Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
TaiwanChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Taiwan lets personal data leave the country freely unless the ministry that regulates your industry has issued an order stopping it. There is no single privacy regulator: each industry ministry polices its own sector, and each has written its own security and breach-reporting rules. A big reform that would create one national regulator was passed in November 2025 but has never been switched on.
The catch
The relaxed headline stops being true the moment you touch health records, national health insurance data, banking or telecoms. Hospital data held in the cloud must physically sit in Taiwan. National health insurance records cannot be released to any organisation set up outside Taiwan at all. Banks need the financial regulator's permission before major consumer-finance systems go offshore, and must keep a backup of important customer data in Taiwan if they do.
Does this apply to me?
Yes. Taiwan's privacy law reaches a foreign company with no office and no staff in Taiwan. The law says plainly that it also applies to organisations outside Taiwan that collect, process or use the personal data of Taiwanese people. There is no revenue or headcount threshold to fall below, and the law does not require you to appoint a local representative.High confidence
Can the data leave the country?
In general, yes. Taiwan's privacy law does not ask you to sign anything or get anyone's permission before sending personal data abroad. Instead it gives each industry ministry the power to order that data in its sector may not go to a particular country. But four sectors have real walls, and in two of them the wall is absolute.High confidence
What do I have to do to send it abroad?
Under the general law, nothing. No standard contract, no government approval, no adequacy finding, no consent form. The model is a blocklist run sector by sector: you may send data anywhere unless the ministry that supervises your industry has issued an order stopping it. Your real job is to find out which ministry supervises you and check whether it has issued one.High confidence
Who enforces this — and are they actually working?
There is no national privacy regulator in Taiwan today. A Personal Data Protection Commission is named in the law as the authority in charge, but that provision has never been switched on, the law creating the Commission is still only a bill, and what exists is a preparatory office that writes draft rules and cannot fine anyone. Enforcement is done instead by whichever ministry regulates your industry, plus city and county governments, and those bodies are genuinely active.High confidence
How long must I keep it, and when must I delete it?
Both directions apply, and the floors are set by other laws, not the privacy law. Accounting vouchers must be kept at least five years and account books and financial statements at least ten years. Medical records must be kept at least seven years, and for children until seven years after they turn eighteen; records from human trials must be kept forever. Going the other way, you must delete personal data once the purpose you collected it for has gone or the period you set has run out.High confidence
What happens when something goes wrong?
Count at least three clocks, and the fastest is one hour. Telecoms companies and larger internet providers must tell the communications regulator within one hour of learning about a major personal data incident, then file a full report within seventy-two hours. Government bodies and designated critical infrastructure operators also have one hour, under the separate cyber security law. Financial firms get seventy-two hours. And under the privacy law itself you must tell the affected people once you have established the facts, with no fixed deadline attached.High confidence
What's the trap?
Five things that will cost someone their weekend. First, the official English text of the privacy law on the government's own website includes provisions that are not law yet, including the one naming the national regulator. Second, breaking a cross-border transfer order is a crime, not a fine — up to five years in prison. Third, there is no single regulator to ask; your duties depend on which ministry supervises you. Fourth, a bank asked for Taiwanese customer data by a foreign financial regulator must get Taiwan's regulator's permission first. Fifth, if you are sued, you have to prove you were not at fault.High confidence
What's about to change?
One thing has already landed and one is waiting on a switch. The National Health Insurance Data Management Act came into force on 10 August 2026, and it gives people a short window to opt their health records out of research use before silence counts as agreement. Separately, the big privacy reform passed in November 2025 is sitting on the shelf: the Cabinet can bring it into force whenever it likes, by a single order, with no consultation.High confidence
Hardest industry wall
  • Health and social care 醫療機構電子病歷製作及管理辦法 (Regulations Governing the Production and Management of Electronic Medical Records by Medical Institutions)
  • Health and social care 全民健康保險資料管理條例 (National Health Insurance Data Management Act)
  • Banking 金融機構作業委託他人處理內部作業制度及程序辦法 (Regulations Governing Internal Operating Systems and Procedures for the Outsourcing of Financial Institution Operation)
IndonesiaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Waking up
In one paragraph
Indonesia's general privacy law lets data leave if the destination protects it about as well as Indonesia does, or you use strong safeguards, or the person agrees. Money and health are walled off. Banks, payment firms, insurers and non-bank lenders must run their systems on Indonesian soil unless the financial regulator says otherwise, and medical records must sit with a local storage provider.
The catch
The relaxed headline is true only until you touch banking, payments, insurance and other non-bank finance, electronic medical records, or public-sector systems. In those areas the servers themselves must be in Indonesia, and moving them out needs a written permission that the banking regulator may take three months to grant. The general privacy watchdog looks quiet; the financial regulators are not.
Does this apply to me?
Yes. The privacy law follows the data, not the office. It covers any organisation, inside or outside Indonesia, whose handling of personal data has legal effects in Indonesia or affects people in Indonesia. There is no size or revenue cut-off to fall below. An organisation with no presence in the country is expected to name a representative in Indonesia, and any online service used by Indonesians is also expected to register with the digital ministry, which can order internet providers to block services that do not.Medium confidence
Can the data leave the country?
In general yes, with homework. You must be able to show the destination protects personal data at a level at least equal to Indonesia's, or put binding safeguards in place, or get the person's clear agreement. That general answer stops at the door of finance, health and government. Banks, payment providers, insurers and other non-bank financial firms must keep their systems in Indonesian data centres and back-up centres, and can only go offshore with written regulator permission. Electronic medical records must be stored with a provider that has storage facilities inside Indonesia.High confidence
What do I have to do to send it abroad?
There is no published list of approved countries and no official standard contract to sign. Under the general law you assess the destination yourself, write down why it is safe enough, and keep that evidence. In finance the model is completely different: you need a real permission from the regulator before the systems move, and the banking regulator allows itself up to three months to answer once your paperwork is complete.Medium confidence
Who enforces this — and are they actually working?
It depends which rule you break. The privacy law's own watchdog is the weak spot: the law says a supervisory body must be set up by the President, and we found no government source showing it is staffed and issuing decisions as of 18 August 2026. Day to day the digital ministry handles complaints, registration and blocking. The financial regulators are a different story — the Financial Services Authority and the central bank are plainly working, and the Authority issued new binding rules as recently as July 2026.Medium confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling and they collide. The hardest floor is health: a hospital or clinic must keep an electronic medical record for at least 25 years after the patient's last visit. Company and tax paperwork must also be kept for years. The ceiling comes from the privacy law, which says personal data must be erased once the purpose is finished, the retention period ends, or the person withdraws consent. Where they clash, the specific keeping rule wins, so a patient asking for deletion does not defeat the 25-year rule.High confidence
What happens when something goes wrong?
Count at least three clocks, and the privacy one is not the fastest. Under the privacy law you have 72 hours to tell the affected people and the regulator about a personal data breach. If you are a bank, you must send the financial regulator a first alert within 24 hours of learning about a serious technology incident, and a full incident report within five working days. Other financial firms, such as insurers and lenders, have five working days. Miss the 24-hour one and the fact that you met the 72-hour one will not help you.High confidence
What's the trap?
Five things that ruin weekends. (1) In finance the wall is a permission, not a contract — moving systems abroad needs a regulator licence and the banking regulator gives itself up to three months to decide, so cloud migrations must be planned around that. (2) In health your cloud provider must have storage facilities in Indonesia, and the Ministry of Health can demand access to the whole medical record. (3) The 25-year medical record rule beats a patient's deletion request. (4) The privacy law carries prison sentences, not just fines, so directors are personally exposed. (5) A foreign company with no office still needs a named representative in Indonesia, and a consumer service that is not registered with the digital ministry can be blocked at the internet level.Medium confidence
What's about to change?
One dated change is certain: from 1 September 2026 trading in digital financial assets, including crypto, runs under the financial regulator's new rulebook, so anyone in that business should re-check where its servers and records must sit. Two things are still pending as far as we could verify: the detailed implementing regulation under the privacy law, and the presidential decision setting up the privacy watchdog itself. Both could land without warning.Medium confidence
Hardest industry wall
  • Banking Peraturan Otoritas Jasa Keuangan Nomor 11/POJK.03/2022 tentang Penyelenggaraan Teknologi Informasi oleh Bank Umum
  • Payments Peraturan Bank Indonesia Nomor 23/6/PBI/2021 tentang Penyedia Jasa Pembayaran
  • Insurance Peraturan Otoritas Jasa Keuangan Nomor 4/POJK.05/2021 tentang Penerapan Manajemen Risiko dalam Penggunaan Teknologi Informasi oleh Lembaga Jasa Keuangan Nonbank
  • Health and social care Peraturan Menteri Kesehatan Nomor 24 Tahun 2022 tentang Rekam Medis
  • Government Peraturan Pemerintah Nomor 71 Tahun 2019 tentang Penyelenggaraan Sistem dan Transaksi Elektronik
  • Mapping and location Undang-Undang Nomor 4 Tahun 2011 tentang Informasi Geospasial