Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
TurkeyChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- Turkey lets personal data leave, but only after you build the paperwork yourself. The regulator has never declared a single country safe, so the approved-destination list is empty. Most companies use a government-published standard contract and must file it within five working days. The regulator is busy: it fined 876 organisations in 2025.
- The catch
- The general rule is 'paperwork, then you may send it'. That stops being true the moment you touch payments, banking, telecoms networks, public-sector systems or critical infrastructure. Payment and electronic money firms must keep their systems, their backups and their data inside Turkey, and may only use cloud providers the central bank has approved by name.
- Does this apply to me?
- Yes. A company with no office in Turkey is still caught, and it is caught harder than a local one. Any organisation based outside Turkey that decides why and how Turkish people's data is used must appoint a representative inside Turkey and sign up to the public register of data controllers before it starts processing. That representative has to be a company set up in Turkey or a Turkish citizen. Turkish small businesses can escape the register if they have fewer than 50 staff and a balance sheet under 100 million lira, but there is no such let-off for foreign companies.High confidence
- Can the data leave the country?
- It depends entirely on your industry, which is why Turkey is rated 'sectoral'. Under the general privacy law data may leave, but only after you put an approved safeguard in place, because the regulator has not yet declared any country safe. In payments and banking the answer flips to no: systems, backups and data have to sit inside Turkey. Public bodies, critical infrastructure, telecoms networks and health records all carry their own extra restrictions on top.High confidence
- What do I have to do to send it abroad?
- The model is an approved-destination list, and the list is empty. Nobody can rely on their country being blessed, so almost everyone uses one of the safeguards instead. The usual route is signing one of four standard contracts the regulator publishes, then telling the regulator within five working days of signing. Group companies can instead get binding corporate rules approved, and there is a permission route for bespoke undertakings, but that route almost always fails.High confidence
- Who enforces this — and are they actually working?
- The Personal Data Protection Authority, and it is fully up and running. In 2025 its board met 42 times, took 2,528 decisions, handled 12,512 complaints and fined 876 organisations a combined 352.5 million lira, which is roughly 8 million US dollars. It publishes named breach announcements most weeks. Financial, telecoms and insurance regulators enforce their own rules alongside it, and a new Cybersecurity Directorate has taken over the national cyber incident centre.High confidence
- How long must I keep it, and when must I delete it?
- Both directions apply, and the ceiling is unusual. Turkey does not give you a fixed number of months to delete by. Instead, once your reason for holding data runs out, you must erase it at your next scheduled clear-out, and any organisation on the public register has to publish a written retention and destruction policy setting those dates. The floor comes from ordinary commercial and tax law, which forces you to keep books and invoices for years.Medium confidence
- What happens when something goes wrong?
- There are at least three clocks. The privacy one is 72 hours: from the moment you learn that data has been taken unlawfully, you have three days to tell the Personal Data Protection Board, and you must tell the affected people as soon as you reasonably can. If you miss the 72 hours you must still report and explain why you were late. Companies based abroad have to report too, if people in Turkey are affected.High confidence
- What's the trap?
- Five things bite people. One: most fines are for paperwork, not privacy. Two thirds of the organisations fined in 2025 were punished for the public register, not for mishandling anyone's data. Two: the bespoke permission route for sending data abroad is close to a dead end, with 76 of 89 applications refused in 2025. Three: filing your standard contract invites inspection rather than closing the file. Four: your representative in Turkey must be Turkish. Five: no country is on the safe list, so there is no shortcut.High confidence
- What's about to change?
- Two dated items and one direction of travel. Retailers running loyalty cards have until 28 February 2027 to build a way of checking that the person at the till really owns the card, after the regulator extended the original deadline in July 2026. Public bodies are working to a July 2026 ruling on what they may publish online. And the government is pushing openly on data sovereignty, with the President chairing a cyber security meeting in May 2026 that treated data as a strategic asset.High confidence
- Hardest industry wall
- Payments — Odeme ve Elektronik Para Kuruluslarinin Bilgi Sistemleri ile Odeme Hizmeti Saglayicilarinin Odeme Hizmetleri Alanindaki Veri Paylasim Servislerine Iliskin Teblig
- Banking — Bankalarin Bilgi Sistemleri ve Elektronik Bankacilik Hizmetleri Hakkinda Yonetmelik
- Government — 2019/12 sayili Bilgi ve Iletisim Guvenligi Tedbirleri Genelgesi ve Bilgi ve Iletisim Guvenligi Rehberi
AustraliaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Australia has no general rule that data must stay in the country. You may send personal information anywhere, and no destination is banned. The catch is that you stay legally responsible for whatever your overseas supplier does with it. Small businesses under A$3 million turnover are exempt from the main privacy law. Specific industries are far stricter, and one of them carries a prison sentence.
- The catch
- The relaxed headline stops the moment you touch six areas. National electronic health records may not leave Australia at all, and taking them offshore is a crime punishable by five years in prison. Banks and insurers must tell the banking regulator before any offshore arrangement. Open banking data, critical infrastructure data, Australian Government hosting and Queensland state government data each have their own rules. Check your sector before you believe the headline.
- Does this apply to me?
- Yes, it reaches you even with no office in Australia. The national privacy law applies to any organisation that carries on business in Australia, whether or not the data is collected or stored here. But Australia has something most countries do not: a real size threshold you can fall below. A business with annual turnover of A$3 million (about US$2 million) or less is generally exempt. That exemption has big holes: it does not apply if you provide a health service, if you buy or sell personal information, or if you supply services under a federal government contract. No local representative and no registration are required.High confidence
- Can the data leave the country?
- In general, yes. Australia has no national law saying personal data must be kept in the country, and no country is blacklisted. You can pick any cloud region you like. What you cannot do is hand off the risk: if your overseas supplier does something with the data that would break Australian rules, the law treats that as your own breach. The hard walls are industry by industry, and the health one is absolute.High confidence
- What do I have to do to send it abroad?
- Before data leaves, you must take reasonable steps to make sure the overseas recipient will handle it the Australian way. In practice that means a contract with the right promises in it. There is no government form to file, no approval to wait for, and no list of approved countries to check. A power to approve countries was switched on in December 2024, but as of today the government has not named a single one. The alternative routes are narrow: you can rely on the recipient already being covered by a substantially similar law, or on the person's informed consent after you warn them you will no longer be responsible.High confidence
- Who enforces this — and are they actually working?
- The Office of the Australian Information Commissioner. It is staffed, it has a sitting Privacy Commissioner, and it is issuing decisions. In October 2025 the Federal Court ordered a pathology company to pay A$5.8 million (about US$3.8 million), the first court penalty in the law's history. The regulator sued Optus in August 2025, settled with Meta for A$50 million in December 2024, and in June 2026 alone published formal findings against Optus, American Express and two health providers. Banking, cyber security, online safety and open banking each have their own separate regulator, and all of them are working.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling and they pull in opposite directions. The clearest floor is telecoms: phone and internet providers must keep call and connection records for two years, and must encrypt them. The general ceiling has no number attached — you must destroy or de-identify personal information once you genuinely no longer need it. Two ceilings are sharp. A social media platform must destroy age-check information as soon as it has finished using it. A digital identity provider must destroy a face or fingerprint scan immediately after the identity check is complete.High confidence
- What happens when something goes wrong?
- Count four clocks, because they run at different speeds. If you pay a ransom and your Australian turnover is above A$3 million (about US$2 million), you have 72 hours to report the payment to the government. If you run critical infrastructure, you have 12 hours for an attack that seriously hits availability, and 72 hours for a lesser one. If you are a bank, insurer or superannuation fund, you have 72 hours for a security incident and only 24 hours if a critical service goes down beyond tolerance. For an ordinary personal data breach you get up to 30 days to assess whether it is serious, then you must tell the regulator and the affected people as soon as you practically can. There is no fixed hour count for that last one, which is the part people get wrong.High confidence
- What's the trap?
- Five things that will cost you a weekend. First, moving national electronic health record data offshore is a crime, not a fine: up to five years in prison. Second, you never stop owning your supplier's mistakes — a major bank had to get a special ruling from the Privacy Commissioner just to keep processing international money transfers. Third, since December 2025 social media platforms must keep under-16s off the service and then destroy the age-check data they collected. Fourth, Queensland's rule for state government data is stricter than the national one and is hidden in section 33 of the Act, not in the numbered principles — the principle numbered 8 says there is no equivalent. Fifth, the value of a penalty unit rose to A$364 (about US$240) on 1 July 2026, so every fine figure you looked up before then is now understated.High confidence
- What's about to change?
- One date dominates: 10 December 2026. On that day privacy policies must start explaining computer-made decisions that significantly affect people, and the new Children's Online Privacy Code must be finalised and registered. The draft of that code was out for public comment from 31 March to 5 June 2026. Further out, the tougher critical infrastructure duties made in June 2026 start biting from mid-2027 and mid-2028 as their grace periods run out. Watch three switches the government already holds and can flip with no consultation.High confidence
- Hardest industry wall
- Health and social care — My Health Records Act 2012, section 77