Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
ZimbabweChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Zimbabwe, but only after several hoops: tell the regulator first, run a risk assessment, get each person's clear permission, and show the destination country protects data properly. Almost every organisation that holds personal data also needs a licence, renewed every year. Breaking the rules is a crime, not just a fine.
- The catch
- The strict part is the general law, not any one industry. Only one flat 'must stay in Zimbabwe' rule was found: the servers behind Zimbabwe's own .zw web addresses. Banks, payment firms and mobile money operators have a separate three-hour alarm clock for security incidents, and a data residency rule the central bank has announced but has not yet written down.
- Does this apply to me?
- Yes, it can reach a foreign company. The law applies to an organisation with no permanent presence in Zimbabwe if the equipment it uses to handle the data sits in Zimbabwe. If that is you, you must appoint a representative based in Zimbabwe. There is no size or revenue floor to fall below: a sports club with a membership list is covered on the same terms as a bank. In March 2026 the regulator said the licence duty covers organisations 'permanently established in Zimbabwe or otherwise'.High confidence
- Can the data leave the country?
- Yes, but not freely, and not quietly. You may only send personal data out of Zimbabwe if the destination protects it about as well as Zimbabwe does, and you must notify the regulator before the data moves. Storing data in a cloud service counts as sending it abroad. So does letting a colleague in another country log in and download it. Only one outright 'stays here' rule was found, and it covers the servers behind Zimbabwe's own .zw web addresses.High confidence
- What do I have to do to send it abroad?
- The model is case-by-case permission, not a tick-box contract. Before data leaves you must notify the regulator, hand it a written risk assessment, get the person's express agreement after telling them where the data is going and who will hold it, show that the destination country protects data properly, and sign a data-sharing agreement with whoever receives it. There is no published list of approved countries and no government contract template to sign. If you were already sending data abroad before the law, you must go back and regularise it.High confidence
- Who enforces this — and are they actually working?
- The telecoms regulator, POTRAZ, doubles as the data protection authority. It is real and it is working. It handed out 570 data controller licences at a ceremony in June 2025, runs an online licensing portal, has published seven guidelines, got a new board in March 2026, and issued a public warning that same month to organisations still processing data without a licence. What is missing is punishment. The penalties in the law are criminal, so they need a prosecution in court, and no prosecutions or fines have been made public.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling, and the floor is the specific one. Every business must keep its books and business records for at least six years, and the tax authority must be able to inspect and retrieve them, including from a computer. Financial firms must keep security logs for at least five years. The ceiling is vague: personal data must not be kept in a form that identifies people for longer than the purpose needs. Where the two collide, the fixed minimum wins, because keeping the record is a separate legal duty.High confidence
- What happens when something goes wrong?
- Three clocks, and they do not line up. You have 24 hours to tell the data protection regulator about a personal data breach — and the clock starts on a suspected breach, not just a confirmed one. You have 72 hours to tell the people affected if the breach is likely to seriously harm them. If you are a bank, a payment provider or a mobile money operator you have only 3 hours to tell the central bank. After that you owe the data regulator answers to its questions within 14 days and a closing investigation report within 21 days.High confidence
- What's the trap?
- Five things that ruin weekends. First, you need a government licence just to hold personal data, it expires every twelve months, and the original deadline was 12 March 2025 — so most organisations are already late. Second, your data protection officer must pass a course approved by the regulator that costs 1,250 US dollars a head. Third, a child is anyone under 18, so a parent must agree before you process a 17-year-old's data. Fourth, the punishment is criminal: up to seven years in prison, while the cash fine tops out around 1,000 US dollars. Fifth, the deletion right only covers false or misleading information, so 'delete my account' is not a legal right here.High confidence
- What's about to change?
- The near-term change is enforcement, not new law. The regulator announced that from 1 September 2026 it will inspect organisations to check they hold a licence and have appointed a data protection officer, working down a list that starts with financial institutions, insurers, local authorities and health care providers. Longer term, Zimbabwe's national artificial intelligence plan for 2026 to 2030 promises data localisation policies and says critical data must sit on local infrastructure. That is a plan, not a law, and nothing has been written yet.Medium confidence
- Hardest industry wall
- Telecoms — Postal and Telecommunications (Domain Names Registration and Management) Regulations, 2023
- Telecoms — Interception of Communications Act [Chapter 11:20], as amended by section 37 of the Cyber and Data Protection Act
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
- The catch
- The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
- Does this apply to me?
- Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
- Can the data leave the country?
- Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
- What do I have to do to send it abroad?
- The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
- Who enforces this — and are they actually working?
- The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
- What happens when something goes wrong?
- There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
- What's the trap?
- Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
- What's about to change?
- Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
- Hardest industry wall
- Telecoms — Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
- E-commerce — Loi n° 18-05 relative au commerce electronique
- Government — Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees