Encryption Law by Country
Where strong encryption is a right, restricted, or compelled. National law and policy, mirrored per country.
Source: Global Partners Digital, World Map of Encryption, updated 2026-07-02. Full data at www.gp-digital.org/world-map-of-encryption
Encryption Law by Country (196)
General right to encryption
No known legislation or policies.
Mandatory minimum or maximum encryption strength
No known legislation or policies.
Licensing/registration requirements
No known legislation or policies.
Import/export controls
No known legislation or policies.
Other restrictions
No known legislation or policies.
Obligations on individuals to assist authorities
Section 49 of the Regulation of Investigatory Powers Act 2000 contains powers for the security and law enforcement agencies in relation to “protected information” i.e. electronic data which, without the key to the data, cannot, or cannot readily, be accessed or put into an intelligible form. Where protected information has come into the hands of an agency, they may, usually with a requirement for written permission from a judge, impose a disclosure requirement upon a person if they reasonably believe that: Under section 50, where a disclosure requirement has been made, the person to whom it is directed must use any key in his possession to obtain access to the information, or to put it into an intelligible form, and make a disclosure of the information in an intelligible form. Alternatively, the person can disclosure the key itself. Failure to comply with a disclosure requirement is a criminal offence punishable in ordinary cases by imprisonment of up to two years’, a fine, or both. In cases involving national security or child indecency, the punishment is imprisonment of up to five years’, a fine, or both. A copy of the Regulation of Investigatory Powers Act 2000 can be found here .
Obligations on providers to assist authorities
Under section 253 of the Investigatory Powers Act 2016, the Secretary of State may give a telecommunications service provider a ‘technical capability notice’. Such a notice may impose on the provider any applicable obligations specified, and require them to take all steps specified in order to comply with those obligations. A technical capability notice may be issued if three requirements are met (s. 253(2)). First, the Secretary of State must considers that the notice is necessary to ensure that the provider has the capability to provide any assistance that they may be required to provide in relation to interception, obtaining communications data or equipment interference authorised by the Act (s. 253(1)(a)). Second, the Secretary of State must considers that the conduct required by the notice is proportionate to what is sought to be achieved by that conduct (s. 253(1)(b)). Third, the decision to give the notice must have been approved by a Judicial Commissioner. A Judicial Commissioner is a specially appointed judge, and, when deciding whether to approve a notice, must consider whether the notice is necessary and proportionate (s. 253(1)(c)). The obligations that can be included in a technical capability notice are to set out in secondary legislation, the Investigatory Powers (Technical Capability) Regulations 2018. While the Regulations don’t explicitly refer to the ability to decrypt communications, they do include the capability to “disclose the content of communications or secondary data in an intelligible form where reasonably practicable” and to “remove electronic protection applied by or on behalf of the telecommunications operator to the communications or data where reasonably practicable”. Where the Secretary of State is considering whether to issue a notice which requires the removal of electronic protection, they must take into account the technical feasibility and likely cost of compliance. (s. 255(4)). Failure to comply with obligations in a technical capability notice is not a criminal offence, but can be enforced through the civil courts. Section 49 of the Regulation of Investigatory Powers Act 2000 contains powers for the security and law enforcement agencies in relation to “protected information” i.e. electronic data which, without the key to the data, cannot, or cannot readily, be accessed or put into an intelligible form. Where protected information has come into the hands of an agency, they may, usually with a requirement for written permission from a judge, impose a disclosure requirement upon a person if they reasonably believe that: Under section 50, where a disclosure requirement has been made, the person to whom it is directed must use any key in his possession to obtain access to the information, or to put it into an intelligible form, and make a disclosure of the information in an intelligible form. Alternatively, the person can disclosure the key itself. Failure to comply with a disclosure requirement is a criminal offence punishable in ordinary cases by imprisonment of up to two years’, a fine, or both. In cases involving national security or child indecency, the punishment is imprisonment of up to five years’, a fine, or both. A copy of the Investigatory Powers Act 2016 can be found here . A copy of the Investigatory Powers (Technical Capability) Regulations 2018 can be found here . A copy of the Regulation of Investigatory Powers Act 2000 can be found here .
Assessment Text Area
In the United Kingdom, telecommunication service providers may be served with a ‘technical capability notice’ by the Secretary of State who must ensure certain requirements are met. These notices impose on the provider any applicable obligations specified, and require them to take all steps specified in order to comply with those obligations. The obligations that can be included in a technical capability notice are to set out in secondary legislation and capability to decrypt encrypted data. Where the Secretary of State is considering whether to issue a notice which requires the removal of electronic protection, they must take into account the technical feasibility and likely cost of compliance. Failure to comply with obligations in a technical capability notice is not a criminal offence, but can be enforced through the civil courts. Security and law enforcement agencies, with a requirement for written permission from a judge, may also impose disclosure requirements to allow for access to encrypted data, subject to certain criteria. Failure to comply with a disclosure requirement is a criminal offence punishable in by imprisonment, a fine, or both.
Murphy's Law