Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
UkraineChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
- In one paragraph
- Ukraine still runs its 2010 privacy law, not a European-style one. Personal data may leave the country only to a country the law treats as safe — that means Europe and the 50-odd countries that signed a Council of Europe data treaty. The United States is not on that list. Fines are tiny, but the human rights Commissioner really does inspect, and misusing data can be a crime.
- The catch
- The general picture changes completely once government is involved. If a Ukrainian state body is the organisation deciding how personal data is used, only a Ukrainian state-owned or municipal company may process that data for it — a private or foreign supplier cannot. State systems, defence data and critical infrastructure also carry hard location rules, and several of the current permissions exist only because the country is under martial law.
- Does this apply to me?
- Probably not, if you have nothing in Ukraine. The 2010 law simply says it covers the processing of personal data by automated means or in structured paper files. It contains no clause reaching foreign companies that only sell into Ukraine from abroad, and it does not make you appoint a local representative. There is no size or revenue threshold either — a corner shop and a bank are treated the same.Medium confidence
- Can the data leave the country?
- Yes, but only to countries Ukraine already treats as safe. Those are the European Economic Area countries plus every country that has signed the Council of Europe's data protection treaty — roughly 55 states. The United States has signed neither, so routine transfers to American servers do not fit the safe-country route and need one of the narrow exceptions instead. Whole sectors then override this: government, defence and critical infrastructure are far tighter, and securities firms are unusually looser.High confidence
- What do I have to do to send it abroad?
- There is no form to file and no government permission to obtain. You either send the data to a country the law already treats as safe, or you rely on one of five narrow exceptions. Those are: the person's clear consent, necessity for a contract made for that person's benefit, protecting someone's life, an important public interest or a legal claim, and the sender giving guarantees that private and family life will not be interfered with. That last one is a catch-all that a lot of Ukrainian practice leans on.High confidence
- Who enforces this — and are they actually working?
- The Ukrainian Parliament Commissioner for Human Rights — the national ombudsman — is the data protection regulator, and it is genuinely working. It publishes a fresh inspection programme every three months; the one for July to September 2026 went up on 2 July 2026. It also publishes what it found, including a run of checks on the national electronic health system. The catch is the money: the regulator cannot fine anyone itself, it writes up a case and sends it to a court, and the maximum penalty is about $800.High confidence
- How long must I keep it, and when must I delete it?
- The floor comes from tax law. Companies must keep primary accounting documents and financial statements for 1,825 days — five years. Papers needed for transfer pricing checks run to 2,555 days, which is seven years. Everything else the tax authority may ask for runs 1,095 days, three years. The ceiling comes from the privacy law: you must delete personal data when the agreed storage period runs out, or when your relationship with the person ends, unless another law tells you to keep it.High confidence
- What happens when something goes wrong?
- This is the biggest surprise in Ukrainian law: if you lose personal data, there is no duty to tell the regulator and no duty to tell the people affected. The 2010 privacy law simply has no breach reporting clause. The only mandatory clocks sit in the cyber security regime, and they only bite if you run a state system or a piece of critical information infrastructure. Even there the law does not set the hours — it leaves the deadline to an order of the cyber agency.Medium confidence
- What's the trap?
- Five. (1) If a Ukrainian government body is the one deciding how personal data is used, only a Ukrainian state-owned or municipal company may handle that data for it — a private or foreign supplier is not allowed at all. (2) Misusing personal data is a crime, not just a fine, and repeat offences carry up to five years in prison. (3) The fines are aimed at named individuals and sole traders, not at companies. (4) Posting anything that shows where Ukrainian troops are carries five to eight years in prison. (5) Martial law lets the government limit the constitutional right to privacy that the whole system rests on.High confidence
- What's about to change?
- The date to watch is not a new law — it is the end of the war. Martial law was extended again on 13 July 2026 and now runs from 2 August 2026 for 90 days, so to about 31 October 2026. Several of today's permissions exist only while it lasts, and they die six months after it ends. A European-style replacement privacy law has been discussed for years and has still not been passed, so nothing about the current regime should be planned around its arrival.High confidence
- Hardest industry wall
- Government — Закон України "Про захист персональних даних", частина третя статті 4
- Government — Закон України "Про захист інформації в інформаційно-комунікаційних системах"
- Defence — Закон України "Про хмарні послуги"
- Mapping and location — Кримінальний кодекс України, стаття 114-2
SloveniaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
- In one paragraph
- Slovenia has no general rule that data must stay in the country. It runs on the European rulebook: send data abroad once you have the right paperwork. Three things break that. The company running the new national health record system may not store data outside Slovenia. Government bodies may cloud only their least sensitive data. And working-time records must sit at the Slovenian workplace.
- The catch
- The easy answer stops being true in four places. First, health: the state-owned company running the central health information system is forbidden by law from transferring or storing personal data outside Slovenian territory, and every healthcare provider in the country must plug into that system. Second, government: a state administration body may only use a public cloud for the lowest security tiers of information, and only after the ministry approves in writing. Third, employment: the record of working time and the documents behind it must be kept at the employer's registered office or at the place where the worker actually works. Fourth, gambling: only a joint-stock company registered in Slovenia can hold a concession, and its system must be wired into the tax authority's own system. Banking, payments, insurance, securities, telecoms and mapping have no storage-location rule that we could find.
- Does this apply to me?
- Yes. Slovenia's privacy rules reach a company with no office there. If you offer goods or services to people in Slovenia, or watch what they do online, the European rules apply to you and Slovenia's own privacy act applies alongside them. There is no size or revenue threshold that lets you out. A company with no office anywhere in Europe must appoint a written representative inside Europe.High confidence
- Can the data leave the country?
- In general yes, with paperwork — Slovenia adds no national storage-location rule of its own on top of the European regime. But four industries break that answer, and one of them is a hard wall. Health is the big one: the state company that runs Slovenia's central health record system is banned outright from storing or sending personal data outside Slovenia, and every healthcare provider must connect to that system. Government cloud, employment records and gambling each carry their own restriction.High confidence
- What do I have to do to send it abroad?
- Slovenia uses the European model, and it works like an approved-destinations list with escape hatches. Data may go to a country the European Commission has approved. If the destination is not approved, you can still send data by signing the Commission's standard contract, using approved group-wide rules, or relying on one of a few narrow exceptions. Slovenia adds nothing of its own. The old Slovenian system, where the Information Commissioner had to authorise each export, was scrapped when the current privacy act arrived in January 2023.High confidence
- Who enforces this — and are they actually working?
- The Information Commissioner, and it is genuinely working. In 2025 it opened 464 inspection cases from complaints plus 102 more from inspection reports, issued 134 enforcement decisions, fined in 89 of them, gave warnings in 45, and handed down what it calls its largest fine since the European rules began. It handled 153 breach reports. It is small: one commissioner and 53 staff at the end of 2025, and it says openly that it does not have enough people. Cybersecurity is enforced separately by a government office set up for the job.High confidence
- How long must I keep it, and when must I delete it?
- Both directions, and the floors are long. A patient's medical file must be kept for ten years after the patient dies, and other basic medical records for fifteen years. Records of who touched personal data in a computer system must be kept for two years after the end of the year, and up to five if the risk is high. Working-time records must be kept at the Slovenian workplace. In the other direction the European rule applies: delete personal data once the purpose is spent.High confidence
- What happens when something goes wrong?
- Count three clocks, not one. A personal data breach goes to the Information Commissioner within 72 hours. A serious cyber incident, if you are an essential or important organisation, goes to the government security office immediately and in any case within 24 hours as an early warning, then a full report within 72 hours, then a final report within one month. Telecoms operators have their own duties on top. Missing the 24-hour warning is the most common failure, because it lands while you are still working out what happened.High confidence
- What's the trap?
- Five things that catch people out. A child can consent at 15 in Slovenia, not 16 — one year younger than the European default. Fingerprints and face scans are banned in the private sector unless a law allows them and the Commissioner approves. Every access to a covered database must be logged and the log kept two years. Leaking personal data you got through your job is a crime, not just a fine. And working-time records must physically be at the Slovenian workplace, which no cloud contract fixes.High confidence
- What's about to change?
- Two dates in the next twelve months matter most. On 19 December 2026 the cybersecurity duties bite for organisations newly captured by Slovenia's 2025 Information Security Act — registration, security measures and the incident clocks. On 12 January 2027 the European Data Act bans all cloud switching and data export fees. Behind both sits the roll-out of the national health record system, whose ban on storing data outside Slovenia is already law but whose timetable we could not pin down.Medium confidence
- Hardest industry wall
- Health and social care — Zakon o digitalizaciji zdravstva (ZDigZ)
- All industries — Zakon o spremembah in dopolnitvah Zakona o evidencah na področju dela in socialne varnosti (ZEPDSV-A)