Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
UkraineChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
In one paragraph
Ukraine still runs its 2010 privacy law, not a European-style one. Personal data may leave the country only to a country the law treats as safe — that means Europe and the 50-odd countries that signed a Council of Europe data treaty. The United States is not on that list. Fines are tiny, but the human rights Commissioner really does inspect, and misusing data can be a crime.
The catch
The general picture changes completely once government is involved. If a Ukrainian state body is the organisation deciding how personal data is used, only a Ukrainian state-owned or municipal company may process that data for it — a private or foreign supplier cannot. State systems, defence data and critical infrastructure also carry hard location rules, and several of the current permissions exist only because the country is under martial law.
Does this apply to me?
Probably not, if you have nothing in Ukraine. The 2010 law simply says it covers the processing of personal data by automated means or in structured paper files. It contains no clause reaching foreign companies that only sell into Ukraine from abroad, and it does not make you appoint a local representative. There is no size or revenue threshold either — a corner shop and a bank are treated the same.Medium confidence
Can the data leave the country?
Yes, but only to countries Ukraine already treats as safe. Those are the European Economic Area countries plus every country that has signed the Council of Europe's data protection treaty — roughly 55 states. The United States has signed neither, so routine transfers to American servers do not fit the safe-country route and need one of the narrow exceptions instead. Whole sectors then override this: government, defence and critical infrastructure are far tighter, and securities firms are unusually looser.High confidence
What do I have to do to send it abroad?
There is no form to file and no government permission to obtain. You either send the data to a country the law already treats as safe, or you rely on one of five narrow exceptions. Those are: the person's clear consent, necessity for a contract made for that person's benefit, protecting someone's life, an important public interest or a legal claim, and the sender giving guarantees that private and family life will not be interfered with. That last one is a catch-all that a lot of Ukrainian practice leans on.High confidence
Who enforces this — and are they actually working?
The Ukrainian Parliament Commissioner for Human Rights — the national ombudsman — is the data protection regulator, and it is genuinely working. It publishes a fresh inspection programme every three months; the one for July to September 2026 went up on 2 July 2026. It also publishes what it found, including a run of checks on the national electronic health system. The catch is the money: the regulator cannot fine anyone itself, it writes up a case and sends it to a court, and the maximum penalty is about $800.High confidence
How long must I keep it, and when must I delete it?
The floor comes from tax law. Companies must keep primary accounting documents and financial statements for 1,825 days — five years. Papers needed for transfer pricing checks run to 2,555 days, which is seven years. Everything else the tax authority may ask for runs 1,095 days, three years. The ceiling comes from the privacy law: you must delete personal data when the agreed storage period runs out, or when your relationship with the person ends, unless another law tells you to keep it.High confidence
What happens when something goes wrong?
This is the biggest surprise in Ukrainian law: if you lose personal data, there is no duty to tell the regulator and no duty to tell the people affected. The 2010 privacy law simply has no breach reporting clause. The only mandatory clocks sit in the cyber security regime, and they only bite if you run a state system or a piece of critical information infrastructure. Even there the law does not set the hours — it leaves the deadline to an order of the cyber agency.Medium confidence
What's the trap?
Five. (1) If a Ukrainian government body is the one deciding how personal data is used, only a Ukrainian state-owned or municipal company may handle that data for it — a private or foreign supplier is not allowed at all. (2) Misusing personal data is a crime, not just a fine, and repeat offences carry up to five years in prison. (3) The fines are aimed at named individuals and sole traders, not at companies. (4) Posting anything that shows where Ukrainian troops are carries five to eight years in prison. (5) Martial law lets the government limit the constitutional right to privacy that the whole system rests on.High confidence
What's about to change?
The date to watch is not a new law — it is the end of the war. Martial law was extended again on 13 July 2026 and now runs from 2 August 2026 for 90 days, so to about 31 October 2026. Several of today's permissions exist only while it lasts, and they die six months after it ends. A European-style replacement privacy law has been discussed for years and has still not been passed, so nothing about the current regime should be planned around its arrival.High confidence
Hardest industry wall
  • Government Закон України "Про захист персональних даних", частина третя статті 4
  • Government Закон України "Про захист інформації в інформаційно-комунікаційних системах"
  • Defence Закон України "Про хмарні послуги"
  • Mapping and location Кримінальний кодекс України, стаття 114-2
CanadaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Canada lets data leave the country. There is no approved-country list and no banned-country list. You stay responsible for the data wherever it goes, and you must tell people it may be handled abroad. The catch is that Canada is really ten jurisdictions at once, and several of them add hard storage rules on top of the national one.
The catch
The relaxed national answer stops being true the moment you touch four things: personal information about people in Quebec, a Nova Scotia public body or its suppliers, federal government data rated Protected B or higher, or a federally regulated bank. Add to that a brand-new cyber security law that says records about critical systems in banking, telecoms, energy and transport must be kept in Canada. In those places Canada is genuinely restrictive.
Does this apply to me?
Yes. Canada's national privacy law reaches a foreign company with no office here if it handles personal information about people in Canada as part of doing business. There is no revenue or headcount threshold that lets you out. You do not normally need a local representative, but payment companies are an exception: a payment firm based abroad that aims its service at people in Canada must register with the central bank and name an agent inside Canada to receive official notices.High confidence
Can the data leave the country?
In general, yes, and with no government permission. Canada's national law does not restrict where personal data is stored or processed. But the headline is wrong for at least six groups. Quebec makes you do a written risk assessment first — and that applies even to sending data to Ontario. Nova Scotia public bodies and their suppliers must keep the data in Canada. Federal government data rated Protected B or higher must sit in Canada. Banks must keep a full copy of their records on servers in Canada. And under the new cyber security law, records about critical systems must be kept in Canada.High confidence
What do I have to do to send it abroad?
At the national level there is no list at all — no approved countries, no banned countries, no government form to file. What you must do instead is stay accountable: put a contract or similar protection in place with whoever handles the data for you, and tell people plainly that their information may be processed in another country and could be seen by foreign courts, police or security agencies. Quebec is different and stricter: there you must complete a written privacy risk assessment before the data moves, and sign a written agreement.High confidence
Who enforces this — and are they actually working?
Canada has many regulators and they are all real, staffed and issuing decisions. The national one, the Privacy Commissioner of Canada, published findings against OpenAI, X, Bell and WestJet in the first half of 2026 alone. But it cannot fine anyone — it makes findings and recommendations, and a case has to go to the Federal Court for money. Quebec's regulator can fine, and has blocked a national grocery chain from switching on a face-recognition system. Banking, payments and cyber security each have their own separate supervisor.High confidence
How long must I keep it, and when must I delete it?
The floor and the ceiling pull in opposite directions. Tax law says keep your business records for six years after the tax year they relate to, and keep them at a place of business in Canada unless the tax authority agrees to somewhere else. Privacy law says the opposite: delete personal information once the reason you collected it has gone. Where the two clash, the duty to keep wins — but only for the specific records the law names, and only for as long as it names.High confidence
What happens when something goes wrong?
Count at least four clocks and they do not agree. The national privacy law gives no fixed number of hours — you report 'as soon as feasible', which in practice means days, not weeks. Payment firms get 48 hours to tell the central bank about a serious incident. Critical infrastructure operators will get no more than 72 hours to tell the national cyber agency, then must tell their own regulator immediately after. Health and provincial rules add more. The overlap is where people get caught: one incident, several reports, several deadlines.High confidence
What's the trap?
Five things that are not in any summary. Quebec's cross-border rule catches you sending data to Ontario, not just abroad. Quebec also makes you tell its regulator 60 days before you switch on any face or fingerprint system, and it has already blocked a big grocery chain from doing so. British Columbia repealed its keep-it-in-Canada rule in 2021, so trackers that still show it are wrong. Nova Scotia's Canada-only rule reaches private suppliers, with fines up to half a million dollars. And your tax records have to sit at a place of business in Canada.High confidence
What's about to change?
One big bill and one big law already passed. The bill is Canada's third attempt to replace its 25-year-old privacy law: it would force a written risk assessment before any personal data goes outside Canada, give people a right to have data deleted, treat everyone under 18 as sensitive, and set up a new commissioner. It was only introduced in June 2026 and is not law — do not plan around it as if it were. The law already passed is the cyber security act, which switches on in stages over the coming year.High confidence
Hardest industry wall
  • Government Personal Information International Disclosure Protection Act
  • Government Direction for Electronic Data Residency (ITPIN 2017-02), with the Policy on Service and Digital
  • Banking Guideline B-10 Third-Party Risk Management, read with Bank Act section 245 and the equivalent provisions of the Insurance Companies Act and Trust and Loan Companies Act
  • All industries Critical Cyber Systems Protection Act, enacted by the Cyber Security Act (Bill C-8)