Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
South AfricaChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Active
In one paragraph
Personal data may leave South Africa, but only if you can point to a reason the law allows — usually a contract with the receiving company that gives people the same level of protection they had at home. There is no government list of approved or banned countries, and no form to file. The privacy regulator is real, staffed and issuing orders, though its fines are small by world standards.
The catch
That relaxed picture breaks in four places. Tax records held electronically must stay in South Africa unless the tax authority gives you written permission. Banks and foreign-exchange dealers need case-by-case permission from the central bank before moving customer or transaction data offshore. Government data touching national security must stay in the country. And sending health, biometric, religious, criminal-record or children's data to a country with weak protection needs the privacy regulator's approval before you start.
Does this apply to me?
It can reach you without an office in South Africa, but not automatically. The law covers you if your organisation is based in South Africa, or if it is based elsewhere but uses equipment or people inside South Africa to handle the data. Simply having South African customers, with everything processed abroad, is arguably outside the law — which is a narrower reach than Europe's. There is no size or revenue threshold, and no requirement to appoint a local representative.High confidence
Can the data leave the country?
Yes, with paperwork. The general rule is that you may send personal data abroad if the receiver is bound by a law, a group-wide policy or a contract that protects it about as well as South African law does. There is no list of approved countries and no permission slip to collect. But several industries and one rule that applies to every company override this, and in those areas data either stays in the country or needs a regulator's blessing first.High confidence
What do I have to do to send it abroad?
You need a legal reason before the data goes, and you decide for yourself whether you have one. The usual route is a contract with the receiving company that carries the same protections forward, including to anyone they pass it on to. Group-wide internal rules, the person's own consent, or the transfer being necessary for their contract also work. Nobody approves it, nothing is filed, and no country is banned — but sensitive data and children's data are the exception and do need approval.High confidence
Who enforces this — and are they actually working?
The Information Regulator, and it is genuinely working. It has a chairperson and two other members, with two seats vacant, and it issued enforcement orders against a college, a mining company and a provincial health department in May and June 2026 alone. In April 2026 it went to the High Court and got a fine against a municipality confirmed — though the judge cut it from about 28,000 US dollars to about 14,000. Banking, insurance and tax regulators enforce their own rules separately and are far better resourced.High confidence
How long must I keep it, and when must I delete it?
Both directions apply and they pull against each other. The privacy law says delete personal data once you no longer need it. Other laws say keep it: five years for tax records, five years for money-laundering checks, five years for cross-border payment records at banks, and between three and five years for phone and internet connection records. Where they clash, the keeping rule wins, because the privacy law allows you to hold data longer when another law requires it.High confidence
What happens when something goes wrong?
There is only one clock that actually runs, and it has no number on it. If personal data is accessed by someone who should not have it, you must tell the regulator and the affected people 'as soon as reasonably possible' — no fixed hours. A separate 72-hour reporting duty to the police is printed in the cybercrime law but has never been switched on, so it does not apply. Financial firms have a third duty to report serious technology and cyber incidents to their regulators.High confidence
What's the trap?
Five things catch people out. First, the regulator cannot fine you for the breach itself — it must order you to fix it, and only ignoring that order becomes a crime that carries a fine of up to 10 million rand, roughly half a million US dollars. Second, sending sensitive or children's data to a weakly protected country needs approval before you start, and you must wait. Third, letting people opt out is not consent for marketing emails or texts. Fourth, plugging a computer holding patient records into another system without permission is a criminal offence. Fifth, your accounting system in a foreign cloud probably needs the tax authority's written permission.High confidence
What's about to change?
Four things are in the pipeline and none of them is law yet. The banking and insurance regulators say they are writing a binding standard on cloud use and sending data offshore. The central bank has proposed that payment clearing and settlement data stay inside South Africa. The privacy regulator has draft rules for health and sex-life data, and a binding code for security gates and cameras at estates and office parks. Separately, a 72-hour police reporting duty already sits in law and can be switched on overnight.High confidence
Hardest industry wall
  • Payments Cloud computing and data offshoring in the national payment system — proposed directive under section 12 of the National Payment System Act 78 of 1998
  • Government National Data and Cloud Policy
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
The catch
The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
Does this apply to me?
Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
Can the data leave the country?
Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
What do I have to do to send it abroad?
The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
Who enforces this — and are they actually working?
The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
What happens when something goes wrong?
There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
What's the trap?
Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
What's about to change?
Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
Hardest industry wall
  • Telecoms Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
  • E-commerce Loi n° 18-05 relative au commerce electronique
  • Government Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees