Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
UzbekistanChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Uzbekistan used to say that data about its citizens had to sit on machines inside the country. In March 2026 it dropped that blanket rule. Most personal data may now be stored abroad if the destination country is on a new government approved list, or you use an approved contract, or you meet international standards. Three kinds of data still cannot leave at all.
The catch
The relaxed headline stops at three walls. Face and fingerprint data, genetic data, and data about customers of telephone and internet companies must be kept inside Uzbekistan. Banks face a separate rule that bans handing the running of their systems to an outside supplier, which blocks most managed cloud arrangements. Detailed maps are handled under state-secrecy rules.
Does this apply to me?
The law is written to cover the handling of personal data whatever tools are used, and it was aimed at foreign online platforms when the storage rules were first tightened in 2021. It does not set a size or revenue threshold, so a small foreign company is treated the same as a large one. We found no clear wording that forces a foreign company to appoint a representative living in Uzbekistan, and no explicit sentence saying the law follows the data outside the country.Medium confidence
Can the data leave the country?
Mostly yes, but only if you can point to one of three permissions. Face and fingerprint data, genetic data, and data about customers of telephone and internet companies must stay in Uzbekistan. Everything else may be stored and processed abroad if the destination country is on the government's approved list, or you sign an approved standard contract or use approved group rules, or you follow recognised international data standards.Medium confidence
What do I have to do to send it abroad?
The model is an approved list. Before ordinary personal data leaves the country you need one of three things: the destination is on the Cabinet of Ministers' list of countries with adequate protection, or you use the standard contract terms or group rules approved by the data authority, or you meet recognised international data standards. The country list was signed on 29 July 2026 and started on 3 August 2026, so it is brand new. We could not read which countries are on it, and no approved standard contract template appears to have been published yet.Medium confidence
Who enforces this — and are they actually working?
The data regulator is the State Centre for Personalization, which sits under the Cabinet of Ministers. It keeps the national register of personal data databases and can issue orders that companies and individuals must obey. It is a working government body and the registration service has run since 2020, but we found no published fines or decisions, so treat enforcement as waking up rather than active. Cyber incidents are handled by a different body, the State Security Service, and banks answer separately to the Central Bank.Medium confidence
How long must I keep it, and when must I delete it?
The ceiling is clear: personal data must be destroyed once the purpose is achieved, once consent is withdrawn, once the agreed period ends, or when a court orders it. The floor is thinner. Organisations covered by the cybersecurity law must keep backup copies covering at least the last three months. We did not verify the general tax and accounting minimum keeping periods during this run, so plan on the usual company record rules as well.Medium confidence
What happens when something goes wrong?
There are two clocks and they are not the same. The privacy law itself contains no duty to report a data breach to the regulator or to the people affected — we checked the text on 18 August 2026 and found none. The cybersecurity law is where reporting lives: organisations covered by it must tell the State Security Service about cyber incidents. Banks also report to the Central Bank under its security rules. We could not confirm a firm deadline in hours for any of these.Medium confidence
What's the trap?
First, every database of personal data has to be entered in a national register — it is a notification, it is free and it takes five working days, but skipping it is still a breach. Second, breaking the personal data rules can be a crime, not just a fine, so a named person can be prosecuted. Third, the face and fingerprint wall catches ordinary products like fingerprint logins and identity checks, not just spy technology. Fourth, banks are banned from handing the running of their technology and security systems to an outside supplier, which rules out most managed cloud and outsourced security operations. Fifth, the standard contract route for sending data abroad exists on paper but no approved template appears to have been published.Medium confidence
What's about to change?
The big change already happened in March 2026 and the follow-up is still landing. The approved country list started on 3 August 2026 and can be widened or cut by the Cabinet of Ministers at any time. The approved standard contract for sending data abroad is still missing, so watch for it. A new Tashkent International Financial Centre opened its legal regime on 25 July 2026 and its law also touched the privacy law, which may create a separate rulebook inside the centre. A national cybersecurity strategy was signed in March 2026.Medium confidence
Hardest industry wall
  • All industries Закон «О персональных данных», статья 27-1, часть 2
  • Telecoms Закон «О персональных данных», статья 27-1, часть 2 (данные пользователей услуг операторов телекоммуникаций)
  • Finance Кредит бюроларининг ахборот хавфсизлиги ва киберхавфсизлигига доир минимал талаблар тўғрисидаги низом
  • Mapping and location Положение о порядке установления ограничительных грифов картографических и геодезических материалов (данных)
  • Government О мерах по организации деятельности Центра обработки данных системы «Электронное правительство»
CanadaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Canada lets data leave the country. There is no approved-country list and no banned-country list. You stay responsible for the data wherever it goes, and you must tell people it may be handled abroad. The catch is that Canada is really ten jurisdictions at once, and several of them add hard storage rules on top of the national one.
The catch
The relaxed national answer stops being true the moment you touch four things: personal information about people in Quebec, a Nova Scotia public body or its suppliers, federal government data rated Protected B or higher, or a federally regulated bank. Add to that a brand-new cyber security law that says records about critical systems in banking, telecoms, energy and transport must be kept in Canada. In those places Canada is genuinely restrictive.
Does this apply to me?
Yes. Canada's national privacy law reaches a foreign company with no office here if it handles personal information about people in Canada as part of doing business. There is no revenue or headcount threshold that lets you out. You do not normally need a local representative, but payment companies are an exception: a payment firm based abroad that aims its service at people in Canada must register with the central bank and name an agent inside Canada to receive official notices.High confidence
Can the data leave the country?
In general, yes, and with no government permission. Canada's national law does not restrict where personal data is stored or processed. But the headline is wrong for at least six groups. Quebec makes you do a written risk assessment first — and that applies even to sending data to Ontario. Nova Scotia public bodies and their suppliers must keep the data in Canada. Federal government data rated Protected B or higher must sit in Canada. Banks must keep a full copy of their records on servers in Canada. And under the new cyber security law, records about critical systems must be kept in Canada.High confidence
What do I have to do to send it abroad?
At the national level there is no list at all — no approved countries, no banned countries, no government form to file. What you must do instead is stay accountable: put a contract or similar protection in place with whoever handles the data for you, and tell people plainly that their information may be processed in another country and could be seen by foreign courts, police or security agencies. Quebec is different and stricter: there you must complete a written privacy risk assessment before the data moves, and sign a written agreement.High confidence
Who enforces this — and are they actually working?
Canada has many regulators and they are all real, staffed and issuing decisions. The national one, the Privacy Commissioner of Canada, published findings against OpenAI, X, Bell and WestJet in the first half of 2026 alone. But it cannot fine anyone — it makes findings and recommendations, and a case has to go to the Federal Court for money. Quebec's regulator can fine, and has blocked a national grocery chain from switching on a face-recognition system. Banking, payments and cyber security each have their own separate supervisor.High confidence
How long must I keep it, and when must I delete it?
The floor and the ceiling pull in opposite directions. Tax law says keep your business records for six years after the tax year they relate to, and keep them at a place of business in Canada unless the tax authority agrees to somewhere else. Privacy law says the opposite: delete personal information once the reason you collected it has gone. Where the two clash, the duty to keep wins — but only for the specific records the law names, and only for as long as it names.High confidence
What happens when something goes wrong?
Count at least four clocks and they do not agree. The national privacy law gives no fixed number of hours — you report 'as soon as feasible', which in practice means days, not weeks. Payment firms get 48 hours to tell the central bank about a serious incident. Critical infrastructure operators will get no more than 72 hours to tell the national cyber agency, then must tell their own regulator immediately after. Health and provincial rules add more. The overlap is where people get caught: one incident, several reports, several deadlines.High confidence
What's the trap?
Five things that are not in any summary. Quebec's cross-border rule catches you sending data to Ontario, not just abroad. Quebec also makes you tell its regulator 60 days before you switch on any face or fingerprint system, and it has already blocked a big grocery chain from doing so. British Columbia repealed its keep-it-in-Canada rule in 2021, so trackers that still show it are wrong. Nova Scotia's Canada-only rule reaches private suppliers, with fines up to half a million dollars. And your tax records have to sit at a place of business in Canada.High confidence
What's about to change?
One big bill and one big law already passed. The bill is Canada's third attempt to replace its 25-year-old privacy law: it would force a written risk assessment before any personal data goes outside Canada, give people a right to have data deleted, treat everyone under 18 as sensitive, and set up a new commissioner. It was only introduced in June 2026 and is not law — do not plan around it as if it were. The law already passed is the cyber security act, which switches on in stages over the coming year.High confidence
Hardest industry wall
  • Government Personal Information International Disclosure Protection Act
  • Government Direction for Electronic Data Residency (ITPIN 2017-02), with the Policy on Service and Digital
  • Banking Guideline B-10 Third-Party Risk Management, read with Bank Act section 245 and the equivalent provisions of the Insurance Companies Act and Trust and Loan Companies Act
  • All industries Critical Cyber Systems Protection Act, enacted by the Cyber Security Act (Bill C-8)