Law / Frameworks / NIST Privacy Framework / Control-P

NIST Privacy Framework, Control-PCT.PO-P2

Policies, processes, and procedures for enabling data review, transfer, sharing or disclosure, alteration, and deletion are established and in place (e.g., to maintain data quality, manage data retention).NIST Privacy Framework, version 1.0, January 2020, CT.PO-P2

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

204
laws
165
places
1
with court rulings behind it
16
not yet in force
4
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Albania
  • Algeria
  • Andorra
  • Angola
  • Antigua and Barbuda
  • Argentina
  • Armenia
  • Austria
  • Azerbaijan
  • Bahamas
  • Bahrain
  • Bangladesh
  • Barbados
  • Belarus
  • Belgium
  • Belize
  • Benin
  • Bermuda
  • Bosnia and Herzegovina
  • Botswana
  • Brazil
  • Brunei Darussalam
  • Bulgaria
  • Burkina Faso
  • Cabo Verde
  • Cambodia
  • Cameroon
  • Cayman Islands
  • Central African Republic
  • Chad
  • China
  • Colombia
  • Colorado
  • Comoros
  • Costa Rica
  • Croatia
  • Cuba
  • Cyprus
  • Czech Republic
  • Côte d'Ivoire
  • Democratic Republic of the Congo
  • Denmark
  • Djibouti
  • Dominican Republic
  • Ecuador
  • Egypt
  • El Salvador
  • Equatorial Guinea
  • Estonia
  • Eswatini
  • Ethiopia
  • European Union
  • Finland
  • France
  • Gabon
  • Gambia
  • Georgia
  • Germany
  • Ghana
  • Greece
  • Grenada
  • Honduras
  • Hungary
  • Iceland
  • Idaho
  • Illinois
  • India
  • Indonesia
  • Ireland
  • Israel
  • Italy
  • Jamaica
  • Japan
  • Jordan
  • Kazakhstan
  • Kenya
  • Kiribati
  • Kosovo
  • Kyrgyzstan
  • Latvia
  • Lebanon
  • Lesotho
  • Liberia
  • Libya
  • Liechtenstein
  • Lithuania
  • Luxembourg
  • Madagascar
  • Maldives
  • Mali
  • Malta
  • Marshall Islands
  • Mauritania
  • Mauritius
  • Mexico
  • Moldova
  • Monaco
  • Mongolia
  • Montenegro
  • Morocco
  • Mozambique
  • Myanmar
  • Nauru
  • Netherlands
  • New Zealand
  • Nicaragua
  • Niger
  • Nigeria
  • North Macedonia
  • Norway
  • Oman
  • Panama
  • Paraguay
  • Peru
  • Poland
  • Portugal
  • Puerto Rico
  • Republic of the Congo
  • Romania
  • Russia
  • Rwanda
  • Saint Kitts and Nevis
  • Saint Lucia
  • Samoa
  • San Marino
  • Sao Tome and Principe
  • Saudi Arabia
  • Senegal
  • Serbia
  • Seychelles
  • Singapore
  • Slovakia
  • Slovenia
  • Solomon Islands
  • Somalia
  • South Africa
  • South Korea
  • Spain
  • Sri Lanka
  • Suriname
  • Sweden
  • Switzerland
  • Syria
  • Taiwan
  • Tajikistan
  • Tanzania
  • Thailand
  • Togo
  • Tonga
  • Trinidad and Tobago
  • Tunisia
  • Turkey
  • Turkmenistan
  • Uganda
  • Ukraine
  • United Arab Emirates
  • United Kingdom
  • United States
  • Uruguay
  • Uzbekistan
  • Vanuatu
  • Vietnam
  • Washington
  • Zambia
  • Zimbabwe

Cross border transfer

141 laws, 140 places
PlaceLawWhat it asks, as read here
Albania Law No. 124/2024, international data transfer

Transfer personal data outside Albania only where the destination country, territory, sector or international organization has been found by the Commissioner to ensure an adequate level of protection, or where you provide an appropriate safeguard such as binding company rules, standard contractual clauses, or a Commissioner approved code of conduct or certification mechanism.

Absent an adequacy decision or safeguard, transfer personal data abroad only on a listed condition such as the data subject's informed and explicit consent to the transfer after being told its risks, contractual necessity, or an important public interest, and never repetitively or beyond a limited number of data subjects when relying on the legitimate-interests fallback.

+2 more
Algeria Loi n° 18-07 relative à la protection des personnes physiques, transfert de données vers un pays étranger

Obtain the ANPDP's prior authorisation before transferring personal data to a foreign state, which the ANPDP grants only where that state's own protections are sufficient, and never transfer or communicate personal data abroad where doing so could harm public security or Algeria's vital interests.

Where the destination state does not meet that sufficiency standard, rely on one of the article 45 derogations, such as the data subject's express consent, performance of a contract with them, or a bilateral or multilateral agreement to which Algeria is party.

Andorra LQPD, transfers of personal data to third countries or international organisations

Before transferring personal data to a country or international organisation outside Andorra, confirm the destination offers an adequate level of protection under Article 43, or put appropriate safeguards in place under Article 44, such as standard data-protection clauses or binding corporate rules.

Where no adequacy finding or appropriate safeguard applies, transfer personal data only under an Article 45(1) derogation, such as the data subject's informed explicit consent or contractual necessity, or, failing that, only under Article 45(2)'s narrow compelling-legitimate-interest exception, informing the Agency and the data subject.

Angola Law on the Protection of Personal Data, cross border transfer

Notify the Agência de Protecção de Dados before transferring personal data to a country that ensures a level of protection at least equal to this law's, and expect the APD to assess adequacy by the nature, purpose and duration of the processing, the destination country and the legal, professional and security rules in force there.

Before transferring personal data to a country that does not ensure an adequate level of protection, obtain the APD's authorisation on one of the law's listed grounds, such as the data subject's unequivocal, express and written consent, an applicable international treaty, humanitarian aid, contractual necessity, an important public interest or legal claim, the data subject's vital interests, a publicly accessible source, or the recipient's contractual guarantee of adequate protection on APD-set terms.

+1 more
Argentina Ley 25.326, cross-border transfer

Before transferring personal data of any kind to a country or international or supranational organization, confirm it provides an adequate level of protection; the transfer is prohibited otherwise.

Rely on the prohibition's exceptions only for international judicial cooperation, health-data exchange the affected person's treatment or an epidemiological investigation requires under dissociation safeguards, a banking or securities transfer under its own applicable law, a treaty-based transfer to which Argentina is a party, or intelligence-agency cooperation against organized crime, terrorism, or drug trafficking.

Armenia Law on Protection of Personal Data, cross-border transfer

An app transferring the personal data of a person in Armenia to a recipient outside Armenia must obtain the data subject's consent, rely on the destination being on the authorized body's published adequacy list or covered by an applicable treaty, or obtain the authorized body's prior written permission for a contract it has approved as providing adequate safeguards.

Austria GDPR Chapter V, Cross-Border Transfer of Personal Data from Austria

Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Austria outside the European Economic Area.

Azerbaijan Law on Personal Data, cross-border transfer

An app transferring the personal data of a person in Azerbaijan to a recipient outside Azerbaijan must ensure the destination provides legal protection at the level Azerbaijani law sets, unless the data subject has consented or the transfer is necessary to protect the subject's life or health, since Azerbaijan has no contract, binding-corporate-rule, or authority-permit route for a non-adequate destination.

Bahrain Personal Data Protection Law, cross-border transfer

An app transferring the personal data of an individual in Bahrain to a recipient outside Bahrain must confirm the destination is on the PDPA's published adequacy whitelist or has case-by-case PDPA authorisation, or must rely on one of Art. 13's listed exemptions such as the Data Subject's consent.

Bangladesh Personal Data Protection Act, 2026, cross-border transfer of personal data

An app transferring the personal data of a person in Bangladesh abroad, including a biometric identifier, must have the data principal's consent or a qualifying contract or personal-interest ground, and must notify the Authority before a bulk cross-border transfer of sensitive personally identifiable data such as fingerprint, facial-recognition, or iris data where it could threaten sovereignty, national security, or financial stability.

Show the other 131 laws
Barbados Data Protection Act, 2019, transfers of personal data outside of Barbados

Before transferring personal data outside Barbados, confirm the destination provides an adequate level of protection or rely on an appropriate safeguard such as standard clauses or binding corporate rules.

Submit any binding corporate rules you rely on to the Commissioner for authorisation, and make them specify what section 25 requires, including the data subjects' rights and how to exercise them, the acceptance of liability, the complaint procedures and the compliance-verification mechanisms.

+1 more
Belarus Law of the Republic of Belarus On Personal Data Protection, cross border transfer of personal data

Confirm the destination country is on the authorized agency's adequate-country list before transferring personal data of a person in Belarus outside the country, or rely on one of the seven Article 9 exceptions, such as the subject's informed consent to the risks or performance of a contract with the subject, or obtain the agency's own permit.

This law has no Standard Contractual Clauses or Binding Corporate Rules self-assessment route for a cross-border transfer; an operator outside the adequate-country list and outside the Article 9 exceptions needs the authorized agency's case-by-case permit.

Belgium GDPR Chapter V and Act Article 222, 4, Cross-Border Transfer Restrictions

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Belgium outside the EEA; a grossly negligent or malicious breach is a criminal offense under Act Article 222, 4.

Belize Data Protection Act 2021, cross-border transfer of personal data from a date not yet set

Before transferring personal data of a person in Belize outside the country, confirm the destination has an adequate level of protection or put an appropriate safeguard in place, such as standard contractual clauses or binding corporate rules.

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, transfert transfrontalier de données

Obtain the Autorité de Protection des Données Personnelles (APDP)'s finding that the destination country or international organization assures a level of data protection equivalent to Benin's own before any transfer of personal data outside Benin.

Obtain the Autorité's prior authorization before any actual transfer of personal data to a third country or international organization, even where an equivalence finding exists.

+1 more
Bermuda Personal Information Protection Act 2016, cross-border transfer of personal information

Remain responsible for a transfer of personal information to an overseas third party complying with this Act, unless a specific exception (such as a small-scale, occasional transfer unlikely to prejudice an individual's rights) applies.

Bosnia and Herzegovina Law on the Protection of Personal Data of Bosnia and Herzegovina, cross-border transfer

Rely on a Council of Ministers adequacy decision, or an appropriate safeguard such as standard contractual clauses, binding business rules, or an approved code of conduct or certification, before transferring personal data outside Bosnia and Herzegovina, under Articles 46 to 49.

Absent an adequacy decision or an appropriate safeguard, transfer personal data outside Bosnia and Herzegovina only on a narrow derogation such as the person's informed explicit consent, contractual necessity, or an essential public interest, and never repetitively or systematically, under Article 51.

+2 more
Botswana Data Protection Act, 2024, transfer of personal data to third countries or international organisations

Before transferring personal data to a third country or an international organisation, including an onward transfer, obtain an adequacy decision from the Commission, put in place appropriate safeguards or approved binding corporate rules, or rely on a listed derogation.

Brazil LGPD, international transfer of data

Transfer personal data outside Brazil only to a country or organization with an adequate level of protection, or under contractual clauses, corporate rules, or another article 33 safeguard.

Where you rely on standard contractual clauses, specific contractual clauses, global corporate rules, or a certification seal for a transfer, use only a form the ANPD has verified or approved, and report any change to those safeguards to it.

+1 more
Brunei Darussalam Personal Data Protection Order 2025, cross-border transfer

Brunei's Personal Data Protection Order 2025 has required, since this duty (Part 6) took effect under Government Gazette No. S 11/2025, an organisation to meet a comparable-protection standard, set by regulations not yet located, before transferring personal data, including a voiceprint or other biometric identifier, outside Brunei Darussalam, unless the Authority has granted an exemption.

Bulgaria GDPR Chapter V, Cross-Border Transfer Restrictions

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Bulgaria outside the EEA.

Burkina Faso Personal Data Protection Law, cross-border transfer of personal data

Before transferring personal data to a foreign country or an international organization, confirm that it assures a level of protection adequate to the protection Burkina Faso itself assures for privacy, fundamental freedoms and rights.

Before any transfer of personal data outside Burkina Faso, obtain the CIL's authorization, sign a data confidentiality and reversibility clause with the receiving party letting data migrate back fully at the end of the contract, and put in place technical and organizational security measures covering encryption, availability, confidentiality, integrity and resilience.

+2 more
Cabo Verde Law No. 133/V/2001 on the Protection of Personal Data, cross border transfer

Confirm that a destination country ensures a level of data protection at least equal to this law's before transferring personal data there, and expect the CNPD to decide adequacy by the nature, purpose and duration of the processing, the country of origin and destination, and the legal, professional and security rules in force there.

Before transferring personal data to a country that does not ensure an adequate level of protection, obtain the CNPD's authorisation based on the data subject's unequivocal consent or one of the law's other listed grounds, such as contractual necessity, an important public interest or legal claim, the data subject's vital interests, or a public register open to consultation.

+1 more
Cambodia Cambodia's Draft Law on Personal Data Protection, cross-border data transfer proposed

If enacted as drafted, a data controller would not be able to transfer personal data outside Cambodia unless the Ministry of Post and Telecommunications granted permission, the controller assessed that appropriate safeguards were in place, or the transfer rested on one of six listed circumstances such as the data subject's written consent.

If enacted as drafted, a data controller relying on the safeguards or listed-circumstance grounds would have to be able to give the Ministry of Post and Telecommunications evidence of them.

Cayman Islands Data Protection Act 2021 Revision, cross-border transfer of personal data

Do not transfer personal data outside the Islands unless the receiving country or territory ensures an adequate level of protection for data subjects, or a Schedule 4 exception (consent, contractual necessity, or Ombudsman-approved terms) applies.

Central African Republic Loi n° 24.001 portant protection des données à caractère personnel, flux transfrontalier

Before transferring personal data outside the Central African Republic, confirm the destination offers a similar level of protection, or rely on one of the Act's specific derogations.

Do not let a recipient in a foreign State transfer the data onward to another State without your agreement as the original controller.

+1 more
Chad Loi n°007/PR/2015, transfert des données vers un pays non membre de la CEEAC/CEMAC

Do not transfer personal data to a country outside the CEMAC and CEEAC blocs unless that country ensures a sufficient level of protection for privacy and fundamental rights and freedoms.

Before any transfer of personal data to a country outside the CEMAC and CEEAC blocs, inform ANSICE in advance.

+1 more
China Personal Information Protection Law, Cross-Border Transfer

Complete a CAC security assessment, personal-information-protection certification, or CAC standard contract before transferring personal information out of China, unless a specific exemption applies.

Store personal information collected within China domestically if operating as a critical information infrastructure operator or processing above the state-set volume threshold; export only after a security assessment.

China Provisions on Promoting and Regulating Cross-Border Data Flows

Confirm which volume tier applies before exporting personal information from China: under 100,000 individuals' non-sensitive personal information a year (or a listed necessary-business exemption) needs no mechanism, 100,000 to under 1,000,000 needs a standard contract or certification, and 1,000,000 or more, or sensitive personal information export above 10,000 individuals, needs the full CAC security assessment.

Complete a security assessment before any cross-border personal information export if operating as a critical information infrastructure operator, regardless of volume.

Colombia Ley 1581 de 2012, Cross Border Data Transfer

Do not transfer personal data to a country the Superintendencia de Industria y Comercio has not found to offer an adequate level of data protection, absent a recognized exception.

Rely on the cross border transfer exceptions only where the data subject has given express and unequivocal authorization for the transfer, the transfer is a medical exchange required for treatment or public health, a banking or securities transfer under its own law, a transfer under a reciprocal international treaty Colombia has joined, a transfer necessary to perform a contract with the data subject, or a transfer legally required to safeguard the public interest or defend a right in a judicial proceeding.

+1 more
Comoros Law on the Protection of Personal Data, transfer to a foreign state

Do not transfer personal data to a foreign state unless that state ensures a sufficient level of protection for privacy and fundamental rights and freedoms, judged by the protections and security measures in force there and by the nature, origin and destination of the data.

Obtain the Commission's prior authorization before a processing operation that provides for transferring personal data to another state, even where you rely on contractual clauses or internal rules to show a sufficient level of protection.

Croatia GDPR Chapter V, Cross-Border Transfer Restrictions

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Croatia outside the EEA.

Cyprus GDPR Chapter V, Cross-Border Transfer of Personal Data from Cyprus

Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Cyprus outside the European Economic Area.

Czech Republic GDPR Chapter V, Cross-Border Transfer Restrictions

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in the Czech Republic outside the EEA.

Côte d'Ivoire Law No. 2013-450 on the Protection of Personal Data, cross-border transfer

Before transferring personal data to a third country, confirm that country affords a level of protection of privacy, freedoms and fundamental rights equivalent to or higher than Côte d'Ivoire's.

Obtain ARTCI's prior authorization before implementing any processing that transfers personal data to a third country, and its permission again before the actual transfer takes place.

Democratic Republic of the Congo Digital Code, Title III, cross-border transfer of personal data

Store personal data in the Democratic Republic of the Congo, and do not transfer it to a third country, digital embassy, or international organization unless the Data Protection Authority finds an adequate level of protection.

Obtain the Data Protection Authority's prior authorization before any actual transfer of personal data to a third country or international organization, even after an adequacy finding.

+2 more
Denmark GDPR Chapter V, Cross-Border Transfer of Personal Data from Denmark

Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Denmark outside the European Economic Area.

Djibouti Digital Code, Book I: cross-border transfer of personal data

Do not transfer personal data to a country or international organization outside Djibouti unless it offers an adequate level of protection or another authorized safeguard applies.

Apply the same adequacy or safeguard requirement to an onward transfer from the destination country or organisation to a further one, not only to the first transfer out.

+1 more
Dominican Republic Ley No. 172-13 sobre Protección Integral de los Datos Personales, cross border transfer of data

Before transferring personal data outside the Dominican Republic, obtain the data subject's free authorization or rely on one of the law's nine specific statutory grounds for the transfer.

Confirm a cross border transfer made without the data subject's consent fits one of the law's enumerated grounds, such as medical treatment or epidemiological research, a banking or securities transaction, an international treaty or free trade agreement commitment, intelligence cooperation against organized crime or terrorism, contractual necessity, a legal requirement to safeguard the public interest or a judicial proceeding, international judicial assistance, or a request from an international organization acting on a public register.

Ecuador LOPDP, transferencia internacional de datos personales

Before transferring personal data outside Ecuador, obtain an Authority adequacy resolution, put appropriate safeguards in place, or obtain the Authority's case-by-case authorization.

Where you rely on binding corporate rules, make them meet what article 58 requires before transferring on them.

+1 more
Egypt Egypt Personal Data Protection Law, cross-border transfer of Personal Data

Obtain a Center license or permit before transferring, storing, or sharing personal data outside Egypt, unless the destination country's protection level meets or exceeds Egypt's own, or the data subject has given explicit consent.

Where you rely on the Data Subject's explicit consent instead of the minimum protection level, use only one of the seven cases article 15 lists.

+1 more
El Salvador Ley para la Protección de Datos Personales, cross border transfer of personal data

Before transferring personal data to another country or international organization, confirm the receiving country meets at minimum this Law's data protection principles or applicable international standards, and take appropriate measures to secure the data at the point of transfer if the receiving country's protection is not adequate.

Obtain the data subject's prior consent before an international transfer of their personal data, unless a reciprocal treaty exception applies or the transfer falls under a Central American Economic Integration treaty.

+1 more
Estonia GDPR Chapter V, Cross-Border Transfer of Personal Data from Estonia

Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Estonia outside the European Economic Area.

Eswatini Data Protection Act, 2022, transfer of personal information outside Eswatini

Before transferring personal information to a recipient in a SADC Member State, confirm the State has transposed the SADC data protection requirements and that the transfer is necessary for a public interest task or your lawful functions, or that no reason exists to think it would prejudice the data subject's legitimate interests.

Before transferring personal information to a recipient outside a SADC Member State, confirm an adequate level of protection is ensured in the recipient's country, considering the nature of the data, the purpose and duration of the processing, and the recipient country's laws and security measures.

+3 more
Ethiopia Personal Data Protection Proclamation, cross-border transfer and data sovereignty

Before transferring personal data to a third-party jurisdiction, confirm the jurisdiction ensures an appropriate level of protection, obtain the data subject's informed consent, or meet another condition the Proclamation lists.

Get the Authority's prior approval before any cross-border transfer of sensitive personal data.

+1 more
European Union GDPR Chapter V, Cross-Border Transfer Restrictions

Rely on a Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in the EU outside the EEA.

Finland GDPR Chapter V, Cross-Border Transfer of Personal Data from Finland

Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Finland outside the European Economic Area.

France GDPR Chapter V, Cross-Border Transfer Restrictions

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in France outside the EEA.

Gabon Law No. 025/2023, interconnection and cross-border transfer of personal data

Obtain the APDPVP's prior authorization before transferring personal data to another State; consult the list of States the Authority has found to offer a sufficient level of protection.

Absent that authorization, transfer only where the data subject has expressly consented to the specific transfer and it is necessary to safeguard their life or the public interest, to establish, exercise or defend a legal claim, to consult a public register, or to perform or negotiate a contract with or for the data subject's benefit, or where the APDPVP or a decree has found the processing otherwise offers a sufficient level of protection, such as through contractual clauses or binding internal rules.

Gambia Personal Data Protection and Privacy Act, 2025, transfer of personal data outside The Gambia from a date not yet set

Before transferring personal data out of The Gambia, confirm that the receiving country or international organisation has a law providing an appropriate level of protection, or put appropriate safeguards in place through an ad hoc or standardised instrument the Information Commission has adopted.

Georgia Law on Personal Data Protection, cross-border transfer

An app transferring the personal data of a person in Georgia to a recipient outside Georgia must rely on the destination being on the State Audit Office's adequacy list, a State Audit Office-permitted contractual safeguard, the data subject's informed written consent, or another Art. 37 statutory basis.

Germany GDPR Chapter V, Cross-Border Transfer of Personal Data from Germany

Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Germany outside the European Economic Area.

Greece GDPR Chapter V, Cross-Border Transfer of Personal Data from Greece

Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Greece outside the European Economic Area.

Hungary GDPR Chapter V, Cross-Border Transfer Restrictions

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Hungary outside the EEA.

Iceland Act No. 90/2018 Article 16, Cross-Border Transfer of Personal Data from Iceland

Confirm that a European Commission adequacy decision has its own EEA Joint Committee decision and ministerial confirmation, published in the Law Gazette, before relying on it for a transfer of personal data of a person in Iceland outside the EEA, under Act No. 90/2018 Article 16.

Rely on Standard Contractual Clauses, Binding Corporate Rules, or a narrow derogation where no confirmed adequacy decision covers the destination country.

India Digital Personal Data Protection Act, 2023, cross-border transfer restrictions from , in 7 months

India's cross-border transfer restriction on personal data, including a voiceprint or other biometric identifier, has not yet commenced and is scheduled to take effect . Once in force, an app may transfer the personal data of an Indian data principal to any country or territory by default, unless the Central Government has notified that destination as restricted.

Indonesia Law on Personal Data Protection, cross-border transfer

An app transferring the personal data of an individual in Indonesia, including a faceprint, voiceprint, or other biometric identifier, to a recipient outside Indonesia must ensure the recipient's country of domicile provides a level of personal data protection equal to or higher than this Law's standard.

Ireland GDPR Chapter V, Cross-Border Transfer of Personal Data from Ireland

Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Ireland outside the European Economic Area.

Israel Privacy Protection (Transfer of Data to Databases Abroad) Regulations, cross-border transfer from a date not yet set

An app transferring the personal data of a person in Israel to a recipient outside Israel must rely on the destination providing protection no less than Israeli law's, or on one of the regulation's eight alternative grounds, most commonly consent, a common-control guarantee, an inter-party agreement, or an authority-gazetted adequate jurisdiction, and must obtain a written guarantee from the recipient in every case.

Italy GDPR Chapter V, Cross-Border Transfer Restrictions

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Italy outside the EEA.

Jamaica Data Protection Act, 2020, transfer of personal data outside Jamaica

Do not transfer personal data to a State or territory outside of Jamaica unless that State or territory ensures an adequate level of protection for the rights and freedoms of data subjects.

Rely on a case in section 31(4), such as the data subject's consent or the necessity of the transfer for a contract with the data subject, only where that case actually applies, or transfer on terms of a kind the Information Commissioner has approved.

Japan Act on the Protection of Personal Information, cross-border transfer

An app transferring the personal data of a person in Japan to a recipient in a foreign country must obtain the data subject's prior consent after disclosing the destination country's protection system and the recipient's own measures, unless the destination is a PPC-recognized equivalent jurisdiction or the recipient maintains APPI-equivalent measures.

Kazakhstan Law on Personal Data and Their Protection, localization and cross-border transfer

An app storing or processing the personal data of individuals in Kazakhstan, including a voiceprint or other biometric identifier, must maintain a database located within Kazakhstan; Kazakhstani law does not on its own text forbid an additional copy abroad. Transferring that data to another country requires that the destination state ensure equivalent protection, or one of four fallback grounds: the subject's consent, a ratified treaty, statutory necessity, or protection of constitutional rights where consent cannot be obtained.

Kenya Data Protection Act, 2019, transfer of personal data outside Kenya

Give the Data Commissioner proof of appropriate safeguards, or otherwise satisfy a condition under section 48, before transferring personal data outside Kenya.

Kiribati Data Protection Act 2025, processing and transfers outside Kiribati from a date not yet set

On commencement, before processing personal data outside Kiribati or transferring it to a person outside Kiribati, take reasonable steps to verify that the recipient jurisdiction affords adequate protection, meaning restrictions and obligations substantially similar to Parts III and V, rights substantially similar to Part IV, and that those restrictions, obligations and rights are substantially enforceable.

On commencement, where adequate protection cannot be verified, transfer or process personal data outside Kiribati only on another listed basis, such as the data subject's informed consent to the transfer, contractual necessity, a medical emergency, a transfer for the data subject's benefit where consent is impracticable but would likely be given, or a transfer under an international agreement such as a mutual legal assistance treaty.

+2 more
Kosovo Law No. 06/L-082 on Protection of Personal Data, transfer of personal data to other states and international organisations

Before transferring personal data to another state or an international organisation, confirm the destination is on the Agency's adequacy list, or ensure the transfer meets one of Article 49's other bases, such as the data subject's informed consent or the controller's own adequate safeguards.

Do not disclose or transfer personal data in response to a foreign court judgment or administrative decision unless an international agreement between that state and Kosovo authorises recognition or enforcement of the request.

Kyrgyzstan Digital Code, cross-border transfer of personal data

An app transferring the personal data of a Kyrgyzstani data subject, including a voiceprint or other biometric identifier, to a state the sectoral regulator has listed as adequate may do so freely. Transfer to a non-listed state requires the subject's consent, a qualifying treaty, statutory necessity, or contract necessity. Kyrgyzstan imposes no domestic-storage or localization requirement on the data itself.

Latvia GDPR Chapter V, Cross-Border Transfer of Personal Data from Latvia

Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Latvia outside the European Economic Area.

Lebanon Law No. 81/2018, Part V, transfer of personal data to another State

Declare in the permit you file with the Ministry of Economy and Trade any transfer of personal data to another State, in any form, that the processing involves.

Keep that declaration accurate for the life of the processing, because the Ministry publishes the personal data intended for transfer to a foreign State against your entry on its public list.

Lesotho Data Protection Act, 2011, transfer of personal information outside Lesotho

Before transferring personal information about a data subject to a third party in a foreign country, confirm the recipient is subject to a law, code of conduct, or contract that effectively upholds processing principles substantially similar to this Act's, including onward-transfer protections, or rely on another listed condition.

Obtain the data subject's consent to the transfer where you do not rely on the recipient's equivalent legal protection.

+1 more
Libya Law No. 6 of 2022, cross border transfer of personal data

Before transferring personal data outside Libya, give due consideration to the nature of the data, its source, the purpose and duration of processing, and the destination country's international commitments, applicable law, rules, and security measures.

Liechtenstein DSG Cross-Border Transfer Chapter and EEA Joint Committee Decision No. 154/2018

Rely on an adequacy finding, appropriate safeguards, or a narrow derogation under the DSG's own transfer chapter before moving personal data of a person in Liechtenstein to a country outside the European Economic Area; a transfer to an EU or EEA state is not restricted under this framework.

Lithuania GDPR Chapter V and VDAI Article 46(3) Authorization, Cross-Border Transfer from Lithuania

Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Lithuania outside the European Economic Area.

Luxembourg GDPR Chapter V, Cross-Border Transfer of Personal Data from Luxembourg

Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Luxembourg outside the European Economic Area.

Madagascar Law No. 2014-038, cross-border transfer of personal data

Before transferring personal data to a foreign State, confirm that State's law assures a similar level of protection, weighing the data's nature, the processing's purpose and duration, the countries of origin and destination, and the destination's laws, professional rules, and security measures.

Where the destination does not assure a similar level of protection, obtain CMIL authorization by offering sufficient guarantees such as appropriate contractual clauses or binding internal rules, or rely on one of the law's listed exceptional grounds, such as the data subject's informed consent to the transfer.

+1 more
Maldives Maldives Personal Data Protection Bill, cross-border transfers proposed

If enacted as drafted, a Controller or Processor would not be able to transfer personal data outside the Maldives without appropriate safeguards, and only where enforceable data subject rights and effective legal remedies are available in the destination.

If enacted as drafted, an agreement with a cross-border recipient would have to carry a data protection process the Data Protection Authority endorses, or the transfer would have to rest on binding corporate rules the Authority has approved.

Mali Loi n° 2013-015, transfer of personal data abroad

Before transferring personal data to a foreign country, confirm that the Autorité de Protection des Données à Caractère Personnel has found the destination State's own legislation or international commitments provide a sufficient level of protection that is actually applied, or obtain an Autorité decision that the transfer and the recipient's processing, including through contractual clauses or internal rules, guarantee a sufficient level of protection for privacy and fundamental rights and freedoms.

Malta GDPR Chapter V, Cross-Border Transfer of Personal Data from Malta

Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Malta outside the European Economic Area.

Mauritania Loi n° 2017-020, transferts vers un pays tiers

Do not transfer personal data to a country that does not ensure an adequate level of protection unless it appears on the Authority's published list of adequate countries, or a narrow consent-based or public-interest derogation applies.

Before transferring personal data to a country that does not ensure an adequate level of protection, obtain the Personal Data Protection Authority's authorisation on a motivated request, backed by sufficient guarantees such as appropriate contractual clauses.

+1 more
Mauritius Data Protection Act 2017, transfer of personal data outside Mauritius

Give the Commissioner proof of appropriate safeguards, obtain the data subject's explicit informed consent, or otherwise satisfy a condition under section 36(1), before transferring personal data outside Mauritius.

Mexico Ley Federal de Protección de Datos Personales en Posesión de los Particulares, transfer of personal data

Do not transfer personal data without the data subject's consent unless a listed Article 36 ground applies, such as a legal or treaty basis, a transfer within a corporate group under common control, or a ground necessary to a contract or legal relationship with the data subject.

Moldova Moldova Law No. 195/2024, transfers of personal data abroad

Rely on the National Centre for Personal Data Protection's adequacy list or an approved standard transfer agreement before transferring personal data of a person in Moldova outside the country.

Apply the same conditions to an onward transfer from the destination country or organisation to another one, not only to the first transfer out.

+1 more
Monaco Loi sur la Protection des Données Personnelles, transfert des données

Before transferring personal data outside Monaco, confirm that the destination country, territory, or international organisation has an adequate level of protection, and treat every European Union member state as meeting that standard.

Absent an adequacy finding, rely on an appropriate safeguard, such as an executory international commitment, standard clauses the Authority has approved, binding corporate rules the Authority has approved, an approved certification mechanism, or an approved code of conduct.

+3 more
Mongolia Law on Protection of Personal Data, cross-border transfer

An app transferring the personal data of a Mongolian data subject, including a voiceprint or other biometric identifier, to a person, legal entity, or organization in another country must have a statutory basis, an applicable international treaty, or the subject's consent; transfer is prohibited by default otherwise, and Mongolia imposes no separate domestic-storage requirement on the underlying data.

Montenegro Law on Personal Data Protection, transfer of personal data from Montenegro from a date not yet set

Obtain the prior consent of the Agency for Personal Data Protection and Free Access to Information before transferring personal data of a person in Montenegro to another country or to an international organisation, under Article 41, unless one of the Article 42 exceptions applies, including transfer to an EU or EEA Member State or a country on the EU adequacy list, the data subject's informed consent, or performance of a contract.

Assess the adequacy of protection in the destination country against the nature of the data, the purpose and duration of the processing, the countries of origin and destination, and the rules of law and security measures in force there, under Article 41, paragraph 2.

Morocco Law No. 09-08, transfer of data to a foreign country

Do not transfer personal data to a foreign country unless that country appears on the CNDP's list of states that ensure a sufficient level of protection.

Where the destination country is not on that list, transfer personal data only with the data subject's express consent, under one of the Article 44 necessity grounds, under a bilateral or multilateral agreement Morocco is party to, or with the CNDP's own express and reasoned authorization.

Netherlands GDPR Chapter V, Cross-Border Transfer Restrictions

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in the Netherlands outside the EEA.

New Zealand Privacy Act 2020, Information Privacy Principle 12 (Disclosure Outside New Zealand)

Before disclosing personal information to an overseas recipient, confirm one of information privacy principle 12's safeguards applies: the individual's informed authorisation, the recipient being subject to this Act or a comparably safeguarded overseas law, the recipient's participation in a prescribed binding scheme, the recipient being subject to a prescribed country's laws, or another reasonable basis to believe the recipient will protect the information comparably.

Nicaragua Ley No. 787, Ley de Protección de Datos Personales, cross border transfer of data

Before transferring personal data outside Nicaragua, confirm the receiving country or organization provides an adequate level of security and protection, or that the transfer fits one of the law's listed exceptions, such as international judicial cooperation, a health data exchange for epidemiological investigation, a banking or securities transfer, a ratified treaty commitment, or intelligence cooperation against organized crime or drug trafficking.

Before making the transfer, verify that both you and the recipient meet the applicable security and confidentiality measures, inform the data subject of the request and its purpose for their consent, prevent the data from reaching a third party, and notify the Direccion de Proteccion de Datos Personales of the transfer you made.

Niger Loi n° 2022-59, transfert transfrontalier des données

Before transferring personal data to another State, confirm that State ensures a sufficient level of protection for privacy and fundamental rights and freedoms, weighing its data-protection laws and regulations, the existence of a protection authority, applicable international conventions, or HAPDP-approved safeguards.

Before any transfer, implement technical and organisational security measures, including encryption and measures for availability, confidentiality, integrity and system resilience, and obtain the HAPDP's authorisation for the transfer.

+1 more
Nigeria Nigeria Data Protection Act, 2023, cross-border data transfer

Before transferring personal data outside Nigeria, rely on an adequacy decision by the Commission, a Commission-approved cross-border data transfer instrument, or another lawful basis such as consent or a compelling legal or fiduciary duty.

Obtain the data subject's consent before transferring their personal data to a country for which the Commission has made no adequacy decision.

+2 more
North Macedonia Law on Personal Data Protection (LPDP), transfer of personal data

Once Chapter V takes effect, transfer personal data to a third country or an international organisation only where the Agency has decided it ensures an adequate level of protection, or under an appropriate safeguard such as binding corporate rules or standard data protection clauses.

Once Chapter V takes effect, know that its transfer conditions will not reach a transfer from North Macedonia to a European Union member state or a member of the European Economic Area, though the controller or processor must still notify the Agency of it.

+1 more
Norway Personal Data Act and GDPR Chapter V, Cross-Border Transfer from Norway

Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Norway outside the European Economic Area.

Oman Personal Data Protection Law, cross-border transfer

An app transferring the personal data of an individual in Oman outside the country must follow the controls and procedures the Executive Regulations set, whose substantive text is not confirmed at primary source; a violation of this provision carries by far the highest penalty tier in Oman's Personal Data Protection Law.

Panama Ley 81 de 2019, cross border transfer of personal data

Before storing or transferring personal data domiciled in Panama across a border, confirm you meet this Law's data protection standards, or standards equal to or higher than them, unless the data subject consented, a contract requires it, it is a banking or securities transfer, or a ratified international treaty compels it.

Before an international transfer of personal data, confirm at least one lawful ground applies, among them the data subject's consent, an equivalent or superior protection level in the receiving country, a ratified treaty, medical necessity, transfer within the same corporate group, a contract, a public interest or legal defense need, judicial cooperation, a banking or securities transaction, international intelligence cooperation, a binding self-regulation mechanism, or contractual clauses meeting this Law's protections.

Paraguay Ley N° 7593/2025, transferencias internacionales de datos personales from , in 14 months

Before transferring personal data outside Paraguay, confirm the destination offers an adequate level of protection or put in place safeguards such as standard contractual clauses, binding corporate rules or a code of conduct.

Apply the same rule to an onward transfer from the destination, not only to the first transfer out.

+1 more
Peru Ley 29733, cross-border transfer of personal data

Before a cross-border transfer of personal data, confirm the destination country maintains an adequate level of protection under the Law, or, where it does not, guarantee as the sender that the processing will comply with the Law.

Assess a cross-border transfer against a level of protection at least equivalent to this Law's own principles and to security and confidentiality measures appropriate to the data's category.

Poland GDPR Chapter V, Cross-Border Transfer Restrictions

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Poland outside the EEA.

Portugal GDPR Chapter V, Cross-Border Transfer of Personal Data from Portugal

Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Portugal outside the European Economic Area.

Republic of the Congo Law No. 29-2019, cross-border transfer of personal data

Do not transfer personal data to a country outside the Republic of the Congo unless it offers a sufficient level of protection for the privacy and fundamental rights and freedoms of the persons the data concerns, and inform the national commission of the transfer in advance.

Rely on the article 24 derogation only for a one-off, non-massive transfer, and only where the data subject has expressly consented, or the transfer is necessary to protect that person's life, safeguard the public interest, allow the establishment, exercise or defence of a legal claim, or perform a contract between you and the data subject.

+1 more
Romania GDPR Chapter V, Cross-Border Transfer Restrictions

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Romania outside the EEA.

Russia Federal Law No. 152-FZ, Article 18(5), Data Localization and Cross-Border Transfer, as Amended by Federal Law No. 23-FZ

Before transferring personal data of a person in Russia to a country not on Roskomnadzor's adequacy list, obtain the subject's written consent naming the recipient country or establish another Article 12 basis.

Rwanda Law relating to the Protection of Personal Data and Privacy, cross-border transfer and data storage

Do not share or transfer personal data to a third party outside Rwanda unless you have the supervisory authority's authorisation with proof of appropriate safeguards, the data subject's consent, or another listed ground such as contract necessity, public interest, a legal claim, or a ratified international instrument.

Store personal data in Rwanda, and store it outside Rwanda only where you hold a valid registration certificate from the supervisory authority authorising storage abroad.

Saint Lucia Data Protection Act, transfer of personal data from a date not yet set

Once section 45 is in force, transfer personal data outside Saint Lucia only where the receiving country or territory has comparable safeguards and the Commissioner has authorized the transfer, or a listed exception applies, such as the data subject's consent, contractual necessity, national or public security, or Commissioner-approved terms.

San Marino San Marino Law No. 171, transfers of personal data abroad

Rely on an EU adequacy decision, a bilateral treaty, an appropriate safeguard such as binding corporate rules or standard clauses, or a narrow derogation before transferring personal data of a person in San Marino outside the country, under Articles 45 to 50.

Apply the same conditions to an onward transfer from the destination country or organisation to another one, not only to the first transfer out.

+1 more
Sao Tome and Principe Lei n.º 03/2016, transfer of personal data abroad

Before transferring personal data outside Sao Tome and Principe, confirm the destination legal order offers an adequate level of protection or rely on a stated derogation, and notify NAPPD of a transfer that relies on one.

Assess the adequacy of the destination legal order's protection in light of the nature of the data, the purpose and duration of the processing, the countries of origin and destination, and the rules of law, professional rules and security measures in force there, since NAPPD alone decides whether that order meets the standard.

+1 more
Saudi Arabia Personal Data Protection Law, cross-border transfer

An app transferring the personal data of an individual in Saudi Arabia to a recipient outside the Kingdom must confirm the transfer does not prejudice national security or Kingdom interests, that the destination affords a level of protection at least equivalent to the Law, and that the transfer is limited to the minimum data needed, following the Transfer Regulation's Appropriate Safeguards or Operational Processes conditions where an adequacy finding is not in place.

Senegal Loi n° 2008-12 du 25 janvier 2008 sur la Protection des Données à Caractère Personnel, transferts vers un pays tiers

Do not transfer personal data to a country that does not ensure a sufficient level of protection unless the CDP has been notified first, or a narrow consent-based or public-interest derogation applies.

Where the destination country does not offer that level of protection and no derogation applies, get the CDP's authorization for the transfer on a motivated request backed by guarantees sufficient to protect the person's privacy and rights.

Serbia Law on Personal Data Protection, transfer of personal data to other states

Transfer personal data outside Serbia freely only to a country, part of a country, sector, or international organization the Commissioner has found to ensure an adequate level of protection, a status presumed for parties to the Council of Europe's Convention 108 on automatic processing of personal data.

Absent an adequacy finding, transfer only where you have put in place appropriate safeguards, such as standard contractual clauses issued by the Commissioner, a legally binding instrument between authorities, or Commissioner-approved binding corporate rules, and only where the person retains enforceable rights and effective legal remedies.

+3 more
Seychelles Data Protection Act, 2023, cross-border data flows

Check whether the Information Commission has prohibited your transfer as necessary in the public interest.

Singapore Personal Data Protection Act, cross-border transfer

An app transferring the personal data of an individual in Singapore, including a faceprint, voiceprint, or other biometric identifier, to a recipient outside Singapore must ensure the recipient provides a standard of protection comparable to the PDPA, through a PDPC-prescribed mechanism, unless the PDPC has granted an exemption.

Slovakia GDPR Chapter V, Cross-Border Transfer Restrictions

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Slovakia outside the EEA.

Slovenia GDPR Chapter V, Cross-Border Transfer Restrictions

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Slovenia outside the EEA.

Somalia Data Protection Act, 2023, cross-border transfers of personal data

Before transferring personal data outside Somalia or to an international organisation, confirm the recipient country, organisation or mechanism affords an adequate level of protection, or rely on a ground the Act lists.

South Africa Protection of Personal Information Act, cross-border transfer

Before transferring personal information outside South Africa, confirm the recipient country, its binding rules, or an agreement provides an adequate level of protection substantially similar to the Act's conditions, or that another listed transfer ground, such as the data subject's consent, applies.

Obtain the Information Regulator's prior authorisation before transferring special personal information, or a child's personal information, to a country that does not provide an adequate level of protection.

South Korea Personal Information Protection Act, cross-border transfer restrictions

An app transferring the personal data of a Korean data subject to a recipient outside South Korea must obtain the data subject's separate consent, or rely on a qualifying treaty, PIPC certification, or PIPC adequacy recognition instead.

Spain LOPDGDD Título VI, International Transfers, Layered on GDPR Chapter V

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Spain outside the EEA, and check whether LOPDGDD Articles 41-43 require AEPD authorization or prior notice for the specific transfer.

Sri Lanka Personal Data Protection Act, cross-border transfer of personal data

An app transferring the personal data of a person in Sri Lanka abroad, including a voiceprint or other biometric identifier, must rely on an adequacy decision, Authority-specified appropriate safeguards, or one of section 26(5)'s derogations, such as explicit informed consent after risk disclosure. A public authority defaults to processing data only within Sri Lanka unless the Authority has affirmatively classified the category for third-country processing.

Suriname Draft Law on the Protection of Privacy and Personal Data, cross border transfer proposed

Do not transfer personal data to a recipient in a third country unless the recipient is subject to a law, binding corporate rules, or a binding agreement providing a level of protection substantially comparable to this law's processing principles and its own transfer rules, unless an article 6 lawful basis applies or the Commissioner for Personal Data Protection has authorised that specific transfer.

Transfer special categories of personal data or criminal conviction or offence data to a third country only where the recipient is bound by an adequate protection instrument or the Commissioner has authorised the specific transfer, not merely on an article 6 lawful basis.

Sweden GDPR Chapter V, Cross-Border Transfer Restrictions

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Sweden outside the EEA.

Switzerland FADP Articles 16-17, Cross-Border Transfer of Personal Data from Switzerland

Rely on the Federal Council's adequacy list, standard contractual clauses with the Swiss-law addendum, binding corporate rules, or a narrow Article 17 derogation before moving personal data of a person in Switzerland outside an adequate jurisdiction.

Syria Law No. 12 of 2024 on Protection of Electronic Personal Data, cross border transfer

Obtain the Authority's license and verify that the destination Arab or foreign state offers an acceptable level of protection before transferring, storing abroad, or sharing personal data with a party there.

Where the destination state lacks a verified protection level, transfer personal data only with the data subject's or their representative's explicit consent and only for one of the purposes article 15(b) lists, such as preserving the data subject's life, defending a legal right, or performing a contract for their benefit.

+1 more
Tajikistan Law on the Protection of Personal Data, localization and cross-border transfer

An app storing or processing the personal data of individuals in Tajikistan, including a voiceprint or other biometric identifier, must by default keep the database exclusively inside Tajikistan, unless it has an arrangement agreed with the authorized state body for personal data protection. Transferring that data abroad separately requires the subject's consent, a ratified treaty, statutory necessity, or protection of constitutional rights where consent cannot be obtained.

Tanzania Personal Data Protection Act, 2022, transborder data flow

Before transferring personal data outside Tanzania, confirm the recipient country provides an adequate level of data protection or that another condition under sections 31-32 is satisfied.

Thailand Personal Data Protection Act, cross-border transfer

An app transferring the personal data of an individual in Thailand to a recipient in another country must ensure the destination has an adequate data protection standard, following the Committee's prescribed rules, unless a statutory exception such as informed consent to an inadequate destination applies.

Togo Loi n° 2019-014, transfert des données vers un pays tiers

Before transferring personal data to a third country, confirm that country ensures a sufficient level of protection for privacy and fundamental rights and freedoms, and inform the Instance beforehand for its reasoned opinion.

Where the destination country does not ensure a sufficient level of protection, transfer personal data there only as a one off, non massive transfer with the data subject's express consent, or where the transfer meets one of the law's listed grounds, such as safeguarding the person's life or a contractual necessity.

+1 more
Tonga Privacy Act 2025, transfers of personal information outside the Kingdom from a date not yet set

Do not transfer personal information outside Tonga unless the Privacy Commission has consented in writing, or the recipient is bound by a law, binding corporate rules, contractual clauses, code of conduct or certification mechanism affording an adequate level of protection.

Trinidad and Tobago Data Protection Act, 2011, cross border disclosure of personal information

Section 6(l)'s general principle already binds everyone who handles personal information: before disclosing personal information outside Trinidad and Tobago, make sure the disclosure is regulated and that comparable safeguards to those under this Act exist in the receiving jurisdiction.

Once Part III is in force, before a public body discloses personal information to a party in another jurisdiction, tell the individual the purpose of the disclosure and the identity of the requester and the receiving jurisdiction's data protection body, and obtain the individual's consent.

+1 more
Tunisia Organic Act on the Protection of Personal Data, cross-border transfer

Never transfer or communicate personal data to a foreign country in a way capable of harming public security or Tunisia's vital interests.

Before transferring personal data abroad, confirm the destination country assures an adequate level of protection, assessed against the data's nature, the processing's purpose and duration, and the safeguards in place.

+1 more
Turkey Personal Data Protection Law (KVKK), cross-border transfer

An app transferring the personal data of a person in Turkey to a recipient outside Turkey must rely on a Board adequacy decision for the destination, or, absent one, on Board-approved binding corporate rules, a Board-published standard contract notified to the Authority within 5 business days of signature, a Board-approved written commitment, or an applicable international convention.

Turkmenistan Law on Information About Private Life, localization and cross-border transfer

An app storing or processing the personal information of individuals in Turkmenistan, including a voiceprint or other biometric identifier, must maintain a database located within Turkmenistan; only data contained in that domestic database may be transferred abroad at all. Transfer to another country additionally requires that the destination ensure protection of personal information, or one of four fallback grounds: written consent, a ratified treaty, statutory necessity, or protection of vital interests or constitutional rights where consent cannot be obtained.

Uganda Data Protection and Privacy Act, 2019, cross-border transfer

Before processing or storing personal data outside Uganda, confirm that the destination country's personal data protection measures are at least equivalent to this Act's, or obtain the data subject's consent to the transfer.

United Arab Emirates Federal Decree-Law on the Protection of Personal Data, cross-border transfer

An app transferring the personal data of an individual in the onshore UAE to a recipient outside the UAE must rely on a Bureau adequacy determination for the destination, or on a PDPL-equivalent contractual safeguard, or on the Data Subject's explicit consent where the transfer does not contradict UAE public or security interest.

United Kingdom UK GDPR Articles 44A-50, Cross-Border Transfer of Personal Data from the United Kingdom

Before moving personal data of a person in the United Kingdom outside the UK, either rely on a UK adequacy regulation, put appropriate safeguards in place such as the ICO's International Data Transfer Agreement or Addendum, or rely on a narrow Article 49 derogation, under UK GDPR Article 44A.

United States DOJ Data Security Program (Bulk Sensitive Personal Data Rule)

Do not engage in a prohibited bulk data-brokerage transaction involving bulk U.S. sensitive personal data, including biometric identifiers such as facial images or voice prints, or government-related data, with a country of concern or covered person.

Uruguay Ley N° 18.331, cross border transfer of personal data

Transfer personal data outside Uruguay only to a country or organization that provides an adequate level of protection under international or regional legal standards, unless one of the law's listed exceptions applies (judicial cooperation, medical necessity, banking or stock-exchange transactions, an applicable treaty, or law-enforcement intelligence cooperation).

Absent an adequate-protection finding, transfer personal data internationally only with the data subject's unambiguous consent, under a contractual-necessity exception, or after the Unidad Reguladora y de Control de Datos Personales authorizes the transfer based on the contractual safeguards you offer.

Uzbekistan Law on Personal Data, cross-border transfer and citizen data localization

An app transferring the personal data of an Uzbek data subject outside Uzbekistan must rely on the destination state's adequate protection, or on consent, statutory necessity, or a treaty where adequacy is absent. Separately, an app processing the personal data of Uzbek citizens, including a voiceprint or other biometric identifier, over the internet must collect, systematize, and store that data on technical means physically located in Uzbekistan and register the database in the State Register of Personal Data Bases. Several major platforms have been blocked in Uzbekistan for noncompliance with this storage duty.

Vanuatu Data Protection and Privacy Act 2024, transborder data flows

Do not transfer personal data generated or collected in Vanuatu outside the country without the Minister's prior authorisation, unless the recipient country or organisation is on the Minister's list of jurisdictions providing an appropriate level of protection, or the data subject's informed consent or another situation in section 17 applies.

Vietnam Law on Personal Data Protection, cross-border transfer

An app transferring the personal data of an individual in Vietnam, including biometric data, to a recipient outside the country must satisfy Article 20's cross-border transfer conditions; a violation risks a fine of up to 5 percent of the organization's prior-year revenue, a materially higher tier than the Law's general penalty.

Zambia Data Protection Act, 2021, transfer of personal data outside the Republic

Store and process personal data on a server or data centre located in Zambia unless the Minister has prescribed an exception, and do not store sensitive personal data outside Zambia without the data subject's explicit consent.

Where you transfer personal data abroad under a standard contract or intra-group scheme the Commissioner approved, certify and periodically report to the Commissioner that the transfer is made under it, and carry the liability for harm caused by the transferee's non-compliance.

+1 more
Zimbabwe Cyber and Data Protection Act, transfer of personal information outside Zimbabwe

Before transferring personal data outside Zimbabwe, confirm an adequate level of protection exists in the recipient's country or that the transfer is solely to carry out tasks within your competence as controller.

Assess adequacy on all the circumstances before the transfer, weighing the nature of the data, the purpose and duration of the processing, who the recipient is, the data protection laws in force there, and the professional rules and security measures complied with.

+1 more

Comprehensive regime

40 laws, 39 places
PlaceLawWhat it asks, as read here
Antigua and Barbuda Data Protection Act, 2013

Do not disclose personal data for a purpose other than the one notified at collection, or a purpose directly related to it, without the data subject's consent, unless a listed exception applies, such as preventing or detecting crime, complying with a court order, or a public interest determination by the Minister.

Keep personal data accurate, complete, not misleading and up to date, having regard to the purpose it was collected and further processed for.

Argentina Ley 25.326, Ley de Protección de los Datos Personales

Collect only personal data that is true, adequate, relevant, and not excessive for the purpose you obtained it, use it only for that purpose, keep it accurate and updated, correct or delete it once you learn it is inaccurate or incomplete, store it so the data subject's access right can be exercised, and destroy it once it is no longer necessary.

Bahamas Data Protection Act 2003, application and processing principles

Collect personal data only by means that are lawful and fair, keep it accurate and up to date, and hold it only for the specified purposes it was collected for.

Bangladesh Personal Data Protection Act, 2026, comprehensive regime and lawful basis

An app that collects, uses, or discloses the personal data of an individual in Bangladesh, including a voiceprint, faceprint, or other biometric identifier, must have a lawful basis before processing, ordinarily the data principal's voluntary, specific, and revocable consent or one of the Act's enumerated legitimate-interest grounds, and must not retain the data beyond what its stated purpose requires.

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel)

Keep personal data accurate, correct or erase inaccurate or incomplete data, and do not keep it in identifiable form beyond what its purpose requires.

Brazil Lei Geral de Proteção de Dados Pessoais (LGPD)

As a public body, publish clear, up to date information about the legal basis, purpose and procedures for any processing you carry out, name a person in charge for it, and do not pass on personal data you hold to a private entity except in the cases the law lists.

Burkina Faso Loi n°001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel

Collect personal data only for determined, explicit and legitimate purposes, keep it accurate and updated, and do not retain it beyond the period the purpose requires.

Cameroon Loi n°2024/017 du 23 décembre 2024 relative à la protection des données à caractère personnel au Cameroun from a date not yet set

Obtain the authority's prior authorization before transferring personal data to a foreign country or an international organization, which the authority will grant only where the destination offers an equivalent level of protection.

Central African Republic Loi n° 24.001 portant protection des données à caractère personnel

Only retain personal data for archival, historical, statistical, or scientific purposes beyond its ordinary retention period under the safeguards a law defines for that purpose.

Chad Loi n°007/PR/2015, principes directeurs du traitement des données (consentement, licéité, finalité, conservation)

Keep personal data accurate and up to date, and retain it no longer than the purpose for which it was collected requires.

Show the other 30 laws
Colombia Ley 1581 de 2012, General Personal Data Protection

Keep proof of the data subject's authorization, tell them at authorization the purpose of the processing, keep their personal data updated and accurate, secure it against unauthorized alteration, loss, consultation, use or access, and correct it once it is shown to be incorrect.

Share personal data only with the data subject or their representatives, a public authority acting within its legal functions or under court order, or a third party the data subject or the law has authorized, and supply any information you owe them in an easily readable format matching what is on file.

Colombia Superintendencia Circular on AI and Personal Data

Only process truthful, complete, exact, updated, verifiable and understandable personal data in an artificial intelligence system, and do not process partial, incomplete, fragmented or misleading personal data.

Costa Rica Protección de la Persona frente al Tratamiento de sus Datos Personales

Do not transfer personal data to a third party or abroad without the data subject's express, valid authorization.

Cuba Ley 149/2022, De Protección de Datos Personales, general regime

Transfer personal data nationally or internationally only on one of the law's enumerated grounds; a general business justification is not enough.

Democratic Republic of the Congo Digital Code, Title III: Personal Data Protection

Keep personal data reliable, adequate, relevant, accurate and not excessive, and correct or erase it once it becomes inaccurate or incomplete.

Equatorial Guinea Ley de Protección de Datos Personales

Do not transfer personal data to a country without an equivalent level of protection unless the Órgano Rector de Protección de Datos Personales has authorised the transfer in advance.

Ethiopia Personal Data Protection Proclamation

Obtain the Authority's prior authorization where you cannot provide appropriate safeguards for a transfer to a third-party jurisdiction, and consult the Authority before processing where an impact assessment indicates the operations are likely to present a high risk.

Grenada Data Protection Act, No. 1 of 2023 from a date not yet set

Do not retain personal data longer than necessary for the purpose it was processed for, and take reasonable steps to keep it accurate, complete and up to date.

Jordan Personal Data Protection Law, comprehensive regime and lawful basis

An app that collects, uses, or discloses the personal data of an individual in Jordan must obtain consent or rely on one of the Law's enumerated alternative bases, must confine retention to the processing purpose unless legislation specifies otherwise, and must appoint a data-protection lead if it processes Sensitive Personal Data or transfers personal data to a database outside Jordan.

Kiribati Data Protection Act 2025 from a date not yet set

On commencement, further process personal data only for a purpose compatible with the original purpose, and do not retain personal data longer than necessary to achieve that purpose unless retention is required or authorised by law, necessary for a legitimate business purpose, or the data subject has consented to it.

Lebanon Law No. 81/2018 on Electronic Transactions and Personal Data, Part V (Personal Data Protection)

Retain personal data only for the period stated in the declaration of processing or in the decision authorizing it.

As a network service provider or data host, keep the traffic data of everyone using your service, the data that identifies them and the other technical data of their communications for three years from the service delivery date, keep it under professional secrecy, and produce it to the judicial police or the court when the competent judicial authority so decides.

Liberia Telecommunications Act of 2007, Protection of Personal Information (§§ 51-52)

Keep customers' information accurate, complete, and up to date for the purposes it is used for.

Marshall Islands Personal Data Protection Act 2025, government personal-data protection principles

Keep personal data accurate and up to date, and take reasonable steps to correct or delete inaccurate personal data without delay.

Retain personal data in identifiable form only as long as necessary to fulfill the purpose for which it was collected.

+1 more
Mauritania Loi n° 2017-020, protection des données à caractère personnel

Do not keep personal data longer than its purpose requires, unless you keep it only for historical, statistical, or scientific treatment, and keep it usable, converting it for durable storage where needed.

Mozambique Electronic Transactions Law, Protection of Personal Electronic Data

Keep any personal data you collect, process, or disclose electronically accurate, complete, and up to date.

Do not access another party's personal data in a computerised archive, file, record, or database, and do not transfer personal data between information systems belonging to distinct services or institutions, without a legal instrument or judicial decision authorising it.

Nauru Communications and Broadcasting Act 2018, confidentiality of subscriber information and communications

Retain a subscriber's information only for billing purposes, and for no longer than 7 years.

Nicaragua Ley No. 787, Ley de Protección de Datos Personales

Do not retain personal data for longer than five years, or the term your contract with the data subject sets, once the data are no longer adequate, proportional, or necessary for their purpose.

Niger Loi n° 2022-59, protection des données à caractère personnel

Keep personal data adequate, relevant and accurate, update it where necessary, and correct or erase it once you find it inaccurate or incomplete.

North Macedonia Law on Personal Data Protection (LPDP)

Disclose personal data held in an official document only to fulfil a task in the public interest, reconciling public access to official documents with the right to data protection.

Panama Ley 81 de 2019, Sobre Protección de Datos Personales

Before disclosing personal data to a requester, identify the requester and the purpose, notify the data subject, and record how long the requester will hold the data and how it will be destroyed, unless the data subject has consented.

Do not disclose personal data identifying a person once seven years have passed since your legal duty to retain it ended, unless that data subject asks you to.

+1 more
Saint Kitts and Nevis Data Protection Act, 2018 from a date not yet set

Take reasonable steps to keep personal data accurate, complete, not misleading and up to date.

Senegal Loi n° 2008-12 du 25 janvier 2008 sur la Protection des Données à Caractère Personnel (Personal Data Protection Act)

Do not keep personal data longer than its purpose requires, unless you keep it only for historical, statistical, or scientific treatment.

Solomon Islands Telecommunications Act 2009, Confidentiality and Consent Duties

Comply with any order or direction the Telecommunications Commission issues under section 72(3) requiring you to retain, or prohibiting you from retaining beyond a specified period, information relating to a consumer, including billing information.

Suriname Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens) proposed

Do not keep personal data in a form that identifies a data subject for longer than the processing purposes require.

Taiwan Personal Data Protection Act (個人資料保護法)

Before transferring personal data outside Taiwan, check whether the Personal Data Protection Commission has restricted that transfer under Article 21.

Trinidad and Tobago Data Protection Act, 2011

Keep personal information accurate, complete and up to date as necessary for the purpose of collection, and protect it with safeguards appropriate to its sensitivity.

Uganda Data Protection and Privacy Act, 2019, comprehensive personal-data regime

Keep the personal data you collect, process, use or hold complete, accurate, up to date and not misleading.

Ukraine Law of Ukraine On the Protection of Personal Data

Rely on the law's Convention 108, EEA, and United States adequacy-by-default treatment, or a documented safeguard, before transferring personal data of a person in Ukraine outside the country.

Uruguay Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended

Keep a negative record of a natural person's unpaid commercial obligation registered for no more than five years from its entry, renewable once for another five years if the debt remains unpaid, and update the record within days of being notified the debt was settled.

Vanuatu Data Protection and Privacy Act 2024, comprehensive personal data protection regime

Keep personal data accurate, adequate and proportionate to the purpose, and for no longer than that purpose requires.

Sensitive categories

8 laws, 8 places
PlaceLawWhat it asks, as read here
Brazil LGPD, sensitive personal data and children's data

Give a public-health research body access to personal data only within a controlled and secure environment, anonymized or pseudonymized where possible, and never transfer that data to a third party.

Do not share sensitive health data between controllers for economic advantage, except for the data subject's requested portability or the listed health-service, pharmaceutical, or health-assistance transactions.

Honduras Ley de Transparencia y Acceso a la Información Pública, protección de datos personales y hábeas data

Do not collect, transmit, disclose false personal data, or refuse to rectify or update it, outside the cases this law allows.

Mexico Ley Federal de Protección de Datos Personales en Posesión de los Particulares, sensitive personal data

Make reasonable efforts to limit the period you process sensitive personal data to the minimum indispensable for the purpose.

Niger Loi n° 2022-59, données sensibles, de santé et biométriques

Limit the exchange of health data between health professionals to what coordination or continuity of care strictly requires, and anonymize health data before sharing it or publishing research drawn from it.

Do not treat an insurer or an employer as an authorized recipient of health data unless a law or regulation specifically allows it.

Puerto Rico Ley para la Protección de la Privacidad Cibernética de los Niños y Jóvenes (children's online privacy)

Do not store, sell, share, or retain a known minor's personal information beyond what is reasonably necessary to provide the service the minor is actively using.

Do not store, sell, or share a known minor's precise geolocation beyond what is reasonably necessary, and only for as long as necessary.

Romania GDPR Article 9 and Law 190/2018 Automated Decision-Making and CNP Rules from a date not yet set

Appoint a Data Protection Officer and set specific retention and deletion deadlines if relying on legitimate interests to process a Romanian national identification number, per commentary describing the Act; verify against the Act's own text before relying on it.

Rwanda Law relating to the Protection of Personal Data and Privacy, sensitive personal data and children's data

Comply with the retention periods this Law sets for sensitive personal data.

Tunisia Organic Act on the Protection of Personal Data, sensitive categories and minors

Get the INPDP's authorization before a physician shares health data with a research body, and never keep or use health data beyond the time its purpose requires.

Biometric privacy

5 laws, 5 places
PlaceLawWhat it asks, as read here
China Provisions on Security Management of Facial Recognition Technology Application

Retain facial information no longer than the minimum time necessary for the stated purpose.

Colorado HB 24-1130, Privacy of Biometric Identifiers and Data

Adopt and publish a written policy that sets a retention schedule and a destruction timeline (the earliest of purpose satisfied, 24 months after the consumer's last interaction, or 45 days, extendable by up to 45 more, after the identifier is no longer needed) and a data-security-incident response protocol.

Illinois Biometric Information Privacy Act (BIPA)

Publish a written, publicly available policy establishing a retention schedule, and permanently destroy biometric identifiers and biometric information within 3 years of the individual's last interaction or when the collection purpose is satisfied, whichever occurs first.

Kosovo Law No. 06/L-082 on Protection of Personal Data, use of biometric characteristics

Where biometric characteristics are used for access control in the public sector, apply the entry and exit records chapter's retention and handling safeguards to that use.

Washington HB 1493, Biometric Privacy Law

Retain an enrolled biometric identifier no longer than reasonably necessary for the purpose it was enrolled for, a legal retention duty, or fraud and security prevention needs.

Enforcement supervision

5 laws, 5 places
PlaceLawWhat it asks, as read here
Idaho Student Data Accessibility, Transparency and Accountability Act (SDATAA) from a date not yet set

Do not retain a K-12 student's biometric information, Social Security number, or affective-computing assessment data as part of the student's permanent educational record.

Mauritius Data Protection Act 2017, enforcement, offences and penalties

Do not disclose personal data in a manner incompatible with the purpose for which it was collected, or without the prior authority of the controller or processor by whom it is kept.

Myanmar Cybersecurity Law, digital platform data retention and disclosure duty from a date not yet set

Myanmar's Cybersecurity Law creates no data-protection right; it is a state-access duty, not a rights regime. A digital platform service with 100,000 or more Myanmar users must retain personal information of a user, including a voiceprint or faceprint the platform stores, for 3 years and disclose it to an authorised individual or organisation on written request, with no consent, purpose-limitation, or individual-notice duty running the other way. Whether this duty currently binds turns on a presidential commencement notification that has not been independently confirmed, though independent reporting places it in force since .

Saudi Arabia Personal Data Protection Law, enforcement and penalties

An app operating in Saudi Arabia must not disclose or publish an individual's Sensitive Data, including identifying biometric data, in violation of the Law, since doing so with intent to harm the Data Subject or gain personal benefit is a criminal offense; other violations are subject to administrative fines up to SAR 5,000,000.

Seychelles Data Protection Act, 2023, enforcement and penalties

Do not disclose personal data without lawful justification in a manner incompatible with the purpose for which it was collected.

Data subject rights

3 laws, 3 places
PlaceLawWhat it asks, as read here
Ghana Data Protection Act, rights of data subjects

Comply with a Commission order to rectify, block, erase, or destroy personal data found to be inaccurate on a data subject's complaint.

Lebanon Law No. 81/2018, Part V, notice, objection, access and correction

Notify every third party the data was sent to of an amendment made at the request of its owner or their heirs, and make the same correction on your own initiative as soon as you learn of a reason to modify or cancel the data.

Tanzania Personal Data Protection Act, 2022, rights of data subjects

Rectify, block, erase or destroy inaccurate personal data when the Commission orders it on a data subject's application, and notify the third parties you disclosed it to.

Breach notification

1 law, 1 place
PlaceLawWhat it asks, as read here
Samoa National Digital Identification Act 2024, personal data breach notification

Do not disclose, transmit, copy, or otherwise disseminate personal data collected or processed under the Act to a person not authorised under the Act or its regulations.

Telephone contact

1 law, 1 place
PlaceLawWhat it asks, as read here
Germany Gesetz gegen den unlauteren Wettbewerb, Documentation of Consent to Telephone Advertising

Retain that documentation for five years from the date consent was given and after every subsequent use of it.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.