Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
TurkeyChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Turkey lets personal data leave, but only after you build the paperwork yourself. The regulator has never declared a single country safe, so the approved-destination list is empty. Most companies use a government-published standard contract and must file it within five working days. The regulator is busy: it fined 876 organisations in 2025.
The catch
The general rule is 'paperwork, then you may send it'. That stops being true the moment you touch payments, banking, telecoms networks, public-sector systems or critical infrastructure. Payment and electronic money firms must keep their systems, their backups and their data inside Turkey, and may only use cloud providers the central bank has approved by name.
Does this apply to me?
Yes. A company with no office in Turkey is still caught, and it is caught harder than a local one. Any organisation based outside Turkey that decides why and how Turkish people's data is used must appoint a representative inside Turkey and sign up to the public register of data controllers before it starts processing. That representative has to be a company set up in Turkey or a Turkish citizen. Turkish small businesses can escape the register if they have fewer than 50 staff and a balance sheet under 100 million lira, but there is no such let-off for foreign companies.High confidence
Can the data leave the country?
It depends entirely on your industry, which is why Turkey is rated 'sectoral'. Under the general privacy law data may leave, but only after you put an approved safeguard in place, because the regulator has not yet declared any country safe. In payments and banking the answer flips to no: systems, backups and data have to sit inside Turkey. Public bodies, critical infrastructure, telecoms networks and health records all carry their own extra restrictions on top.High confidence
What do I have to do to send it abroad?
The model is an approved-destination list, and the list is empty. Nobody can rely on their country being blessed, so almost everyone uses one of the safeguards instead. The usual route is signing one of four standard contracts the regulator publishes, then telling the regulator within five working days of signing. Group companies can instead get binding corporate rules approved, and there is a permission route for bespoke undertakings, but that route almost always fails.High confidence
Who enforces this — and are they actually working?
The Personal Data Protection Authority, and it is fully up and running. In 2025 its board met 42 times, took 2,528 decisions, handled 12,512 complaints and fined 876 organisations a combined 352.5 million lira, which is roughly 8 million US dollars. It publishes named breach announcements most weeks. Financial, telecoms and insurance regulators enforce their own rules alongside it, and a new Cybersecurity Directorate has taken over the national cyber incident centre.High confidence
How long must I keep it, and when must I delete it?
Both directions apply, and the ceiling is unusual. Turkey does not give you a fixed number of months to delete by. Instead, once your reason for holding data runs out, you must erase it at your next scheduled clear-out, and any organisation on the public register has to publish a written retention and destruction policy setting those dates. The floor comes from ordinary commercial and tax law, which forces you to keep books and invoices for years.Medium confidence
What happens when something goes wrong?
There are at least three clocks. The privacy one is 72 hours: from the moment you learn that data has been taken unlawfully, you have three days to tell the Personal Data Protection Board, and you must tell the affected people as soon as you reasonably can. If you miss the 72 hours you must still report and explain why you were late. Companies based abroad have to report too, if people in Turkey are affected.High confidence
What's the trap?
Five things bite people. One: most fines are for paperwork, not privacy. Two thirds of the organisations fined in 2025 were punished for the public register, not for mishandling anyone's data. Two: the bespoke permission route for sending data abroad is close to a dead end, with 76 of 89 applications refused in 2025. Three: filing your standard contract invites inspection rather than closing the file. Four: your representative in Turkey must be Turkish. Five: no country is on the safe list, so there is no shortcut.High confidence
What's about to change?
Two dated items and one direction of travel. Retailers running loyalty cards have until 28 February 2027 to build a way of checking that the person at the till really owns the card, after the regulator extended the original deadline in July 2026. Public bodies are working to a July 2026 ruling on what they may publish online. And the government is pushing openly on data sovereignty, with the President chairing a cyber security meeting in May 2026 that treated data as a strategic asset.High confidence
Hardest industry wall
  • Payments Odeme ve Elektronik Para Kuruluslarinin Bilgi Sistemleri ile Odeme Hizmeti Saglayicilarinin Odeme Hizmetleri Alanindaki Veri Paylasim Servislerine Iliskin Teblig
  • Banking Bankalarin Bilgi Sistemleri ve Elektronik Bankacilik Hizmetleri Hakkinda Yonetmelik
  • Government 2019/12 sayili Bilgi ve Iletisim Guvenligi Tedbirleri Genelgesi ve Bilgi ve Iletisim Guvenligi Rehberi
United KingdomChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
In one paragraph
Data can leave the United Kingdom, but you need the right paperwork first. Sending it to Europe or to about fifteen other approved places needs nothing extra. Anywhere else needs a government-published contract and a risk check. No general law forces data to stay in Britain. The privacy regulator is busy and its fines are getting bigger.
The catch
The easy headline stops being true in three places. Telecoms operators must keep backup copies of key network information inside the United Kingdom. National Health Service patient records may only be sent to countries the United Kingdom has formally approved, which rules out the standard contract route. And government material classified SECRET or above cannot sit in public cloud at all. Everyone else can store data abroad with the right contract in place.
Does this apply to me?
Yes. British privacy law reaches a company anywhere in the world if it deliberately offers goods or services to people in the United Kingdom, or watches what they do online. There is no size or revenue floor to hide under. If you are caught and have no British office, you generally have to name a representative in the United Kingdom, unless you are a public body or your processing is rare and low risk.High confidence
Can the data leave the country?
Yes, with paperwork. The United Kingdom has no general law forcing data to stay in the country. Send it to the European Economic Area or another approved country and you need nothing extra; send it anywhere else and you need an approved contract plus a written risk assessment. Three industries are stricter: telecoms, the health service and classified government work. Banking, payments, insurance, securities, education, online gambling and mapping have no location rule that we could find.High confidence
What do I have to do to send it abroad?
The model is an approved-list one. If the destination is on the government's approved list you may send data with no extra paperwork. If it is not, you must sign the government's own contract template and run a risk assessment first. The list is well populated: the whole European Economic Area plus Andorra, Argentina, the Faroe Islands, Gibraltar, Guernsey, the Isle of Man, Israel, Jersey, New Zealand, South Korea, Switzerland and Uruguay, with partial cover for Canada, Japan and the United States.High confidence
Who enforces this — and are they actually working?
The Information Commissioner's Office, and it is very much working. It fined Capita fourteen million pounds (about $18 million) in October 2025, Reddit £14.47 million (about $18.5 million) in February 2026, and the owner of Imgur in the same month, and it issues smaller marketing fines almost monthly. Watch a quirk: a replacement body called the Information Commission legally exists but had no staff and did no work in its first financial year, so the old office is still the one that acts.High confidence
How long must I keep it, and when must I delete it?
There is no single deletion deadline. The rule is that you keep personal data only as long as you actually need it, and you must be able to explain the period you chose. Pulling the other way are minimum keeping periods: company and tax records for six years, telecoms connection records for up to twelve months if the government serves a notice, and telecoms security data for thirteen months. Where a minimum and a maximum clash, the legal duty to keep wins and you keep the data.High confidence
What happens when something goes wrong?
Count at least three clocks. Any organisation has 72 hours to tell the privacy regulator about a personal data breach, and must tell the affected people if the risk to them is high. Telecoms and internet providers also have 72 hours under the electronic communications rules — that used to be 24 hours and quietly changed on 20 August 2025. Operators of essential services such as water, energy and transport have their own 72-hour clock to their own regulator.High confidence
What's the trap?
Five. (1) A child can consent at 13 here, not 16 — but the children's design code covers everyone under 18, and the regulator fined Reddit £14.47 million (about $18.5 million) for weak age checks. (2) Telecoms firms must keep some backup data physically in Britain. (3) Health service data can only go to approved countries, so the standard contract does not help you. (4) Misusing personal data can be a crime, not just a fine. (5) The government can secretly order a company to weaken its security, and Apple is fighting one of those orders right now.Medium confidence
What's about to change?
Two things to watch in the next twelve months. A cyber security bill is going through Parliament and will widen incident reporting to data centres and managed service suppliers — it is not law yet, so do not plan as if it were. And the privacy regulator is due to be replaced by a new body called the Information Commission, but only once ministers lay the paperwork, which had not happened by mid-2026. The regulator is also writing a statutory code on artificial intelligence.High confidence
Hardest industry wall
  • Telecoms The Electronic Communications (Security Measures) Regulations 2022, with the Telecommunications Security Code of Practice 2026 (version 1.1)