Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
TanzaniaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Tanzania, but only after the privacy regulator grants a permit for that exact transfer. No country is pre-approved, so each move abroad is its own application. Before you process anything you must register with the regulator and name a data protection officer, who then reports every three months. Some industries must keep their main systems in the country.
- The catch
- The permit route is the general rule. It does not help you in banking, payments, online gambling or government work: in those four areas the main copy of the data has to sit on machines inside Tanzania, and a permit does not buy you a way around that.
- Does this apply to me?
- It can reach a foreign company, but the test is narrower than in Europe. The law covers anyone who is based in Tanzania, and also covers a company that is not based in Tanzania if the processing itself happens inside the country. Simply passing data through Tanzania on the way somewhere else does not count. There is no size or revenue threshold to fall below, and no separate rule forcing a foreign firm to appoint a local representative.High confidence
- Can the data leave the country?
- Yes, but you must ask first, every time. Tanzania does not publish a list of countries that are automatically safe, so there is no shortcut: you apply to the privacy regulator for a permit naming the exact data, the exact recipient and the exact destination. The regulator says it had issued about 39 of these permits by May 2026. Four industries are stricter still — banking, payments, online gambling and government — because their main systems have to be physically in Tanzania whatever any permit says.High confidence
- What do I have to do to send it abroad?
- The model is case-by-case permission. There is no approved-country list to rely on and no standard contract you can just sign, so nothing lawful leaves the country until the regulator says yes to that specific transfer. You apply with the type of data, the purpose, the recipient, the destination country, proof that the destination protects data properly, evidence of a binding contract with the recipient, and the person's consent. The regulator has fourteen days to decide and the permit only covers the recipient it names.High confidence
- Who enforces this — and are they actually working?
- The Personal Data Protection Commission, based in Dodoma, is the main regulator. It is genuinely up and running: it has a director general, a governing board with named members, an online registration system, and by May 2026 it reported over fourteen thousand registered organisations, more than three hundred and forty complaints received and thirty-nine transfer permits granted. What is missing is published punishment — its own decisions page was empty when checked, so we cannot show a single fine actually imposed. Other regulators police their own industries: the central bank, the communications authority, the gaming board and the e-Government Authority.High confidence
- How long must I keep it, and when must I delete it?
- The floor is set by other laws, and in finance it is long: banks, insurers and other firms covered by the money-laundering rules must keep customer and transaction records for at least ten years, and payment providers must keep every transaction record for at least ten years too. The ceiling comes from the privacy law, which says personal data may only be kept for the period the relevant law or regulations set, and only in a form that identifies people for as long as the purpose needs. Where the two collide the specific keeping period in the sector law wins, and you delete when that clock runs out rather than earlier.High confidence
- What happens when something goes wrong?
- The privacy law gives you no clock in hours. It says only that you must tell the regulator about a security breach affecting personal data without undue delay, and it does not require you to tell the affected people at all. Treat twenty-four to seventy-two hours as the safe reading, because there is no published guidance setting a number. Separately, the police can order you to freeze data for up to fourteen days during an investigation, and licensed communications companies have their own reporting duties to the national cyber incident team.Medium confidence
- What's the trap?
- Five things cost people their weekend here. The criminal fine is fifty times the regulator's fine, and directors are personally on the hook. Every single organisation must appoint a data protection officer who then files a report to the regulator every three months. You cannot register without Tanzanian company papers, and you cannot lawfully process anything until you are registered. Every organisation must also write its own code of ethics and get the regulator to approve it. And the police can demand your data without a court order.High confidence
- What's about to change?
- Nothing big is scheduled in the next twelve months that we could verify. The most recent change already landed: from the first of July 2026 the rules on online media services were widened, so more online publishers need a licence from the communications regulator. The bigger risk is what the government can already do without warning. The minister can write regulations naming types of data that may never leave the country, the privacy regulator can ban transfers to a whole destination, and it can refuse any permit on national security grounds.Medium confidence
- Hardest industry wall
- Payments — The Payment Systems (Licensing and Approval) Regulations, 2015
- Banking — Outsourcing Guidelines for Banks and Financial Institutions, 2021
- Online gaming — The Gaming (Internet Gaming) Regulations, 2022
- Government — The e-Government Act, 2019
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
- The catch
- The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
- Does this apply to me?
- Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
- Can the data leave the country?
- Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
- What do I have to do to send it abroad?
- The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
- Who enforces this — and are they actually working?
- The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
- What happens when something goes wrong?
- There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
- What's the trap?
- Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
- What's about to change?
- Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
- Hardest industry wall
- Telecoms — Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
- E-commerce — Loi n° 18-05 relative au commerce electronique
- Government — Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees