Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
UzbekistanChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Uzbekistan used to say that data about its citizens had to sit on machines inside the country. In March 2026 it dropped that blanket rule. Most personal data may now be stored abroad if the destination country is on a new government approved list, or you use an approved contract, or you meet international standards. Three kinds of data still cannot leave at all.
The catch
The relaxed headline stops at three walls. Face and fingerprint data, genetic data, and data about customers of telephone and internet companies must be kept inside Uzbekistan. Banks face a separate rule that bans handing the running of their systems to an outside supplier, which blocks most managed cloud arrangements. Detailed maps are handled under state-secrecy rules.
Does this apply to me?
The law is written to cover the handling of personal data whatever tools are used, and it was aimed at foreign online platforms when the storage rules were first tightened in 2021. It does not set a size or revenue threshold, so a small foreign company is treated the same as a large one. We found no clear wording that forces a foreign company to appoint a representative living in Uzbekistan, and no explicit sentence saying the law follows the data outside the country.Medium confidence
Can the data leave the country?
Mostly yes, but only if you can point to one of three permissions. Face and fingerprint data, genetic data, and data about customers of telephone and internet companies must stay in Uzbekistan. Everything else may be stored and processed abroad if the destination country is on the government's approved list, or you sign an approved standard contract or use approved group rules, or you follow recognised international data standards.Medium confidence
What do I have to do to send it abroad?
The model is an approved list. Before ordinary personal data leaves the country you need one of three things: the destination is on the Cabinet of Ministers' list of countries with adequate protection, or you use the standard contract terms or group rules approved by the data authority, or you meet recognised international data standards. The country list was signed on 29 July 2026 and started on 3 August 2026, so it is brand new. We could not read which countries are on it, and no approved standard contract template appears to have been published yet.Medium confidence
Who enforces this — and are they actually working?
The data regulator is the State Centre for Personalization, which sits under the Cabinet of Ministers. It keeps the national register of personal data databases and can issue orders that companies and individuals must obey. It is a working government body and the registration service has run since 2020, but we found no published fines or decisions, so treat enforcement as waking up rather than active. Cyber incidents are handled by a different body, the State Security Service, and banks answer separately to the Central Bank.Medium confidence
How long must I keep it, and when must I delete it?
The ceiling is clear: personal data must be destroyed once the purpose is achieved, once consent is withdrawn, once the agreed period ends, or when a court orders it. The floor is thinner. Organisations covered by the cybersecurity law must keep backup copies covering at least the last three months. We did not verify the general tax and accounting minimum keeping periods during this run, so plan on the usual company record rules as well.Medium confidence
What happens when something goes wrong?
There are two clocks and they are not the same. The privacy law itself contains no duty to report a data breach to the regulator or to the people affected — we checked the text on 18 August 2026 and found none. The cybersecurity law is where reporting lives: organisations covered by it must tell the State Security Service about cyber incidents. Banks also report to the Central Bank under its security rules. We could not confirm a firm deadline in hours for any of these.Medium confidence
What's the trap?
First, every database of personal data has to be entered in a national register — it is a notification, it is free and it takes five working days, but skipping it is still a breach. Second, breaking the personal data rules can be a crime, not just a fine, so a named person can be prosecuted. Third, the face and fingerprint wall catches ordinary products like fingerprint logins and identity checks, not just spy technology. Fourth, banks are banned from handing the running of their technology and security systems to an outside supplier, which rules out most managed cloud and outsourced security operations. Fifth, the standard contract route for sending data abroad exists on paper but no approved template appears to have been published.Medium confidence
What's about to change?
The big change already happened in March 2026 and the follow-up is still landing. The approved country list started on 3 August 2026 and can be widened or cut by the Cabinet of Ministers at any time. The approved standard contract for sending data abroad is still missing, so watch for it. A new Tashkent International Financial Centre opened its legal regime on 25 July 2026 and its law also touched the privacy law, which may create a separate rulebook inside the centre. A national cybersecurity strategy was signed in March 2026.Medium confidence
Hardest industry wall
  • All industries Закон «О персональных данных», статья 27-1, часть 2
  • Telecoms Закон «О персональных данных», статья 27-1, часть 2 (данные пользователей услуг операторов телекоммуникаций)
  • Finance Кредит бюроларининг ахборот хавфсизлиги ва киберхавфсизлигига доир минимал талаблар тўғрисидаги низом
  • Mapping and location Положение о порядке установления ограничительных грифов картографических и геодезических материалов (данных)
  • Government О мерах по организации деятельности Центра обработки данных системы «Электронное правительство»
AzerbaijanChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Azerbaijan has had a personal data law since 2010. Data may leave the country, but only if you decide the destination protects it as well as Azerbaijan does, and you must declare those exports up front. The real cost is not the export rule. It is that you must register your database with the state before you collect a single record.
The catch
The easy-sounding export rule hides where the work actually is. Nothing may be collected until the system holding it sits on a state register, and the government's security rules are unusually specific, down to the encryption key length and where the archive building may stand. Banking and payments have no separate storage wall, but a new cybersecurity regime started in August 2026 and a social media law bites in 2027.
Does this apply to me?
The law is silent about foreign companies, and that silence is the answer. Unlike Europe's rules, Azerbaijan's personal data law has no clause reaching organisations abroad that sell to Azerbaijanis. What it does have is a duty on the 'owner' of a database to register it with the state before collecting anything, and that duty is enforced through the register in Baku. A foreign company with no Azerbaijani entity has no realistic way to register, and no regulator has said whether it must. From 2027 one narrow group of foreign firms is caught by name: social network providers offering services to users in Azerbaijan must set up a local branch or representative office.Medium confidence
Can the data leave the country?
Yes, with conditions, and the condition is a judgement call you make yourself. Azerbaijan bans sending personal data abroad in only two situations: where it would threaten national security, or where the destination country's law does not protect the data to the standard Azerbaijani law sets. Nobody publishes a list of good or bad countries, so you decide, and you carry the risk. If the person has consented, or if the transfer is needed to protect their life or health, the destination's standard stops mattering at all. We looked hard for industry walls in banking, payments, insurance, securities, telecoms and health and found none that force data to stay in the country.High confidence
What do I have to do to send it abroad?
There is no form to file and no approval to get. You need three things instead: a lawful basis for the processing in the first place, your own written assessment that the destination country protects the data well enough, and a declaration of the transfer in your entry on the state register. That last point is the one people miss. The registration form asks you to list the categories of personal data you send to other countries and to international organisations, so an undeclared export is also a registration failure.High confidence
Who enforces this — and are they actually working?
This changed three months ago. On 3 June 2026 the President abolished the Electronic Security Service and created the National Cybersecurity Agency in its place, under the Ministry of Digital Development and Transport, with express powers over personal data as well as cyber security. The agency is real and working: it runs the state register, takes complaints about data misuse through its website, publishes advisories most weeks, and signed a cooperation agreement with Latvia's data protection inspectorate in July 2026. It is not independent of government, and we found no published fines. The register itself is the strongest evidence it functions: 444 systems are listed and the most recent approval is dated 7 August 2026.High confidence
How long must I keep it, and when must I delete it?
The ceiling is strict and the floor is thin. Once you have achieved the purpose you collected the data for, and there is no longer a need to keep it, you must destroy it without delay. If your registration is cancelled, everything in that system must be blocked immediately and destroyed. Sensitive data must go as soon as the reason for holding it disappears, unless the person agrees to it staying or being archived. In the other direction, the personal data law itself sets no minimum keeping period. The clearest floor we could verify is new: from 2026, records of a digital forensic investigation into a cyber incident must be kept for at least three years.Medium confidence
What happens when something goes wrong?
There is no personal data breach notification duty at all. The 2010 law never created one, and nothing since has added one, so losing customer records triggers no report to any regulator and no letter to the people affected. What does exist is a cyber incident duty, and it is fast: since August 2026, organisations that run information infrastructure must pass information about cyber threats, attacks and incidents to the National CERT immediately. Once the National CERT asks you something, you have 24 hours to answer a threat research request and 5 working days to answer a digital investigation request. Financial firms have a second clock through the Central Bank's FinCERT portal.High confidence
What's the trap?
Five. One: you cannot start. Collecting or processing personal data in an unregistered system is an offence, and registration takes up to a month. Two: the security rules are engineering specifications, not principles, and include a minimum 256-bit encryption key, a data centre archive system housed in a separate building, and state expert review of your system design documents. Three: every operator must set things up so that police and intelligence bodies can carry out surveillance, and must keep the methods secret. Four: the fine for breaking the data law is 300 to 500 manat, roughly 175 to 290 US dollars, which tells you the real risk is being ordered to stop, not being fined. Five: the law says data system work needs a special licence, and no licensing regime matching it appears to be running.High confidence
What's about to change?
One big date and one big gap. The big date is roughly August 2027, twelve months after publication, when Azerbaijan's minimum age of 16 for social network accounts starts. Providers must verify age using a bank card, an email address and a mobile number, must delete what they collected for that check immediately, and must open a local branch. The penalty ladder ends with a court ordering the platform's traffic in Azerbaijan cut by 90 per cent. The big gap is that the July 2026 cybersecurity law leaves the important lists and technical requirements to be written by ministries, and they are not out yet.High confidence
Hardest industry wall
  • Government “Hökumət buludu”nun (G-cloud) yaradılması və “bulud” xidmətlərinin göstərilməsi sahəsində tədbirlər haqqında Azərbaycan Respublikası Prezidentinin Fərmanı