Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
Trinidad and TobagoChecked 19 August 2026
Depends on your industryWork: MediumEnforcement: Dormant
- In one paragraph
- Trinidad and Tobago passed a privacy law in 2011 and then switched on only a small piece of it. The privacy principles apply on paper, but the parts that create duties for companies, duties for government bodies, and any punishment were never brought into force. No Information Commissioner has ever been appointed. The real rules come from the Central Bank, the telecoms regulator and money-laundering law.
- The catch
- The relaxed general picture stops at the door of four industries. Banks, insurers and payment firms follow Central Bank rules that say you should only send data to countries with protection equal to or better than Trinidad and Tobago's, and must tell the Central Bank within 24 hours of a cyber incident. Telephone and internet companies carry a confidentiality duty in their operating licence and must be able to help police intercept traffic. Gambling operators face a rule that keeps records physically on the licensed premises, though that rule is not switched on yet. Government bodies face a strict keep-it-in-country rule that is also not switched on. Check your industry before you rely on the headline.
- Does this apply to me?
- Almost certainly not in any way you could be punished for. The privacy law does contain a clause that reaches anyone who collects personal information from people in Trinidad and Tobago, or who uses a local internet or phone company to do it, even with no office there. That clause has never been switched on. There is no size or revenue threshold and no requirement to appoint a local representative. If you are a bank, insurer, telephone company or gambling operator, you need a local licence anyway, and that licence is what actually binds you.High confidence
- Can the data leave the country?
- In general yes, and nobody will stop you. The one cross-border sentence that is actually in force says data sent abroad must go somewhere with protection comparable to Trinidad and Tobago's, and that an official list of approved countries must be published. That list has never been published, because the official who would publish it has never been appointed. So the rule is a locked door with nobody holding the key. Four industries are different and are set out below.High confidence
- What do I have to do to send it abroad?
- On paper the model is an approved-country list, which normally means you cannot send data anywhere until the government names the destination. In practice the list has never been published, and there is no regulator to publish it or to complain to, so the model is unenforced. If you are supervised by the Central Bank, the practical test is different and real: you must satisfy yourself the destination protects data at least as well as Trinidad and Tobago does, get your customer's consent, and write the right terms into the contract.High confidence
- Who enforces this — and are they actually working?
- Nobody, for general privacy. The law creates an Office of the Information Commissioner and that office has legally existed since January 2012, but no Commissioner has ever been appointed and the office has never been staffed. In January 2023 the responsible government minister told the Senate he regretted that the office 'has not yet been fully operationalized'. Nothing has changed since. The bodies that do enforce data-adjacent rules are the Central Bank for financial firms, the telecoms authority for phone and internet companies, and the money-laundering unit for record-keeping.High confidence
- How long must I keep it, and when must I delete it?
- The floors are real and the ceiling is not. If you handle money you must keep transaction records, customer identity records, account files and correspondence for six years, and investment firms must keep their books for at least six years too. Electronic money issuers must keep customer and transaction files for seven years. Gambling licensees will have to keep records seven years once that part of the law starts. The only delete-by rule says personal information should be kept no longer than needed for the purpose it was collected for, and nobody enforces it, so when a keep-it rule and a delete-it rule clash, the keep-it rule wins in practice.High confidence
- What happens when something goes wrong?
- There is no general duty to report a data breach to anyone, and no duty to tell the people affected. That is the single biggest gap in the country's rules. If the Central Bank regulates you, there is a hard clock: alert the Central Bank within 24 hours of becoming aware of a cyber incident, and file the full report within 72 hours. The national cyber team accepts reports from anyone but cannot compel them. So most organisations have zero clocks and financial firms have two.High confidence
- What's the trap?
- Five things bite people here. A law that looks binding is mostly asleep. A second law you would assume protects online consumers is also asleep. Phone and internet companies can be ordered to go and collect data they do not even hold, and are forbidden from telling anyone. The country has been under a state of emergency, and emergency orders can authorise the searching of seized computers and phones. And the punishment written into the privacy law includes prison and a fine of up to a tenth of company turnover, which would be severe if it were ever switched on.High confidence
- What's about to change?
- One new law is signed and waiting. In May 2026 Parliament passed a law on airline and ship passenger data that sets seven-year retention, six-month anonymisation of booking data, and conditions on sending that data to other countries. It has been signed by the President but not switched on. No bill to fix or replace the 2011 privacy law has been introduced. The bigger risk is not new legislation at all: the President can switch on the sleeping parts of the existing privacy law at any moment, with no consultation and no notice.High confidence
- Hardest industry wall
- Online gaming — Gambling (Gaming and Betting) Control Act, 2021, Part III and Schedule 3
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
- The catch
- The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
- Does this apply to me?
- Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
- Can the data leave the country?
- Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
- What do I have to do to send it abroad?
- The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
- Who enforces this — and are they actually working?
- The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
- What happens when something goes wrong?
- There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
- What's the trap?
- Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
- What's about to change?
- Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
- Hardest industry wall
- Telecoms — Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
- E-commerce — Loi n° 18-05 relative au commerce electronique
- Government — Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees