Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
United StatesChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
In general the United States lets data go anywhere. There is no national privacy law and no permit is needed to move data abroad. Two things bite hard. Six countries are effectively off limits for large amounts of sensitive data, with prison sentences attached. And anything connected to government work must physically stay on American soil.
The catch
The open headline stops the moment you touch one of six areas: government contracting, police records, federal tax records, defence technical data, telecom licences, and bulk sensitive data flowing to China, Russia, Iran, North Korea, Cuba or Venezuela. Also note that the rule that actually binds you is almost always a state law or an industry regulator's rule, not a national privacy act. There isn't one.
Does this apply to me?
Yes. American rules reach a foreign company with no office in the country. California's privacy law applies to any for-profit business that 'does business in California' and crosses one of three thresholds, and physical presence is not one of them. The children's rule covers foreign websites aimed at American children. No state and no federal law requires you to appoint a local representative — a real difference from Europe.High confidence
Can the data leave the country?
It depends entirely on your industry, so the single national answer is misleading. For ordinary consumer or employee data, yes — send it anywhere, no paperwork. But six sectors have hard walls. Government contracting, police data, federal tax data and defence work require the data to physically stay in the United States. Telecom licences restrict which foreign staff may even look at records. And for anyone, sending large volumes of sensitive data to six named countries is now a crime.High confidence
What do I have to do to send it abroad?
For ordinary data, nothing. No standard contract, no government approval, no destination approval list. The model is a blocklist and it is now populated: six countries are named. Before you move large volumes of sensitive data, your only real job is to work out whether a country of concern, or a company or person they control, could end up with access — including through a vendor, an investor or an employee.High confidence
Who enforces this — and are they actually working?
Nobody, and everybody. There is no national privacy regulator. Instead the consumer protection regulator, the health department, the securities regulator, the communications regulator, the Justice Department, all fifty state attorneys general and one dedicated state privacy agency each enforce a slice. Almost all of them are visibly working right now. The one exception is the new national data transfer programme: it is staffed and issuing guidance but has published no enforcement action yet.High confidence
How long must I keep it, and when must I delete it?
There is a strong floor and a weak but growing ceiling. Investment firms must keep some books for six years and most others for three, with the first two years easy to reach. Health providers keep their paperwork for six years. In the other direction, state privacy laws now force you to publish how long you keep each type of data and to stop keeping it longer than you said, and since April 2026 children's data may no longer be kept indefinitely. Where a keep-it rule and a delete-it rule collide, the keep-it rule wins: every state law carves out data you are required by law to retain.High confidence
What happens when something goes wrong?
Count the clocks — there are at least seven, and they disagree. New York financial firms: 72 hours to the state regulator, and only 24 hours to report paying a ransom. Telecom carriers: seven working days to the police agencies and the communications regulator, and you may not warn customers until seven working days after that. Investment and finance firms: 30 days to affected customers. Health organisations: 60 days. Texas and many other states: 30 days to the state attorney general. Listed companies: four working days to disclose a material incident. The overlap, not any single deadline, is what people fail.High confidence
What's the trap?
Five that cost people their weekend. One: the national data transfer programme carries prison — up to twenty years for a deliberate breach. Two: Illinois lets individuals sue over fingerprints and face scans with fixed damages per person, no proof of harm needed, and that is where the largest privacy payouts happen. Three: the children's rule uses under 13, but several state laws use under 18, so a single age gate will not do. Four: government work means American soil, and police data allows only the United States, its territories, tribal lands and Canada. Five: a rule can be printed in the law book and still be unenforceable, because a court has blocked it.High confidence
What's about to change?
Four things in the next twelve months. The national critical infrastructure reporting rule should be finalised in late 2026, which will switch on a 72-hour incident clock and a 24-hour ransom-payment clock for a very wide range of businesses. California's rules on automated decision-making bite on 1 January 2027. The open banking rule is being rewritten after a court blocked it. And a federal privacy bill is moving in Congress, but it is only a bill and binds nobody.High confidence
Hardest industry wall
  • Government Criminal Justice Information Services (CJIS) Security Policy
  • Government Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies
  • Defence Defense Federal Acquisition Regulation Supplement clause 252.239-7010, Cloud Computing Services
  • Telecoms National security agreement / letter of assurance conditioning a section 214 authorisation, reviewed by the Committee for the Assessment of Foreign Participation in the United States Telecommunications Services Sector
HungaryChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Active
In one paragraph
Hungary has no general rule that data must stay in the country. It runs on the European rulebook: you may send data abroad if you have the right legal paperwork in place. Hungary used to force state registers to be processed on Hungarian soil, but that rule was scrapped in April 2024. The privacy regulator is real, staffed and issuing decisions, though its fines are small by European standards.
The catch
Two things break the easy answer. Since January 2025 a large slice of the economy — energy, transport, banking, health, water, digital infrastructure, waste, manufacturing and most of the public sector — may only use a shared cloud or process data outside Hungary after completing a formal data classification under the cybersecurity law. And an online casino serving Hungarian players must keep its game server inside the European Economic Area, full stop.
Does this apply to me?
Yes. A company with no office in Hungary is still caught if it offers goods or services to people in Hungary or watches their behaviour, because the European privacy rules reach outside Europe. There is no revenue or headcount threshold to hide under. If you have no establishment anywhere in Europe you must appoint a written representative inside Europe, and Hungary is a perfectly ordinary place to put one.High confidence
Can the data leave the country?
Yes, on the normal European terms — nothing in general Hungarian law says data must be stored in Hungary. This is a change worth noticing: the rule that state registers could only be processed on Hungarian soil was repealed with effect from 1 April 2024, and the law that replaced it has no territorial restriction at all. Two sectors override this. An online casino must keep its game server inside the European Economic Area. And any company or public body inside the scope of Hungary's cybersecurity law must finish a formal data classification before it uses a shared cloud service or processes data abroad.Medium confidence
What do I have to do to send it abroad?
You need a European transfer tool before the data leaves, and Hungary adds no extra permit, filing or fee on top. The model is an approved-list one: you may send data to a country the European Commission has declared safe, or you sign the standard European contract clauses and write down a risk assessment of the destination. There is no Hungarian government sign-off, and no Hungarian list of banned countries. For police, security and other work outside the European privacy rules, Hungary's own Info Act sets the conditions instead.High confidence
Who enforces this — and are they actually working?
The National Authority for Data Protection and Freedom of Information, known by its Hungarian initials NAIH, and it is genuinely working. It has published decisions right through to May 2026, released its report on 2025 activity on 30 March 2026, and issued public statements in July and August 2026. Its president is Dr Attila Peterfalvi. The catch is size, not activity: a typical fine is small — two million forint, roughly six thousand dollars, in an April 2025 data-security case.High confidence
How long must I keep it, and when must I delete it?
Hungary pushes hard in both directions. The floor is long: accounting records and vouchers must be kept for eight years, and health records for decades — the health data law works in periods of thirty years and more. The ceiling is the European rule that you delete personal data once the purpose is spent. When the two collide, the specific statutory keep-period wins, so a deletion request does not empty your ledgers or a hospital's files.Medium confidence
What happens when something goes wrong?
Count at least two clocks, and three if you are a bank. A personal data breach goes to the privacy regulator within 72 hours. A cyber incident at a company or public body covered by the cybersecurity law goes to the national incident response centre, and the European rules that Hungary is copying use a 24-hour first alert followed by a fuller report at 72 hours. Financial firms have a separate and faster set of deadlines under the European operational resilience rules.Medium confidence
What's the trap?
Five things that are not in the summary. One: mishandling personal data is a crime in Hungary, not just a fine — up to one year in prison, two years for sensitive data, three years for public officials. Two: the old rule forcing state data to stay in Hungary is dead, so quoting it makes you look out of date, while the new cybersecurity classification gate is very much alive and most checklists miss it. Three: several cybersecurity deadlines have already passed, so newly in-scope companies are late on day one. Four: an online casino's game server must sit in the European Economic Area. Five: Hungary's freedom-of-information regime can make your contract with a state body public.High confidence
What's about to change?
Three dated items. The Court of Justice will rule on Hungary's sovereignty protection law; the court's adviser said on 12 February 2026 that it breaks European law, and the judgment could land any time. From 12 January 2027 cloud providers across Europe, Hungary included, must charge nothing to move your data out. And Hungary's cybersecurity supervision moves from paperwork to inspections now that the first audit deadline of 30 June 2026 has passed.Medium confidence
Hardest industry wall
  • Online gaming 1991. evi XXXIV. torveny a szerencsejatek szervezeserol es a vegrehajtasi rendeletei (online kaszinojatek engedelyezesi feltetelei)
  • Government 2021. evi XCI. torveny a nemzeti adatvagyonrol, 13. §