Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
ZambiaChecked 18 August 2026
A copy must stayWork: Very highEnforcement: Waking up
- In one paragraph
- Zambia is one of the strictest countries in Africa on paper. The default rule is that personal data must be processed and stored on a server or in a data centre inside Zambia. A copy may go abroad only with the person's consent plus a contract the regulator has approved — and the regulator has approved none. Every organisation handling personal data must register, and breaches must be reported within 24 hours.
- The catch
- This is a general rule, not an industry rule. It catches a two-person shop exactly as it catches a bank, and there is no revenue or headcount threshold to fall below. On top of it sit three more layers: a cyber security law that lets the government order anything it labels 'critical information' to be hosted inside Zambia across eleven named industries, a central bank order requiring live read-only access to electronic money systems, and telecoms rules requiring fingerprint or face data for every mobile line.
- Does this apply to me?
- Almost certainly yes in practice, but the law does not say so clearly. The Act applies to processing of personal data by automated means and to processing done on paper. The regulator's own registration guideline says all persons and entities in all sectors must register, whatever their turnover or staff numbers. The registration form has a section to be completed by anyone representing a foreign entity, so the regulator plainly expects overseas businesses to be inside the net.Medium confidence
- Can the data leave the country?
- Only if a copy stays behind. Zambian law starts from the position that a company must process and store personal data on a server or in a data centre located in Zambia. The most sensitive categories — health, race, religion, politics, sex life, fingerprints, genetics, trade union membership, child abuse records — must be processed and stored in Zambia with no exception at all. Sending anything abroad, including to a cloud region or an off-site backup, needs its own permission from the regulator.High confidence
- What do I have to do to send it abroad?
- Each transfer needs its own permission. There are three routes and none of them is a form you can simply sign. The first needs the person's consent plus a standard contract or group-wide scheme approved by the regulator — the regulator has published no approved contracts, so this route is not usable today. The second needs the Minister to declare a destination country acceptable, which has not happened. The third is a one-off approval from the regulator for a particular transfer.High confidence
- Who enforces this — and are they actually working?
- The Data Protection Commission, which sits inside the Ministry of Technology and Science. It is real: it has a named Commissioner, a live online registration portal, published fees and a set of guidelines issued in early 2025. But it looks thinly resourced and it is not visibly punishing anyone. Its website has published exactly two news items, both on 3 February 2025, and two of its guidance pages still contain placeholder filler text. We found no published fine or decision against any named organisation.High confidence
- How long must I keep it, and when must I delete it?
- Zambia has a floor and a ceiling, and they point in opposite directions. The floor is unusual: you must keep personal data for at least one year after you have finished using it for the purpose you collected it for. The ceiling is the ordinary rule that you must not keep data in an identifiable form for longer than you need it, and people can ask you to erase it. Telecoms operators have their own floor of three years after a device was last used.High confidence
- What happens when something goes wrong?
- Twenty-four hours to tell the regulator, and that clock starts when the breach happens, not when your lawyers finish arguing about it. You must also tell the affected people as soon as practicable. If you are a processor working for someone else, you tell your client as soon as practicable and they carry the deadline. A second and shorter clock applies if you hold information the government has labelled critical: you must notify the cyber security agency immediately and file a written preliminary report within twelve hours.High confidence
- What's the trap?
- Five things that are not in any summary. One: you must keep data for a year after you stop needing it, which collides head-on with the right to be erased. Two: every organisation must appoint a data protection officer — there is no size cut-off. Three: every organisation must be audited every year, and if you were allowed to store data abroad you pay for auditing the foreign server too. Four: the fines are criminal, and directors, managers, shareholders and partners can be convicted personally. Five: a child in Zambia is anyone under eighteen, and you must build age checks and parental consent into your product.High confidence
- What's about to change?
- Nothing large is scheduled to start in the next twelve months. The risk here is the opposite kind: three switches the government already holds and has not yet flipped. Any one of them could change the picture with a single notice and no consultation. Two would make life much easier; one would make it much harder.Medium confidence
- Hardest industry wall
- All industries — The Data Protection Act, 2021
- All industries — The Data Protection Act, 2021, section 70(3)
- All industries — The Data Protection (Registration and Licensing) Regulations, 2021
- All industries — The Cyber Security Act, 2025
- Telecoms — The Information and Communication Technologies (Registration of Electronic Communication Apparatus) (Amendment) Regulations, 2026
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
- The catch
- The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
- Does this apply to me?
- Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
- Can the data leave the country?
- Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
- What do I have to do to send it abroad?
- The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
- Who enforces this — and are they actually working?
- The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
- What happens when something goes wrong?
- There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
- What's the trap?
- Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
- What's about to change?
- Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
- Hardest industry wall
- Telecoms — Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
- E-commerce — Loi n° 18-05 relative au commerce electronique
- Government — Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees