Personal data protection and localization in Uzbekistan
A company processing customer or employee data is responsible for the legal basis, security and storage location. Mandatory localization depends on the data category (Art. 27-1 of the Law). Registration takes five working days (para. 10 of the Regulation). The Personal Data Law, government regulations and model procedures govern processing; administrative and criminal codes establish liability.
At a glance:
- Anyone who processes personal data is an operator, regardless of how their business is described.
- Mandatory local storage covers biometric and genetic data and data about users of local telecommunications operators.
- State registration of a database is free (para. 9 of the Regulation); registration exemptions apply.
- Consent is one basis for processing; it does not displace localization or cross-border transfer requirements.
- For a business, the processing basis, storage location and access to data are separate conditions for operating each database.
Who is a personal data operator
An operator is a public body, individual or legal entity that processes personal data (Art. 4 of the Law). A database owner has the rights to possess, use and dispose of the database. The data subject is the individual whom the data concern. A third party has a connection with them through processing activities but is not the subject, owner or operator in the relevant relationship.
Personal data are information that identifies a person, including information recorded on paper. Processing includes collection, systematization, storage, amendment, supplementation, use, provision, dissemination, transfer, anonymization and destruction. An online shop maintaining a customer database and an employer holding employee information therefore determine their roles by what they actually do. Engaging a contractor does not remove the company's own obligations.
The Law applies regardless of the processing technology (Art. 3 of the Law). Its exclusions cover an individual's personal and household processing; creation, storage and use of archival documents; state secrets and information concerning defence and national security; and data from operational search, intelligence, counterintelligence, crime prevention, law enforcement and measures against laundering criminal proceeds. A commercial organization's ordinary customer database does not become a household activity simply because it is small.
Which databases require registration and how to apply
The database is registered, with its owner or operator acting as the applicant. The statutory requirement concerns databases containing data subject to mandatory storage in Uzbekistan (Art. 20 of the Law). The same provision exempts databases containing data:
- about members of a public association or religious organization, processed by that organization without dissemination or disclosure to third parties;
- made publicly available by the subject;
- consisting only of subjects' surnames, first names and patronymics;
- needed for a one-time entry pass to the owner's or operator's premises, or similar purposes;
- included in systems classified as state automated information systems;
- processed without automated tools;
- processed in accordance with labour legislation.
A registration exemption does not remove data security duties. Where a database mixes employee and customer records, the employment exemption cannot be extended to everything in it. A separate rule expressly requires separate employee and other subject databases (para. 6 of the Protection Level Regulation).
The current service regulation names the Department of Migration and Personalization under the Ministry of Internal Affairs of Uzbekistan as the competent authority (para. 4 of the Regulation). Applications are made in person through a Public Services Centre or the portal, the Unified Portal of Interactive Public Services, referred to below as the public services portal (para. 7 of the Regulation). Online applications can be filed at any time; one received outside working hours is treated as accepted on the next working day.
The applicant completes a questionnaire; for an in-person application, a centre employee completes it. A representative attaches a power of attorney. The information is checked and confirmed using an available identification method; applications through the portal do not require a digital signature (para. 8 of the Regulation).
The database questionnaire (Annex 2 to the Regulation) asks for the following groups of information:
- Individual applicant: surname, first name, patronymic, personal identification number of an individual (PINFL), telephone, email if available, and address.
- Legal entity applicant: full name, location, telephone, email if available, and taxpayer identification number (TIN).
- Database: name, processing start date, duration or condition for ending processing, country and address of storage, and processing purpose.
- Management: remote access, database ownership, rights to the database, whether cross-border transfer is possible, and the responsible person's full name and position.
- Data content: the categories in the form, and biometric and genetic information. For example, the form has fields for photographs, telephone numbers, employment and health; these are selected examples of its checkboxes.
| Action | Deadline or result | Basis |
| Registration or refusal | Five working days from receipt of the questionnaire | Questionnaire review, para. 10 |
| Certificate issued | On registration day, with a QR code and the authority's digital signature | Electronic certificate, para. 10 |
| Notification of changes under the Law | Within ten calendar days of the change | Changes to registration information, Art. 20 |
| Application to amend the register | Within seven working days; review takes five working days | Updating the register, para. 15 |
Both change-notification deadlines matter: seven working days do not always fall within ten calendar days. Filing before the earlier deadline allows both requirements to be met. The Regulation preserves the registration number (para. 16 of the Regulation).
Refusal is permitted for incomplete or inaccurate information (para. 11 of the Regulation). Other grounds, including a view that registration is unnecessary or inadvisable, are prohibited. A decision or failure to act may be challenged before a superior authority or a court (para. 22 of the Regulation).
A database is removed from the register on three grounds (para. 17 of the Regulation): the owner's or operator's application, cessation of their activity, or a court decision terminating processing. Following removal, the certificate becomes invalid (para. 18 of the Regulation), and the number is not reused.
Which data must be stored in Uzbekistan
The current localization rule distinguishes between personal data categories (Art. 27-1 of the Law). Individuals' biometric data, genetic data and data about individuals using telecommunications operators active in Uzbekistan must be stored in Uzbekistan. For other data, the Law provides conditions for overseas storage.
| Category | Storage requirement |
| Biometric and genetic data | Mandatory storage in Uzbekistan |
| Data about users of telecommunications operators active in Uzbekistan | Mandatory storage in Uzbekistan |
| Other personal data | Overseas storage and processing if one statutory alternative is met |
For other data, one of the following alternatives is sufficient, but actual compliance must be substantiated: the foreign state is recognized as providing adequate protection; the operator adopts and follows standard contractual clauses or binding corporate rules meeting approved requirements; or the operator follows international standards for data management and storage included in an approved list.
A cloud service contract alone does not demonstrate compliance with the second alternative. The government resolution instructs the authorities to approve requirements for contractual mechanisms (para. 7 of Resolution 415). That instruction does not establish that any contract or international certificate already qualifies. For a particular arrangement, the data category, country, recipient and applicable protection mechanism must be identified.
Special, biometric and genetic data
Special personal data concern racial or social origin, political, religious or philosophical beliefs, political party and trade union membership, physical and mental health, private life and criminal convictions. Processing is generally prohibited; the Law provides exceptions to that prohibition (Art. 25 of the Law):
- protection of state security against external and internal threats by the competent public authority;
- the subject's written consent, including an electronic document;
- publication by the subject in publicly accessible sources;
- protection of the rights and legitimate interests of the subject or others;
- activities of courts and relevant law enforcement bodies in criminal cases or enforcement proceedings;
- prosecution authorities' measures against laundering criminal proceeds and financing terrorism;
- official statistics and statistical use by other public bodies, with mandatory anonymization;
- medical and social services, diagnosis and treatment, where a healthcare worker or another person at a healthcare institution who is responsible for data protection processes the information;
- exercising rights and performing duties in employment relationships;
- protecting the legitimate interests of the subject or a third party where the subject lacks or has limited legal capacity;
- public disclosure of data, including data about candidates for elected public office;
- activities of a nongovernmental nonprofit or religious organization, political party or trade union concerning only members or employees, without disclosure to third parties without consent;
- placement of children without parental care in families and other guardianship measures;
- processing for state security purposes;
- processing of conviction records by public bodies and other persons within their powers.
Biometric data describe a person's anatomical and physiological characteristics. Genetic data concern inherited or acquired characteristics derived from analysis of a biological sample or an equivalent analysis. Their use to establish identity is permitted with the subject's consent (Art. 26 of the Law), except for implementing international treaties, administering justice, enforcement proceedings and other statutory cases. This processing basis is assessed separately from mandatory local storage.
Cross-border transfers and foreign cloud services
A transfer by an owner or operator outside Uzbekistan is a cross-border transfer (Art. 15 of the Law). The general destination rule is adequate protection of subjects' rights. Transfer to states without such protection is possible with the subject's consent to cross-border transfer; where necessary to protect the constitutional order, public order, rights and freedoms, health and morality; or in cases covered by international treaties. Transfers may be prohibited or restricted to protect those public interests, citizens' rights, defence and state security.
The government list contains 49 states and territories (Annex to Resolution 415). Selected examples include the Republic of Austria, Federal Republic of Germany, Republic of Korea, Russian Federation, Republic of Singapore, Swiss Confederation and Japan. The United States entry is qualified: it covers only companies operating within the EU-US Data Privacy Framework (footnote to the list). A server address in the United States alone is insufficient to rely on that entry.
For unlisted states, the resolution requires compliance with the authority's legal, organizational and technical conditions (para. 4). Consent to transfer must therefore be considered alongside those requirements and the rules on overseas storage. An exemption from local registration does not itself permit transfer to any country.
A separate rule permits automatic transfers to listed countries through information systems established under international agreements, without additional permits or notification (para. 4). It covers personal and anonymized data and requires measures to prevent leaks. This is a specific arrangement for those systems, not a general exemption for every cloud service.
If a leak is detected during a cross-border transfer, the operator must notify the competent authority within 24 hours (para. 4) of detection and provide detailed information about its causes and remedial measures within 72 hours. These deadlines apply to that particular situation; they should not automatically be extended to every type of incident.
This article covers the conditions for handling data. The article on marketplaces explains online platforms' obligations to buyers, contracts and payment arrangements. It is relevant when data processing supports sales through a platform.
How to obtain consent to processing
For ordinary data, consent may take any form that can be evidenced (Art. 21 of the Law). Special personal data require written consent, including an electronic document. Parents, guardians or trustees consent for minors; in their absence, the guardianship authorities do so. A legal representative acts for a person who lacks or has limited legal capacity. After death, heirs consent if the person did not consent during their lifetime; the Law also requires heirs' written consent for a person declared dead or missing by a court.
The Model Procedure specifies the contents of consent (para. 11): the operator's name and TIN, or an individual operator's details and PINFL; the subject's details and identity document; purposes; a list of data to be processed; the consent period; consent to disclosure to third parties and/or cross-border transfer; consent to publication in publicly accessible sources; and other information. The consent record should therefore show which operations and purposes the individual accepted.
Acceptance of an offer can express consent where the offer specifies the processing purposes (para. 9 of the Model Procedure). One practical way to retain evidence is to save the accepted version, date and user action. This is an example of recordkeeping, not an additional statutory document format.
If the purpose changes, the operator obtains fresh consent (Art. 19 of the Law). For example, using information collected for an order for a different purpose requires a separate assessment of the legal basis. Dissemination beyond the originally stated purposes also requires the subject's consent (Art. 14 of the Law).
Consent can be withdrawn in its original form or in writing, including an electronic document. The Model Procedure requires destruction by the next working day (para. 10) after receipt of a request to stop processing. If legislation imposes an independent retention duty, the data that must continue to be processed and their mandatory purpose are determined separately; withdrawal should not be treated as permission to destroy legally required records.
When processing without consent is permitted
Consent appears in the list of lawful processing grounds (Art. 18 of the Law), but it is not the only ground. Processing is also permitted:
- to perform a contract with the subject or take steps at their request before concluding it;
- to fulfil the owner's or operator's statutory duties;
- to protect the legitimate interests of the subject or another person;
- to exercise the rights and legitimate interests of the owner, operator or a third party, or achieve socially significant purposes, provided subjects' rights and legitimate interests are not infringed;
- for statistics and other research, with mandatory anonymization;
- where the data were obtained from publicly accessible sources.
Where processing is necessary to protect the subject's own rights and legitimate interests, it is permitted without consent until consent can be obtained. The contractual ground covers processing needed for the contract, not every subsequent use of a customer database.
Public availability presupposes consent to unrestricted access (Art. 29 of the Law) or the absence of a statutory confidentiality requirement. Inclusion in a public directory requires written consent; the subject may request removal, which may also follow an authority's or court's decision. Finding a file online does not establish that it was published lawfully. For historical, statistical, sociological and scientific research, anonymization is mandatory (Art. 16 of the Law).
How to organize data security and destruction
The owner, operator and third parties take legal, organizational and technical measures (Art. 27 of the Law) to protect private life, data integrity and preservation, maintain confidentiality and prevent unlawful processing. Employees may use data only within their official and employment duties (Art. 12 of the Law).
The company appoints a responsible unit or official (Art. 31 of the Law), approves the necessary data set, retains evidence of consent, and allows electronic requests for suspension and destruction. Processing may be entrusted to a third party on written consent, including electronic consent; to perform a contract between the owner and subject; or in statutory cases. Protection duties run from collection until destruction or anonymization.
The Model Procedure sets out the following mandatory organizational and technical actions (para. 30):
- Separate publicly accessible and nonpublic information, define processing procedures and identify authorized persons.
- Install security tools and update the software used to process nonpublic data.
- Keep database management system event logs and records of users' actions involving nonpublic data.
- Apply integrity controls and use secure channels and/or encryption to transfer nonpublic data with consent, subject to statutory exceptions.
- Use cryptographic storage protection and user identification or authentication for nonpublic data.
- For a legal entity, appoint an authorized person or unit, approve an internal policy, and establish procedures for blocking and destruction in response to requests.
The necessary protection level is determined under the government protection regulation (para. 32 of the Model Procedure). When responsible staff are transferred or their employment ends, access must be revoked by their last working day (para. 5 of the Model Procedure for the Responsible Unit or Person).
Retention is linked to the collection and processing purpose (Art. 10 of the Law). The Model Procedure separately recognizes periods established by legislation or contract (para. 5). The Law provides four destruction grounds: achievement of the purpose, withdrawal of consent, expiry of the processing period covered by consent, and a final court decision. Destruction means that data cannot be recovered (Art. 17 of the Law).
The general destruction period for those grounds is three days (para. 23 of the Model Procedure). Withdrawal is subject to the shorter next-working-day rule explained above. For unlawful processing, destruction on the demand of the subject, their representative, a court or another competent authority must occur within one working day (para. 24).
What employers must consider
An employment database is exempt from registration in the statutory case, but the employer must protect the data. Data are obtained from the employee; if they can be obtained only from third parties, prior notice and written consent are required (Art. 176 of the Labour Code). An exception covers third parties to whom the employer has referred the employee under legislation, for example for a medical examination. The employer explains the purposes, sources, methods, nature of the information and consequences of refusal, pays for protection, obtains employees' signed acknowledgment of the documents and develops safeguards with employee representatives.
The following requirements apply when transferring employee data (Art. 178 of the Labour Code):
- Written consent for disclosure to a third party, except to prevent a threat to life or health and in other statutory cases.
- Written consent for commercial purposes.
- The recipient is informed of the purpose and asked to confirm compliance; confidentiality is required, subject to the qualification for statutory data exchanges.
- Internal transfers follow a local policy acknowledged by the employee's signature.
- Only specifically authorized persons have access, limited to what their employment functions require.
- Health information is requested only insofar as it concerns the ability to perform the job.
- Employee representatives receive only the information necessary for their functions, through the statutory procedure.
An employment contract clause waiving data protection is invalid (Art. 177 of the Labour Code). Employees have free access to their data (Art. 179), including copies subject to statutory exceptions, and may request corrections and notification of previous recipients about corrected information.
Inspections, directions and access restrictions
The Law provides for state supervision and binding directions to remedy violations (Art. 8 of the Law). The current registration regulation and overseas-transfer resolution use the name Department of Migration and Personalization under the Ministry of Internal Affairs for the relevant service and notifications. The statutory article retains the authority's earlier name, so the recipient is determined with reference to the current specific instrument.
A separate procedure governs supervision of special processing conditions online, including Uzkomnazorat's powers (Annex 3 to Resolution 707). Measures include examination, monitoring, inspection, directions and submission of an administrative offence report to court. The subject of supervision must reflect the current categories requiring local storage, rather than the former all-data rule.
The procedure provides for a finding of a violation, a direction with a specific correction deadline, and, if it remains uncorrected, listing the violator and restricting access (scheme to Annex 3). Once remediation is confirmed, the resource is removed from the register and the restriction lifted. This is a separate consequence from a financial penalty.
A court may also order unlawful processing to stop, require deletion or blocking and, where full deletion is ordered, require destruction of backup copies (para. 13 of Supreme Court Plenum Resolution 21). Internal deletion procedures must therefore cover recovery copies where the judgment requires it.
The article on business inspections explains general rules on scheduling and registering inspections, admitting inspectors and challenging results. It is relevant when a notice arrives or a supervisory official visits. This article addresses the specific consequences of personal data violations.
Fines and criminal liability
The Code of Administrative Liability establishes fines of 7 and 50 BRV (Art. 46-2) for the listed unlawful data operations and breaches of the relevant localization requirements. One BRV is the base calculation unit. An individual pays 7 BRV and an official 50 BRV. These amounts have applied since 31 January 2022. A separate part covering unlawful processing using artificial intelligence and dissemination of data provides for 50–100 BRV and confiscation of the objects of the offence.
| Offence | Person liable and fine | Other available sanctions |
| Basic administrative offence | Individual: 7 BRV, UZS 3.080.000; official: 50 BRV, UZS 22.000.000 | Monetary fine under the first part |
| Offence involving artificial intelligence | Person responsible: 50–100 BRV, UZS 22.000.000–44.000.000 | Confiscation of the objects of the administrative offence |
| Basic criminal offence | Person responsible: 100–150 BRV, UZS 44.000.000–66.000.000 | Instead of a fine: deprivation of a specified right for up to three years or corrective labour for up to two years |
| Criminal offence with qualifying circumstances | Person responsible: 150–200 BRV, UZS 66.000.000–88.000.000 | Instead of a fine: corrective labour for two to three years, restriction of liberty for one to three years, or imprisonment for up to three years |
The basic criminal offence concerns the specified conduct after an administrative penalty (Art. 141-2 of the Criminal Code). The qualifying circumstances are listed separately: prior agreement by a group; repetition or commission by a dangerous recidivist; financial gain or other base motives; use of official position; and serious consequences. The table shows alternative sanctions; a fine is not automatically added to every other punishment. The current criminal provision concerning localization has applied since 31 January 2022.
Example. If an official receives the fine for the basic administrative offence, the calculation is UZS 440.000 × 50 = UZS 22.000.000. For an individual under the same provision, it is UZS 440.000 × 7 = UZS 3.080.000. These illustrate the prescribed sanctions, not two fines imposed on one person.
What changed in 2025–2026
- Since 25 December 2025, the revised regulation introduced by Resolution 821 of 24 December 2025 has provided for filing through public services centres or the portal, free service and a decision within five working days. The former review period cannot be used for the current procedure.
- Law ZRU-1115 of 21 January 2026 introduced a separate administrative offence for unlawful processing using artificial intelligence and dissemination of data. This provision took effect on 21 January 2026.
- From 27 March 2026, Law ZRU-1125 of 26 March 2026 changed registration and localization. From 25 July 2026, a special territorial legal regime (Art. 3 of the Law) allows different processing and protection rules in a territory for which a Constitutional Law establishes that regime.
- Since 3 August 2026, Resolution 415 of 29 July 2026 has established the destination list and duties where a leak occurs during a cross-border transfer.
This general account does not explain the rules of the special territory. The article on the Tashkent International Financial Centre describes its legal regime. It is relevant where a company operates within the centre.
How to respond to data subjects' requests
The operator organizes access, correction and cessation of processing as separate procedures. A subject may request information about processing (Art. 22 of the Law): confirmation of processing; grounds and purposes; methods; the owner's or operator's name and address and information about permitted recipients; data content and sources; processing and retention periods; how to exercise their rights; and details of completed or intended cross-border transfers.
The provision allows restrictions to protect others' rights. Exceptions to the duty to provide information cover prior notification, data made public by the subject or obtained from a public source, and disclosure that would infringe individuals' or legal entities' rights and legitimate interests. A refusal must be sent in writing within ten days and may be challenged before the authority or a court.
Data must be amended or supplemented on request within three days (Art. 11 of the Law); identified inaccuracies must be corrected without delay. A subject may request temporary suspension of processing (Art. 30 of the Law) if the data are incomplete, outdated, inaccurate, unlawfully obtained or unnecessary for the purpose.
On inclusion in a database, the subject receives written notice of the purposes and rights. Following disclosure to a third party, the operator gives notice within three days (Art. 23 of the Law). Written notice is not required when public bodies exercise their powers, when data are transferred for historical, statistical, sociological or scientific purposes, or when data are collected from public sources.
A decision with legal consequences based solely on automated processing is possible in the statutory cases (Art. 24 of the Law): written consent, including electronic consent; performance of a contract between the owner and subject or an earlier contract; and other statutory cases. The operator explains the decision-making process and consequences, permits objections and explains available protection. An objection must be considered and the result communicated in writing within ten days.
Decisions using artificial intelligence face an additional restriction: legally significant decisions affecting human rights and freedoms cannot rely solely on AI conclusions (Art. 7-1 of the Informatization Law as amended by ZRU-1115). A basis for automated processing therefore does not displace this specific safeguard.
Frequently asked questions
Must an ordinary customer database be registered?
The answer depends on its data and applicable exemptions. The current registration provision (Art. 20 of the Law) links registration to mandatory storage of the relevant categories in Uzbekistan. The first question is therefore whether the database contains biometric or genetic data, or data about users of local telecommunications operators within the specific rule. Each exemption is then assessed separately. A lawful registration exemption does not remove requirements for a processing basis, confidentiality or security.
Can data be stored in a foreign CRM?
A CRM is a customer relationship management system. Overseas hosting is assessed by data category and storage conditions (Art. 27-1 of the Law). Alternative safeguards are available for other data not subject to mandatory local storage. Cross-border transfer rules, the actual storage country and the recipient must also be checked. For a US company, naming the United States is insufficient: the government list includes a specific Data Privacy Framework qualification.
Is a consent checkbox on a website sufficient?
For ordinary data, the Law allows a provable form of consent (Art. 21 of the Law). The operator must nevertheless be able to show that the user accepted specified purposes, data content and processing conditions. A record without the terms themselves may be insufficient evidence. Special data require written consent, including an electronic document. Neither a checkbox nor an offer displaces requirements for storage location and overseas transfers.
Must all data be deleted after consent is withdrawn?
Withdrawal ends processing on that basis; the Model Procedure sets a next-working-day deadline (para. 10). The operator must also determine whether a separate legal duty requires retention of particular information. Retention rules recognize legislation and contracts, so legally required records should not be destroyed automatically. Continued storage needs its own purpose and legal basis, rather than the consent that has been withdrawn.
What is required after a leak during an overseas transfer?
The operator notifies the competent authority within 24 hours of detection (para. 4 of Resolution 415) and provides detailed information on the causes and remedial measures within 72 hours. Internal procedures can specify who records the detection time, prepares the notice and gathers evidence. This is a practical means of meeting the obligation; the statutory deadline does not depend on the contractor completing its own investigation.
Tax and Legal
legal review and updates
4b Afrosiyob Street,
Tashkent, Uzbekistan
16 September 2026