Data residency and cross-border transfer rules
19 regulations worldwide that deal with data residency, with every phased deadline and the official source for each.
19 regulations
Add to calendar
- Indonesia PDP Law
Indonesia
AmendedPrivacyBreach notificationNext: Jan 16, 2027 Implementing regulation GR 33/2026 takes effect
- South Korea PIPA
South Korea
AmendedPrivacyBreach notificationNext: Jul 1, 2027 Mandatory ISMS-P certification
- Brazil LGPD
Brazil
In forcePrivacyBreach notificationEffective Sep 18, 2020
- In forceData residencyPrivacy
Effective Mar 22, 2024
- AmendedCybersecurityData residency
Effective Jun 1, 2017
- In forceCybersecurityData residency
Effective Sep 1, 2021
- In forcePrivacyCybersecurity
Effective Jan 1, 2025
- China PIPL
China
In forcePrivacyData residencyEffective Nov 1, 2021
- DOJ Bulk Data Rule
United States (Federal)
In forcePrivacyData residencyEffective Apr 8, 2025
- EU-US Data Privacy Framework
European Union
In forcePrivacyData residencyEffective Jul 10, 2023
- In forcePrivacyBreach notification
Effective Nov 25, 2019
- Malaysia PDPA
Malaysia
AmendedPrivacyBreach notificationEffective Nov 15, 2013
- Nigeria NDPA
Nigeria
AmendedPrivacyBreach notificationEffective Jun 12, 2023
- PADFA
United States (Federal)
In forcePrivacyData residencyEffective Jun 23, 2024
- Saudi PDPL
Saudi Arabia
In forcePrivacyData residencyEffective Sep 14, 2023
- Thailand PDPA
Thailand
In forcePrivacyBreach notificationEffective Jun 1, 2022
- Turkey KVKK
Turkey
AmendedPrivacyData residencyEffective Apr 7, 2016
- UAE PDPL
United Arab Emirates
In forcePrivacyBreach notificationEffective Jan 2, 2022
- Vietnam PDPL
Vietnam
In forcePrivacyData residencyEffective Jan 1, 2026
Upcoming deadlines
January 20271 deadline
Implementing regulation GR 33/2026 takes effect
Detailed PDP implementing rules (DPIA, cross-border, children's consent) apply, 6 months after the 16 Jul 2026 enactment.
July 20271 deadline
Mandatory ISMS-P certification
ISMS-P certification becomes mandatory for private entities meeting the statutory criteria.
Past deadlines
September 20261 deadline
2026 PIPA amendments take effect
10%-of-revenue fines, CEO accountability, and notice duties for possible breaches apply.
March 20261 deadline
2026 PIPA amendment promulgated (Act No. 21445)
Amendment raising fines to 10% of revenue and adding CEO accountability promulgated.
January 20262 deadlines
PDPL and Decree 356/2025 take effect
Personal data protection obligations, DPIA/TIA filing and penalty framework apply; Decree 13/2023 replaced.
2025 amendments take effect
Higher fines, first-violation fines, AI governance provisions and PIPL-alignment duties apply under the 28 Oct 2025 NPCSC Decision.
October 20252 deadlines
- EU-US Data Privacy FrameworkEuropean Union
Latombe appeal lodged at the Court of Justice
Latombe appealed the General Court judgment to the Court of Justice on points of law (reported as Case C-703/25 P); the DPF stays valid while it is pending.
Due diligence, audit and reporting obligations apply
Subpart J (data compliance program, due diligence and audits for restricted transactions) and reporting requirements in 202.1103 and 202.1104 apply.
September 20252 deadlines
GAID 2025 takes effect
General Application and Implementation Directive becomes effective, replacing the NDPR 2019 and NDPR Implementation Framework.
- EU-US Data Privacy FrameworkEuropean Union
General Court upholds DPF (Latombe v Commission)
General Court dismissed Philippe Latombe's action for annulment (Case T-553/23) and confirmed the US offered adequate protection when the decision was adopted.
August 20251 deadline
Deadline to adopt ANPD standard contractual clauses
Agents relying on contractual clauses for international transfers must incorporate the ANPD-approved SCCs into their contracts within 12 months of publication.
June 20251 deadline
PDPA amendments phase 3
Mandatory DPO appointment, data breach notification, and data portability take effect.
April 20252 deadlines
Prohibitions and restrictions take effect
Core prohibitions on covered data transactions and security requirements for restricted transactions apply.
PDPA amendments phase 2
'Data controller' terminology, biometric data as sensitive data, higher penalties, Security Principle for processors, and removal of the cross-border whitelist take effect.
January 20252 deadlines
PDPA amendments phase 1
Miscellaneous provisions commence (e.g. electronic service of notices).
Network Data Regulations take effect
All provisions, including the 10-million-person threshold duties and annual important-data risk assessments, apply.
October 20241 deadline
PDP Law transition ends
Controllers and processors must fully comply (Art. 74 two-year transition).
September 20242 deadlines
One-year grace period ends
Grace period for controllers to comply ends; PDPL fully enforceable.
Old transfer regime ends
Transitional period ends in which the former Article 9 explicit-consent transfer basis could still be relied on.
August 20241 deadline
International transfer regulation published
Resolution CD/ANPD 19/2024 on international transfers and standard contractual clauses published and in force.
June 20242 deadlines
Law 7499 amendments take effect
New sensitive data and cross-border transfer rules (Arts. 6 and 9) apply.
March 20241 deadline
Cross-border data flow provisions take effect
Exemptions and volume thresholds apply from publication (Art. 14); security assessment results are valid for 3 years (Art. 9).
September 20231 deadline
PDPL in force
PDPL and its implementing regulations take effect.
July 20231 deadline
- EU-US Data Privacy FrameworkEuropean Union
DPF adequacy decision adopted and effective
Commission adopted Implementing Decision (EU) 2023/1795, effective on notification to Member States; EU-US transfers to DPF-certified organisations may proceed without additional safeguards.
June 20231 deadline
NDPA signed into law
President signs the Nigeria Data Protection Act, 2023.
October 20221 deadline
PDP Law enacted and in force
Law takes effect on enactment, starting a 2-year transition.
June 20221 deadline
- Thailand PDPAThailand
PDPA main obligations take effect
Core data protection obligations and penalties apply after postponement Royal Decrees.
January 20221 deadline
November 20211 deadline
- China PIPLChina
PIPL takes effect
All PIPL obligations (legal bases, consent, cross-border rules, data subject rights) apply (Art. 74).
September 20211 deadline
Data Security Law takes effect
Data classification, important-data protection and data export restrictions apply (Art. 55).
August 20211 deadline
ANPD sanctions enforceable
Administrative sanctions (Arts. 52-54) become applicable per Law 14.010/2020.
September 20201 deadline
November 20191 deadline
Data Protection Act in force
Act commences.
June 20171 deadline
Cybersecurity Law takes effect
Original CSL obligations for network operators and CII operators apply.