Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
UkraineChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
In one paragraph
Ukraine still runs its 2010 privacy law, not a European-style one. Personal data may leave the country only to a country the law treats as safe — that means Europe and the 50-odd countries that signed a Council of Europe data treaty. The United States is not on that list. Fines are tiny, but the human rights Commissioner really does inspect, and misusing data can be a crime.
The catch
The general picture changes completely once government is involved. If a Ukrainian state body is the organisation deciding how personal data is used, only a Ukrainian state-owned or municipal company may process that data for it — a private or foreign supplier cannot. State systems, defence data and critical infrastructure also carry hard location rules, and several of the current permissions exist only because the country is under martial law.
Does this apply to me?
Probably not, if you have nothing in Ukraine. The 2010 law simply says it covers the processing of personal data by automated means or in structured paper files. It contains no clause reaching foreign companies that only sell into Ukraine from abroad, and it does not make you appoint a local representative. There is no size or revenue threshold either — a corner shop and a bank are treated the same.Medium confidence
Can the data leave the country?
Yes, but only to countries Ukraine already treats as safe. Those are the European Economic Area countries plus every country that has signed the Council of Europe's data protection treaty — roughly 55 states. The United States has signed neither, so routine transfers to American servers do not fit the safe-country route and need one of the narrow exceptions instead. Whole sectors then override this: government, defence and critical infrastructure are far tighter, and securities firms are unusually looser.High confidence
What do I have to do to send it abroad?
There is no form to file and no government permission to obtain. You either send the data to a country the law already treats as safe, or you rely on one of five narrow exceptions. Those are: the person's clear consent, necessity for a contract made for that person's benefit, protecting someone's life, an important public interest or a legal claim, and the sender giving guarantees that private and family life will not be interfered with. That last one is a catch-all that a lot of Ukrainian practice leans on.High confidence
Who enforces this — and are they actually working?
The Ukrainian Parliament Commissioner for Human Rights — the national ombudsman — is the data protection regulator, and it is genuinely working. It publishes a fresh inspection programme every three months; the one for July to September 2026 went up on 2 July 2026. It also publishes what it found, including a run of checks on the national electronic health system. The catch is the money: the regulator cannot fine anyone itself, it writes up a case and sends it to a court, and the maximum penalty is about $800.High confidence
How long must I keep it, and when must I delete it?
The floor comes from tax law. Companies must keep primary accounting documents and financial statements for 1,825 days — five years. Papers needed for transfer pricing checks run to 2,555 days, which is seven years. Everything else the tax authority may ask for runs 1,095 days, three years. The ceiling comes from the privacy law: you must delete personal data when the agreed storage period runs out, or when your relationship with the person ends, unless another law tells you to keep it.High confidence
What happens when something goes wrong?
This is the biggest surprise in Ukrainian law: if you lose personal data, there is no duty to tell the regulator and no duty to tell the people affected. The 2010 privacy law simply has no breach reporting clause. The only mandatory clocks sit in the cyber security regime, and they only bite if you run a state system or a piece of critical information infrastructure. Even there the law does not set the hours — it leaves the deadline to an order of the cyber agency.Medium confidence
What's the trap?
Five. (1) If a Ukrainian government body is the one deciding how personal data is used, only a Ukrainian state-owned or municipal company may handle that data for it — a private or foreign supplier is not allowed at all. (2) Misusing personal data is a crime, not just a fine, and repeat offences carry up to five years in prison. (3) The fines are aimed at named individuals and sole traders, not at companies. (4) Posting anything that shows where Ukrainian troops are carries five to eight years in prison. (5) Martial law lets the government limit the constitutional right to privacy that the whole system rests on.High confidence
What's about to change?
The date to watch is not a new law — it is the end of the war. Martial law was extended again on 13 July 2026 and now runs from 2 August 2026 for 90 days, so to about 31 October 2026. Several of today's permissions exist only while it lasts, and they die six months after it ends. A European-style replacement privacy law has been discussed for years and has still not been passed, so nothing about the current regime should be planned around its arrival.High confidence
Hardest industry wall
  • Government Закон України "Про захист персональних даних", частина третя статті 4
  • Government Закон України "Про захист інформації в інформаційно-комунікаційних системах"
  • Defence Закон України "Про хмарні послуги"
  • Mapping and location Кримінальний кодекс України, стаття 114-2
GreeceChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
For most businesses Greece is a normal European country: personal data can leave, as long as you use one of the standard European transfer tools. But Greece has two hard walls that Europe does not. Phone and internet connection records must physically sit on machines inside Greece. Online gambling operators must keep their records on a server inside Greece too. The privacy regulator is fully staffed and fining companies today.
The catch
The relaxed European headline stops being true the moment you touch three things. Telecoms connection records must be stored on physical media inside Greek territory for twelve months. Online gambling records must sit on a server or safe inside Greece for ten years. And Greek public bodies must run their central systems on the Greek state's own clouds, not on a commercial cloud of their choosing. Outside those three, plus the health and public sectors, Greece imposes no storage-location rule of its own.
Does this apply to me?
Yes, it reaches a foreign company with no office in Greece. The European privacy rules apply to anyone anywhere who offers goods or services to people in Greece, or who watches what they do online. The Greek national law adds that it also covers anyone processing data on Greek soil. There is no size or revenue threshold that lets you off. If you have no establishment anywhere in Europe, you must appoint a written representative inside the European Union.High confidence
Can the data leave the country?
In general, yes. Greece adds no storage-location rule of its own to the European baseline, so ordinary business data can be sent abroad once you have the right European transfer paperwork. Three industries break that rule completely. Telecoms companies must keep their connection records on machines physically inside Greece. Online gambling operators must keep their records on a server inside Greece. And Greek government bodies must run their main systems on state-operated clouds. Health, banking and insurance have extra hoops but no location rule.High confidence
What do I have to do to send it abroad?
You need one of the standard European transfer tools before data leaves Europe. The simplest is sending it to a country the European Commission has already approved. If the destination is not approved, you sign the European Commission's standard contract with the recipient, or use approved group-wide internal rules, and you write down why you think the data will still be safe there. Greece adds no extra permission, filing or fee of its own.High confidence
Who enforces this — and are they actually working?
Six bodies, and all six are genuinely working. The Hellenic Data Protection Authority is the main privacy regulator and is issuing numbered decisions and fines every month — its most recent published decisions run to July 2026 and include fines on a bank and an electricity supplier. A separate constitutional authority polices the secrecy of communications. There is also a national cybersecurity authority, a telecoms regulator, the central bank for finance and insurance, and a gambling regulator. This is not a paper regime.High confidence
How long must I keep it, and when must I delete it?
Both directions apply, and they collide. Business books must be kept five years. Medical files must be kept ten years in a private practice and twenty years everywhere else. Online gambling records must be kept ten years. Telecoms connection records must be kept exactly twelve months and then automatically deleted. In the other direction, the European rule says you must not keep personal data longer than you need it. When a specific keeping rule and the general deleting rule clash, the specific keeping rule wins.High confidence
What happens when something goes wrong?
Count three clocks, not one. If personal data is lost or exposed, you have 72 hours to tell the privacy regulator. If you run important infrastructure, you have only 24 hours to send a first warning to the national cybersecurity authority, then 72 hours for a fuller report and one month for the final one. If you are a phone or internet provider, you have 24 hours to report a personal data breach and a separate duty to tell the communications secrecy authority. Missing the 24-hour clocks is the most common failure.High confidence
What's the trap?
Five things that will cost you a weekend. First, a child in Greece can consent to an online service at fifteen, not sixteen — so an age gate built to the European default is set wrong. Second, misusing personal data is a crime here, with prison time, not just a fine. Third, several articles of the Greek privacy law are printed in the statute but the regulator has formally said they must not be applied, because they clash with European law. Fourth, telecoms connection records must physically stay in Greece. Fifth, government bodies cannot simply pick a commercial cloud.High confidence
What's about to change?
Three dated changes. Electronic invoicing between businesses became compulsory for large Greek companies on 2 March 2026 and becomes compulsory for everyone else on 1 October 2026. Greece's new artificial intelligence law took effect on 22 July 2026 and forces public bodies to register every artificial intelligence system before switching it on. And from 12 January 2027 European law bans cloud providers from charging you to move your data out.High confidence
Hardest industry wall
  • Telecoms Νόμος 3917/2011 — Διατήρηση δεδομένων που παράγονται ή υποβάλλονται σε επεξεργασία σε συνάρτηση με την παροχή υπηρεσιών ηλεκτρονικών επικοινωνιών
  • Online gaming Νόμος 4002/2011 — Ρύθμιση της αγοράς παιγνίων, άρθρο 47, και Κανονισμοί Παιγνίων (ΥΑ 79305/2020 και 79835/2020)
  • Government Νόμος 4727/2020 — Ψηφιακή Διακυβέρνηση, άρθρο 87 (Κυβερνητικά νέφη)