Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
TaiwanChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Taiwan lets personal data leave the country freely unless the ministry that regulates your industry has issued an order stopping it. There is no single privacy regulator: each industry ministry polices its own sector, and each has written its own security and breach-reporting rules. A big reform that would create one national regulator was passed in November 2025 but has never been switched on.
The catch
The relaxed headline stops being true the moment you touch health records, national health insurance data, banking or telecoms. Hospital data held in the cloud must physically sit in Taiwan. National health insurance records cannot be released to any organisation set up outside Taiwan at all. Banks need the financial regulator's permission before major consumer-finance systems go offshore, and must keep a backup of important customer data in Taiwan if they do.
Does this apply to me?
Yes. Taiwan's privacy law reaches a foreign company with no office and no staff in Taiwan. The law says plainly that it also applies to organisations outside Taiwan that collect, process or use the personal data of Taiwanese people. There is no revenue or headcount threshold to fall below, and the law does not require you to appoint a local representative.High confidence
Can the data leave the country?
In general, yes. Taiwan's privacy law does not ask you to sign anything or get anyone's permission before sending personal data abroad. Instead it gives each industry ministry the power to order that data in its sector may not go to a particular country. But four sectors have real walls, and in two of them the wall is absolute.High confidence
What do I have to do to send it abroad?
Under the general law, nothing. No standard contract, no government approval, no adequacy finding, no consent form. The model is a blocklist run sector by sector: you may send data anywhere unless the ministry that supervises your industry has issued an order stopping it. Your real job is to find out which ministry supervises you and check whether it has issued one.High confidence
Who enforces this — and are they actually working?
There is no national privacy regulator in Taiwan today. A Personal Data Protection Commission is named in the law as the authority in charge, but that provision has never been switched on, the law creating the Commission is still only a bill, and what exists is a preparatory office that writes draft rules and cannot fine anyone. Enforcement is done instead by whichever ministry regulates your industry, plus city and county governments, and those bodies are genuinely active.High confidence
How long must I keep it, and when must I delete it?
Both directions apply, and the floors are set by other laws, not the privacy law. Accounting vouchers must be kept at least five years and account books and financial statements at least ten years. Medical records must be kept at least seven years, and for children until seven years after they turn eighteen; records from human trials must be kept forever. Going the other way, you must delete personal data once the purpose you collected it for has gone or the period you set has run out.High confidence
What happens when something goes wrong?
Count at least three clocks, and the fastest is one hour. Telecoms companies and larger internet providers must tell the communications regulator within one hour of learning about a major personal data incident, then file a full report within seventy-two hours. Government bodies and designated critical infrastructure operators also have one hour, under the separate cyber security law. Financial firms get seventy-two hours. And under the privacy law itself you must tell the affected people once you have established the facts, with no fixed deadline attached.High confidence
What's the trap?
Five things that will cost someone their weekend. First, the official English text of the privacy law on the government's own website includes provisions that are not law yet, including the one naming the national regulator. Second, breaking a cross-border transfer order is a crime, not a fine — up to five years in prison. Third, there is no single regulator to ask; your duties depend on which ministry supervises you. Fourth, a bank asked for Taiwanese customer data by a foreign financial regulator must get Taiwan's regulator's permission first. Fifth, if you are sued, you have to prove you were not at fault.High confidence
What's about to change?
One thing has already landed and one is waiting on a switch. The National Health Insurance Data Management Act came into force on 10 August 2026, and it gives people a short window to opt their health records out of research use before silence counts as agreement. Separately, the big privacy reform passed in November 2025 is sitting on the shelf: the Cabinet can bring it into force whenever it likes, by a single order, with no consultation.High confidence
Hardest industry wall
  • Health and social care 醫療機構電子病歷製作及管理辦法 (Regulations Governing the Production and Management of Electronic Medical Records by Medical Institutions)
  • Health and social care 全民健康保險資料管理條例 (National Health Insurance Data Management Act)
  • Banking 金融機構作業委託他人處理內部作業制度及程序辦法 (Regulations Governing Internal Operating Systems and Procedures for the Outsourcing of Financial Institution Operation)
HungaryChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
In one paragraph
Hungary has no general rule that data must stay in the country. It runs on the European rulebook: you may send data abroad if you have the right legal paperwork in place. Hungary used to force state registers to be processed on Hungarian soil, but that rule was scrapped in April 2024. The privacy regulator is real, staffed and issuing decisions, though its fines are small by European standards.
The catch
Two things break the easy answer. Since January 2025 a large slice of the economy — energy, transport, banking, health, water, digital infrastructure, waste, manufacturing and most of the public sector — may only use a shared cloud or process data outside Hungary after completing a formal data classification under the cybersecurity law. And an online casino serving Hungarian players must keep its game server inside the European Economic Area, full stop.
Does this apply to me?
Yes. A company with no office in Hungary is still caught if it offers goods or services to people in Hungary or watches their behaviour, because the European privacy rules reach outside Europe. There is no revenue or headcount threshold to hide under. If you have no establishment anywhere in Europe you must appoint a written representative inside Europe, and Hungary is a perfectly ordinary place to put one.High confidence
Can the data leave the country?
Yes, on the normal European terms — nothing in general Hungarian law says data must be stored in Hungary. This is a change worth noticing: the rule that state registers could only be processed on Hungarian soil was repealed with effect from 1 April 2024, and the law that replaced it has no territorial restriction at all. Two sectors override this. An online casino must keep its game server inside the European Economic Area. And any company or public body inside the scope of Hungary's cybersecurity law must finish a formal data classification before it uses a shared cloud service or processes data abroad.Medium confidence
What do I have to do to send it abroad?
You need a European transfer tool before the data leaves, and Hungary adds no extra permit, filing or fee on top. The model is an approved-list one: you may send data to a country the European Commission has declared safe, or you sign the standard European contract clauses and write down a risk assessment of the destination. There is no Hungarian government sign-off, and no Hungarian list of banned countries. For police, security and other work outside the European privacy rules, Hungary's own Info Act sets the conditions instead.High confidence
Who enforces this — and are they actually working?
The National Authority for Data Protection and Freedom of Information, known by its Hungarian initials NAIH, and it is genuinely working. It has published decisions right through to May 2026, released its report on 2025 activity on 30 March 2026, and issued public statements in July and August 2026. Its president is Dr Attila Peterfalvi. The catch is size, not activity: a typical fine is small — two million forint, roughly six thousand dollars, in an April 2025 data-security case.High confidence
How long must I keep it, and when must I delete it?
Hungary pushes hard in both directions. The floor is long: accounting records and vouchers must be kept for eight years, and health records for decades — the health data law works in periods of thirty years and more. The ceiling is the European rule that you delete personal data once the purpose is spent. When the two collide, the specific statutory keep-period wins, so a deletion request does not empty your ledgers or a hospital's files.Medium confidence
What happens when something goes wrong?
Count at least two clocks, and three if you are a bank. A personal data breach goes to the privacy regulator within 72 hours. A cyber incident at a company or public body covered by the cybersecurity law goes to the national incident response centre, and the European rules that Hungary is copying use a 24-hour first alert followed by a fuller report at 72 hours. Financial firms have a separate and faster set of deadlines under the European operational resilience rules.Medium confidence
What's the trap?
Five things that are not in the summary. One: mishandling personal data is a crime in Hungary, not just a fine — up to one year in prison, two years for sensitive data, three years for public officials. Two: the old rule forcing state data to stay in Hungary is dead, so quoting it makes you look out of date, while the new cybersecurity classification gate is very much alive and most checklists miss it. Three: several cybersecurity deadlines have already passed, so newly in-scope companies are late on day one. Four: an online casino's game server must sit in the European Economic Area. Five: Hungary's freedom-of-information regime can make your contract with a state body public.High confidence
What's about to change?
Three dated items. The Court of Justice will rule on Hungary's sovereignty protection law; the court's adviser said on 12 February 2026 that it breaks European law, and the judgment could land any time. From 12 January 2027 cloud providers across Europe, Hungary included, must charge nothing to move your data out. And Hungary's cybersecurity supervision moves from paperwork to inspections now that the first audit deadline of 30 June 2026 has passed.Medium confidence
Hardest industry wall
  • Online gaming 1991. evi XXXIV. torveny a szerencsejatek szervezeserol es a vegrehajtasi rendeletei (online kaszinojatek engedelyezesi feltetelei)
  • Government 2021. evi XCI. torveny a nemzeti adatvagyonrol, 13. §