may not warn customers until seven working days after that. Investment and finance firms: 30 days to affected customers. Health organisations: 60 days. Texas and many other states: 30 days to the state attorney general. Listed companies: four working days to disclose a material incident. The overlap, not any single deadline, is what people fail.High confidence
- What's the trap?
- Five that cost people their weekend. One: the national data transfer programme carries prison — up to twenty years for a deliberate breach. Two: Illinois lets individuals sue over fingerprints and face scans with fixed damages per person, no proof of harm needed, and that is where the largest privacy payouts happen. Three: the children's rule uses under 13, but several state laws use under 18, so a single age gate will not do. Four: government work means American soil, and police data allows only the United States, its territories, tribal lands and Canada. Five: a rule can be printed in the law book and still be unenforceable, because a court has blocked it.High confidence
- What's about to change?
- Four things in the next twelve months. The national critical infrastructure reporting rule should be finalised in late 2026, which will switch on a 72-hour incident clock and a 24-hour ransom-payment clock for a very wide range of businesses. California's rules on automated decision-making bite on 1 January 2027. The open banking rule is being rewritten after a court blocked it. And a federal privacy bill is moving in Congress, but it is only a bill and binds nobody.High confidence
- Hardest industry wall
- Government — Criminal Justice Information Services (CJIS) Security Policy
- Government — Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies
- Defence — Defense Federal Acquisition Regulation Supplement clause 252.239-7010, Cloud Computing Services
- Telecoms — National security agreement / letter of assurance conditioning a section 214 authorisation, reviewed by the Committee for the Assessment of Foreign Participation in the United States Telecommunications Services Sector