Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
VietnamChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Vietnam, but the police have to be able to see the paperwork. Anyone sending Vietnamese people's data abroad must build a transfer impact file, lodge it with the Ministry of Public Security and keep it ready for inspection. The ministry can order the flow to stop. Getting cross-border transfers wrong can cost 5 percent of last year's revenue.
- The catch
- Two hard walls sit behind that headline. First, the police ministry holds a power to order named online services to keep data inside Vietnam and to open a local office. Second, the government has published a list of 26 'core' and 18 'important' data categories that carry extra state control. Health, insurance and banking each have their own sharing bans on top.
- Does this apply to me?
- Yes. The rules reach a foreign company with no office in Vietnam, as long as it processes Vietnamese people's data or is involved in data processing that happens in Vietnam. There is no size or revenue floor to duck under. And if your business is processing personal data as a service for others, you cannot do it from abroad at all: that business must be a Vietnamese company, run by a Vietnamese citizen who lives in Vietnam.Medium confidence
- Can the data leave the country?
- Yes, with paperwork. Vietnam does not publish a list of banned or approved countries. Instead, every transfer of a Vietnamese person's data abroad has to be backed by a written transfer impact file that goes to the cyber police, who can inspect it and can order you to stop sending data. On top of that, three areas are much tighter: online services the police ministry names can be told to keep data inside the country, state-classified 'core' and 'important' data carries extra control, and health bodies are simply barred from handing patient data to insurers without the patient asking in writing.Medium confidence
- What do I have to do to send it abroad?
- Build a file, send it to the cyber police, and keep it current. The file has to name both ends of the transfer, explain why the data is going abroad, list what is going, describe the protections, record the person's consent and attach a binding document between sender and receiver. One original copy goes to the cyber police within 60 days of starting to process the data. There is no approved-country list and no standard contract to sign, so nothing releases you from the file.Medium confidence
- Who enforces this — and are they actually working?
- The police. Data protection in Vietnam sits inside the Ministry of Public Security, and the working unit is its cyber security and high-tech crime department, known as A05. It is real, staffed and busy: in the first six months of 2025 alone it dealt with 56 cases of illegal trading in personal data covering more than 110 million records. What it does not yet have is the rulebook for fining ordinary companies under the new law. That decree was still a draft in May 2026, so the headline penalties are not yet routine practice.Medium confidence
- How long must I keep it, and when must I delete it?
- The ceiling is clear, the floor is not. When an employment contract ends, the employer must erase or destroy the worker's personal data unless the law or the contract says otherwise. Processing must also stop when the person who gave consent for a child's data takes that consent back. In the other direction, we could not verify Vietnam's minimum keeping periods for tax, accounting or security logs against an official source during this run, so treat those as unchecked rather than as absent.Medium confidence
- What happens when something goes wrong?
- The clock most people quote is 72 hours to the cyber police, counted from the breach. If you are late you must also explain why you were late. A supplier who spots a breach must tell the company that hired it as fast as it can. Banks and credit businesses have a second duty: tell the customer when their bank, finance or credit information has leaked. Watch this answer: the 72-hour rule comes from the 2023 decree, and we could not confirm the deadline written into the 2025 decree that now sits under the new law.Medium confidence
- What's the trap?
- Five things that cost people their weekend. One: selling personal data is banned outright, and the fine is up to ten times whatever you made from it. Two: the cross-border fine is a share of turnover, not a cash cap, so it scales with the size of the group. Three: the police can order you to stop sending data abroad simply because Vietnamese people's data has leaked, with no court in the way. Four: if you process personal data as a service for other companies, you need a police certificate, a Vietnamese company, a Vietnamese boss who lives in Vietnam and three qualified staff. Five: publishing anything about a child's private life needs the child's own agreement from age seven, on top of the parent's.High confidence
- What's about to change?
- The next twelve months are about decrees, not new laws. A rewritten Cybersecurity Law took effect on 1 July 2026, and the government told the police ministry to have the decrees under it ready before that date. At least one of them, the decree that sets the actual fines for cyber security and personal data breaches, was still a draft in May 2026. A list of information systems treated as critical to national security is due before 31 December 2026. The new e-commerce law also started on 1 July 2026.Medium confidence
- Hardest industry wall
- All industries — Luat An ninh mang
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
- The catch
- The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
- Does this apply to me?
- Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
- Can the data leave the country?
- Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
- What do I have to do to send it abroad?
- The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
- Who enforces this — and are they actually working?
- The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
- What happens when something goes wrong?
- There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
- What's the trap?
- Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
- What's about to change?
- Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
- Hardest industry wall
- Telecoms — Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
- E-commerce — Loi n° 18-05 relative au commerce electronique
- Government — Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees