Cybersecurity, telecoms and hosting in Uzbekistan
Telecom and hosting providers, server owners and operators of critical systems have different compliance obligations. The telecommunications and licensing laws govern licensing; the Cybersecurity Law governs system protection; and the Personal Data Law governs data location. For leaks during cross-border transfers, a Cabinet resolution sets 24-hour and 72-hour deadlines for notification and a detailed report.
At a glance:
- Hosting is included among data-network services; the licence must cover the relevant activity subtype.
- Mandatory local storage covers specified personal data categories; the law provides conditions for storing other data abroad.
- Critical information infrastructure entities must report incidents immediately.
- A company's obligations depend on its activities and role: providing services, processing data and operating critical systems.
Which telecom and hosting services require a licence
Designing, building and operating networks and providing telecommunications services are licensed activities (Licensing Law, Appendix 1, item 32). The list distinguishes activity subtypes: permission to design a network does not itself authorize services to subscribers over that network.
The list includes the following groups and subtypes:
| Networks | Activities and services covered |
| Local, long-distance and international | Design and construction; operation and services of local and long-distance networks; separately, operation and services of international networks |
| Cellular mobile radiotelephone communications | Design; construction; operation and service provision |
| Radiotelephone, trunked and satellite communications within the republic | Design; construction; operation; service provision |
| Data transmission | Design; construction; operation; service provision |
| Television and radio broadcasting distribution | Design; construction; operation; service provision |
Hosting means supplying technical resources for placing information on a server that is continuously connected to the Internet (Telecommunications Service Rules, registration No. 3762, paragraph 2). The Rules expressly classify hosting as a data-network service. Commercial hosting therefore falls to be assessed within licensing of those services; the licensing list does not contain a separately named “hosting licence”. Calling a product a cloud, virtual server or server rental does not replace an assessment of the service actually supplied.
The list of possible data-network services includes network access and traffic transit; access to international networks and the Internet; real-time access to information resources and systems; electronic messages and email; cryptographic and other protection of confidential information; subnet allocation; registration and administration of domains and the domain name system; allocation and maintenance of IP addresses; IP telephony and IP television; and hosting. Other services may also be provided in accordance with legislation. The actual service package must be specified in the subscriber contract.
Only the licence holder may exercise the licensed rights: transferring those rights is prohibited (Licensing Law, Article 13). Using a licensed operator's channels does not itself replace the licence of a company supplying licensed services in its own name.
When a data-transmission licence is unnecessary
The law provides express exceptions (Telecommunications Law, Article 13):
- data-network services supplied by public access points, including those operated by small businesses in rural areas;
- local, long-distance and international telecommunications services supplied by small businesses in rural areas;
- use of data networks in production and technological processes;
- use of those networks to deliver signals for services of a bank, payment system, payment organization or electronic commerce platform. In the last two cases, the exception concerns the licence to operate data networks and/or provide their services.
It follows that a company's own server and commercial hosting for customers cannot automatically be treated as the same activity. For an internal network, its use in production and technological processes must be assessed; for services sold to third parties, the service content and the specific exception must be considered. Exemption of a bank or platform from data-transmission licensing does not remove its personal data or cybersecurity obligations.
The general procedure for applications, refusal, licence reissue and appeals is covered in the article on licences and permits. It is relevant when obtaining authorization; this article addresses telecommunications, hosting and system protection.
How to obtain a data-network services licence
Applications are submitted through the Licence information system or the Unified Portal of Interactive Public Services. The telecommunications licensing passport names the Telecommunications Regulatory Agency as licensing authority. For data transmission, the decision involves the Interdepartmental Coordinating Commission for Improving Information Activities and Data Transmission and Increasing Their Efficiency. The applicant must be a legal entity.
Depending on the activity subtype, the passport requires the following documents and information:
- an application stating the entity's name and legal form, addresses, banking details, telephone number, taxpayer identification number, email, selected subtype, purpose of application and agreement to comply with the requirements;
- for network operation and services, a description of the principal technical equipment held on a lawful basis, services, frequency bands and nominal frequencies, and service area;
- for design and construction, a list of the necessary technical equipment;
- for operation and services, a network establishment and development plan with the relevant technical parameters;
- for television and radio distribution services, a broadcasting concept;
- for operation and services of television and radio distribution networks, an opinion confirming compliance with site security requirements or a copy of the security contract;
- where radio equipment is used, information from the competent authority on frequency availability and transmitter characteristics;
- where another person's equipment will be used, a document confirming the lease or right of use;
- for distribution of foreign television and radio products, a document confirming consent from the foreign media organization or rights holder.
The applicant pays an application processing fee of one BRV, the base calculation unit, equivalent to UZS 440.000, when applying. The processing period is ten working days, or twenty-five working days when coordination with the interdepartmental commission is required; data transmission requires that coordination. For design and construction, the entity must employ at least two specialists with higher technical education and at least three years of experience designing and building telecommunications networks. These are selected licensing requirements, rather than the passport's complete set of conditions.
Example. For an applicant seeking to provide data-network services, the processing fee and first annual state duty total UZS 440.000 + UZS 13.200.000 = UZS 13.640.000. This includes only those two mandatory payments: equipment and technical compliance costs depend on the project.
The passport also exempts Internet cafés without their own network that provide access through an operator's or provider's network. Other passport exceptions include paid television with no more than ten subscribers; cable television or wired radio confined to one institution or its premises; specified telephone and fax services using operator-assigned numbers; emergency response and exclusively governmental special-purpose networks; internal production networks without services to third parties; and data-network use for the core activities of the listed financial institutions and electronic commerce platforms. These exceptions apply within the conditions described in the passport.
How much a data-transmission licence costs
Telecommunications licences carry an annual state duty (Licensing Law, Article 17). Rates for data networks are set directly by the State Duty Law.
The following is a partial fee schedule covering data networks only (State Duty Law, Appendix). The BRV rate applicable on the payment date is used.
| Activity subtype | Annual duty in BRV | Amount in UZS |
| Design | 2 | 880.000 |
| Construction | 4 | 1.760.000 |
| Operation | 6 | 2.640.000 |
| Services supplied by operators and providers | 30 | 13.200.000 |
| Design, construction, operation and service provision | 40 | 17.600.000 |
Example. A licence covering only data-network service provision costs 30 × UZS 440.000 = UZS 13.200.000 annually. For the combined activity subtype, the rate is 40 × UZS 440.000 = UZS 17.600.000. This compares two statutory rates for different scopes of activity.
The next annual payment is due at least 30 days before the next year of licence use begins. Failure to pay on time results in suspension. The deadline relates to the licence-use year, and does not automatically coincide with the beginning of a calendar year.
Data transmission is subject to a licence of indefinite duration (Licensing Law, Article 16). Indefinite duration does not remove the annual duty. Operation and services of cellular and television/radio distribution networks are exceptions to the indefinite-duration regime.
What obligations continue after licensing
Operators and providers must comply with licence conditions and service rules, maintain service quality, publish quality assessment methods, preserve the confidentiality of calls and messages, and provide timely information about service conditions and tariff changes. They must also develop their networks in accordance with the prescribed procedure, compensate losses caused by contractual breaches, supply service information free of charge and accept requests through subscriber support centres. These are operator and provider obligations (Telecommunications Law, Article 27).
Separate requirements cover certification of technical equipment (Telecommunications Law, Article 14) and mandatory network attestation (Article 15) for processing state secrets or confidential information. That article provides voluntary attestation for other networks.
For operational investigative activities, operators and providers must arrange through the specially authorized body the purchase, installation and normal operation of the required equipment at their own expense (Telecommunications Law, Article 23). Equipment specifications are agreed with that body; only the specially authorized body deploys and uses it for those activities. Compliance with instructions, provision of the necessary conditions and statutory coordination of connections to other systems are mandatory.
Which assets are critical information infrastructure
Critical information infrastructure, or CII, covers systems of strategic and socioeconomic importance. CII entities may include state organizations, owners and lessees of assets, other lawful holders, and persons operating assets or ensuring their interaction. Consequently, private ownership does not exclude CII status (Cybersecurity Law, Article 3).
The law names systems used in public administration and public services; defence; state security; law enforcement; the fuel and energy complex and nuclear energy; chemicals and petrochemicals; metallurgy; water use and supply; agriculture; healthcare; housing and utilities; banking and finance; transport; information and communications technologies; ecology and environmental protection; extraction and processing of strategic minerals; and manufacturing. The list is open and also covers other economic and social sectors.
Being in a named sector does not replace categorization of the particular asset. The law distinguishes high, medium and low levels (Cybersecurity Law, Article 26); the authorized body determines the criteria. It also maintains the unified CII register (Article 27).
The authorized cybersecurity body is the State Security Service, or SSS (Cybersecurity Law, Article 11). Its lawful requirements and instructions are binding. The CII register and State Register of Personal Databases have different legal grounds and do not replace one another.
What CII owners and operators must do
CII entities must ensure continuous operation and cyber protection (Cybersecurity Law, Article 28). That article's complete list of obligations is:
- Ensure uninterrupted operation of the asset's information systems.
- Inform the authorized body of incidents.
- Assist in identifying and preventing attacks, remedying their consequences and establishing incident causes.
- Install and operate monitoring systems in compliance with technical requirements.
- Secure the asset in accordance with cybersecurity requirements.
- Follow instructions to remedy identified violations.
- Remedy the consequences of incidents and attacks.
- Provide the authorized body with access to monitoring systems or the asset for the prescribed activities.
- Notify changes to information about an asset entered in the register.
The regulation attached to Presidential Resolution PP-167 adds duties to comply with regulatory and technical requirements; notify the SSS and its working body immediately; assist them; report unlawful interference by state bodies; agree installation of protective equipment and maintain it at the entity's expense; ensure that equipment works; respond and participate in investigations; provide the prescribed access for inspectors; agree prevention and recovery plans; and participate in scheduled exercises. These are requirements for CII entities (Appendix 1, paragraph 12).
For state systems and CII assets, backups must cover at least the latest three months (Cybersecurity Law, Article 15). Storage is organized under the internal information security policy. Purchasing a cloud backup service alone does not demonstrate compliance with the retention period or recoverability.
Responsible personnel undergo attestation (Cybersecurity Law, Article 29). The protection system is connected to the authorized body's incident monitoring and management system by its decision; additional asset-specific requirements must also be agreed with that body. Personnel are attested every three years (PP-167, paragraph 5); their appointment and removal must be reported promptly. Continuing professional development is also required (Cybersecurity Law, Article 34).
Which documents and checks CII assets need
The head of the asset is responsible for its cybersecurity (PP-167, Appendix 2, paragraph 4). The head appoints specialists or a dedicated unit. The security policy, instructions, requirements and procedures for using protective measures and supervising their operation are approved by the head (paragraph 5).
The asset must have the following document groups (Appendix 2, paragraph 6):
- appointment of responsible specialists or establishment of a unit;
- approval and improvement of policies, regulations, instructions and protection rules;
- monitoring, analysis of threats, scenarios and vulnerabilities, and prevention and remediation measures;
- trial operation, acceptance tests and practical testing of protection;
- improvement of staff knowledge and practical skills;
- approved working or operational documentation;
- scheduled and unscheduled protection-system inspections;
- compliance with rules for bringing in, removing, storing, transferring and writing off storage media;
- implementation of annual planned measures.
Mandatory cybersecurity compliance examination covers state information resources, state information systems and CII information systems (Cybersecurity Law, Article 18). Cyber protection equipment and software for state systems and CII assets require mandatory certification (Article 19). Categories of assets requiring mandatory attestation are determined by legislation (Article 20).
CII cybersecurity assessments are conducted with the authorized body's permission and with specialist organizations involved (Cybersecurity Law, Article 31). Commissioning an ordinary technical audit does not replace mandatory procedures.
Additional measures apply to equipment processing confidential and secret information. They include, among other things, identification and authentication, access management, restrictions on the software environment, media protection, audits, malware protection, attack detection, integrity controls, configuration and update management, response, emergency actions, backups, monitoring and rapid recovery. These are selected technical requirements (Appendix 2, paragraph 15), applied according to the threats facing the asset.
Which data must be stored on servers in Uzbekistan
The current law does not require every category of personal data to be stored locally without exception. Mandatory storage in Uzbekistan applies to three categories (Personal Data Law, Article 27-1):
- individuals' biometric data;
- individuals' genetic data;
- data of individuals using services of telecommunications operators operating in Uzbekistan.
Other personal data may be stored and processed abroad if one condition in the same article is met: the destination is recognized as providing adequate protection; the operator adopts and complies with standard contractual clauses or binding corporate rules meeting approved requirements; or the operator complies with international personal data management and storage standards on the approved list. A supplier's general promise of security does not establish a specific legal basis.
The Cabinet has approved a list of foreign destinations. It includes, for example, Germany, the United Kingdom, Russia, Singapore, the Republic of Korea and Japan; these are examples rather than the full list. The United States entry is qualified: it covers EU-US Data Privacy Framework participants. A supplier's US address alone does not establish that this condition is met.
For destinations outside the list, the resolution requires the operator and database owner to meet legal, organizational and technical conditions set by the authorized body. An instruction to develop requirements for contractual clauses and corporate rules is not equivalent to an already approved instrument applicable to the chosen cloud service.
Cross-border transfers are also governed by separate legal grounds (Personal Data Law, Article 15). For states without adequate protection, the law lists the subject's consent to the transfer; the need to protect the constitutional order, public order, rights and freedoms, public health and morals; and cases covered by international treaties. Transfer consent does not remove mandatory local storage for the categories listed above.
Must the database be registered and hosting arrangements authorized
Registration applies to databases containing data subject to mandatory storage in Uzbekistan (Personal Data Law, Article 20). Registration follows an application-based notification procedure. Changes to registration details must be reported within ten calendar days of the change.
The same article excludes databases containing data of members of public associations or religious organizations, subject to non-disclosure to third parties; data made public by the subject; only surnames, first names and patronymics; data for a one-off admission pass; data in state automated information systems; data processed without automation; and data processed under employment legislation. Exemption from registration does not remove protection obligations.
Processing may rely on consent or another statutory ground (Personal Data Law, Article 18): performance of a contract with the subject or preparatory steps requested by them; the operator's statutory duties; protection of the subject's or another person's lawful interests; exercise of the operator's or a third party's lawful interests, or socially significant purposes without infringing subjects' rights; anonymized research; or data obtained from publicly available sources. A basis must be established separately for each processing purpose.
Processing may be entrusted to a third party with written consent, including electronic consent, for performance of a contract with the subject, or in cases provided by legislation. Responsible personnel and protection are required from collection until destruction or anonymization (Personal Data Law, Article 31). A hosting contract does not remove the database owner's own obligations.
Legal, organizational and technical measures must protect privacy, data integrity and preservation, confidentiality, and prevent unlawful processing. They must be taken by the operator, owner and third party (Personal Data Law, Article 27). Persons with access to the data must maintain confidentiality (Article 28).
When data is transferred to a third party, the subject must be notified in writing within three days (Personal Data Law, Article 23). The law excludes notification when state bodies exercise their powers, data is transferred for historical, statistical, sociological or scientific purposes, or data is collected from public sources. This is not a universal data-leak notification deadline.
Data must be destroyed on statutory grounds (Personal Data Law, Article 17): achievement of the purpose, withdrawal of consent, expiry of the agreed processing period, or a final court decision. Contracts and backup settings must therefore allow deletion duties to be performed when they arise.
What to do during an incident and whom to notify
Cybersecurity entities must prevent unlawful disclosure, theft, loss, integrity breaches, blocking and falsification of data; take timely action; restore systems promptly; notify the authorized body; preserve digital traces; and permanently retain information needed for incident analysis and cybercrime investigations. They must also exchange data with that body, comply with requirements, maintain response mechanisms and a security unit or permitted outsourcing, and provide the prescribed monitoring access. These duties of cybersecurity entities (Cybersecurity Law, Article 16) apply beyond CII alone.
| Event | Recipient | Deadline or content |
| CII incident | SSS and its working body | Immediately, under the prescribed procedure |
| Leak discovered during cross-border transfer of personal data | Authorized personal data body | Within 24 hours of discovery; detailed information about causes and measures taken within 72 hours |
| An internal incident investigation has been completed | Authorized cybersecurity body | Report the findings; an internal investigation is allowed where the necessary resources and technical capabilities exist |
The cross-border transfer resolution identifies the Migration and Personalization Department under the Ministry of Internal Affairs as the authorized body. If an event affects both CII and a cross-border transfer, notification grounds must be assessed separately: reporting to one authority does not establish compliance with the other duty.
The law provides these response measures (Cybersecurity Law, Article 23): prevention of vulnerabilities and errors; removal of malware and restriction of its spread and the attack source; isolation of assets from actual threats; and information provision to law enforcement. In practice, recovery must be coordinated with preservation of digital traces: reinstalling a system without preserving necessary information may hinder an investigation.
A public vulnerability announcement does not replace mandatory reporting to the authority. Information may be disclosed after protective measures with the cybersecurity entity's permission (Cybersecurity Law, Article 24). Incident information within the CII cybersecurity system is restricted and may be disclosed after the incident is fully resolved (Article 30).
What liability can follow violations and leaks
An incident does not automatically create identical liability for the server owner, an employee and the attacker. The particular act or omission, the person's duties, fault and consequences required by the offence must be established. Administrative and criminal sanctions apply to individuals; separate licensing fines apply to legal entities.
The following offences directly relate to the obligations discussed here. They represent only part of the possible offences. CAL means the Code of Administrative Liability of the Republic of Uzbekistan.
| Violation | Person liable and sanction | Legal basis |
| Unlawful dealings with personal data and failure to meet applicable localization and registration requirements | Citizens: 7 BRV (UZS 3.080.000); officials: 50 BRV (UZS 22.000.000) | Personal data, CAL Article 46-2, part 1 |
| Unlawful processing using artificial intelligence and dissemination through the media, telecommunications networks or the Internet | 50–100 BRV (UZS 22.000.000–44.000.000), with confiscation of the items involved | CAL Article 46-2, part 2 |
| Breach of computer-system operating rules by a person with access, causing destruction, blocking or alteration of information, or equipment disruption | Citizens: 5–7 BRV (UZS 2.200.000–3.080.000); officials: 7–10 BRV (UZS 3.080.000–4.400.000). For systems containing confidential information: respectively 7–10 and 10–15 BRV | Operating rules, CAL Article 155-1 |
| Unauthorized telecommunications network access without elements of a criminal offence | Citizens: 10–20 BRV (UZS 4.400.000–8.800.000); officials: 20–50 BRV (UZS 8.800.000–22.000.000), with confiscation of the instrument used | Network access, CAL Article 155-2 |
| Conducting licensed activities without a licence | Citizens: 15–20 BRV (UZS 6.600.000–8.800.000); officials: 20–25 BRV (UZS 8.800.000–11.000.000) | Unlicensed activity, CAL Article 165, part 4 |
| A legal entity conducting telecommunications activities without a licence or obtaining one with forged documents | 250 BRV (UZS 110.000.000) | Legal entity fine, Licensing Law, Appendix 4 |
A licensing penalty imposed on a company does not exempt its officials where grounds for their liability exist (Licensing Law, Article 52).
Example. The fine for an official under the first part of the personal data provision is 50 × UZS 440.000 = UZS 22.000.000. This calculates one statutory sanction; compensation to the injured person is determined separately and is not included.
Unlawful dealings with personal data after an administrative penalty for the same conduct may result in 100–150 BRV (Criminal Code, Article 141-2), equivalent to UZS 44.000.000–66.000.000, deprivation of a specified right for up to three years, or corrective labour for up to two years. Aggravating features are prior conspiracy by a group, repetition or dangerous recidivism, mercenary or other base motives, use of official position, or grave consequences. The corresponding sanctions are 150–200 BRV (UZS 66.000.000–88.000.000), corrective labour for two to three years, restriction of liberty for one to three years, or imprisonment for up to three years.
Creating and operating systems without prescribed protective measures, where this causes major damage or substantial harm to protected interests, may lead to up to 50 BRV (Criminal Code, Article 278-1), equivalent to up to UZS 22.000.000, or corrective labour for up to one year. Where damage is particularly large, the sanctions are 50–100 BRV (UZS 22.000.000–44.000.000) or corrective labour for one to two years. This provision concerns failure to fulfil protection duties, so liability is not confined to an outside attacker.
Harm caused unlawfully must be compensated in full (Civil Code, Article 985), including lost profits, subject to fault rules and statutory exceptions. Harm caused by an employee in performing their duties is borne by the employer (Civil Code, Article 989) in the cases prescribed by law.
Compensation for non-pecuniary harm generally depends on the wrongdoer's fault (Civil Code, Article 1021); the monetary amount is determined by the court (Article 1022) independently of compensation for property loss. It is not a fixed fine: the court considers the nature of suffering, circumstances, degree of fault, and requirements of reasonableness and fairness.
What changed in 2025–2026
- Plenum Resolution No. 21 of 24.11.2025 clarified personal data protection in civil proceedings. Where processing is unlawful, a court may require deletion of the data and destruction of backups; system owners need a workable deletion process.
- Presidential Decree UP-38 of 10.03.2026 provides that state bodies and organizations may outsource cybersecurity only to legal entities on the relevant register. Its roadmap also contains future projects: an instruction to develop regulation does not itself establish finalized technical requirements for private hosting.
- Law ZRU-1125 of 26.03.2026 changed the personal data localization regime. Server selection must follow the current distinction between data categories and storage conditions.
- Cabinet Resolution No. 415 of 29.07.2026 introduced reporting deadlines for leaks during cross-border transfers. The destination list and the separate US-company qualification must be considered when choosing an overseas supplier.
What to check in operator and hosting contracts
The review begins with the service description and allocation of roles. The contract should match the actual service to the licensed subtype, data categories to storage location, and each party's functions to protection and response obligations. This is a way of applying the requirements described above to a particular architecture, rather than a separate statutory contract template.
A workable allocation of duties requires information about the location of the primary database and backups, administrator and subcontractor access, data return and deletion, log preservation, incident reporting and recovery. Contractual information-sharing deadlines should allow each party to meet its applicable notification deadline. A technical support clause alone does not identify who preserves digital traces and prepares the report.
Providers should distinguish the service customer, database owner, processing operator and CII entity. One company may hold several roles; outsourcing some work does not automatically transfer every statutory obligation. For the customer, the review should produce documents and a technical description establishing who does what when a service fails or data leaks.
Frequently asked questions
Does selling virtual hosting require a licence?
The Telecommunications Service Rules include hosting among data-network services, and that activity subtype is licensed. Selling technical resources for storing customer information on a continuously connected server therefore requires checking the licence for those services. The label “virtual server” does not create a separate exception. The contract and licence must be compared against the actual service and authorized subtype; the company's internal network is assessed separately.
Can a customer database be stored in a foreign cloud?
The answer depends on its data. Biometrics, genetic data and data of individuals using telecommunications operators' services are subject to mandatory local storage (Personal Data Law, Article 27-1). Other data requires one of the statutory protective mechanisms for overseas storage and compliance with cross-border transfer rules. Backups, the destination country and the foreign supplier's access arrangements must also be checked.
How much time is available to report a leak?
There is no single deadline for every event discussed here. CII incidents must be reported immediately. When a leak is discovered during a cross-border personal data transfer, the operator must notify the competent authority within 24 hours of discovery and provide detailed information on the causes and measures taken within 72 hours. If both regimes apply, both grounds, recipients and deadlines must be considered.
Does a hosting contract remove responsibility for data?
There is no automatic exemption. The owner, operator and engaged third party have protection obligations from collection until destruction or anonymization (Personal Data Law, Article 31). The contract allocates work, access and communications, but does not replace a lawful processing basis or storage requirements. In a dispute, the particular breach, causation, loss and applicable fault rules matter.
Tax and Legal
legal review and updates
4b Afrosiyob Street,
Tashkent, Uzbekistan
16 September 2026