Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
UzbekistanChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Uzbekistan used to say that data about its citizens had to sit on machines inside the country. In March 2026 it dropped that blanket rule. Most personal data may now be stored abroad if the destination country is on a new government approved list, or you use an approved contract, or you meet international standards. Three kinds of data still cannot leave at all.
The catch
The relaxed headline stops at three walls. Face and fingerprint data, genetic data, and data about customers of telephone and internet companies must be kept inside Uzbekistan. Banks face a separate rule that bans handing the running of their systems to an outside supplier, which blocks most managed cloud arrangements. Detailed maps are handled under state-secrecy rules.
Does this apply to me?
The law is written to cover the handling of personal data whatever tools are used, and it was aimed at foreign online platforms when the storage rules were first tightened in 2021. It does not set a size or revenue threshold, so a small foreign company is treated the same as a large one. We found no clear wording that forces a foreign company to appoint a representative living in Uzbekistan, and no explicit sentence saying the law follows the data outside the country.Medium confidence
Can the data leave the country?
Mostly yes, but only if you can point to one of three permissions. Face and fingerprint data, genetic data, and data about customers of telephone and internet companies must stay in Uzbekistan. Everything else may be stored and processed abroad if the destination country is on the government's approved list, or you sign an approved standard contract or use approved group rules, or you follow recognised international data standards.Medium confidence
What do I have to do to send it abroad?
The model is an approved list. Before ordinary personal data leaves the country you need one of three things: the destination is on the Cabinet of Ministers' list of countries with adequate protection, or you use the standard contract terms or group rules approved by the data authority, or you meet recognised international data standards. The country list was signed on 29 July 2026 and started on 3 August 2026, so it is brand new. We could not read which countries are on it, and no approved standard contract template appears to have been published yet.Medium confidence
Who enforces this — and are they actually working?
The data regulator is the State Centre for Personalization, which sits under the Cabinet of Ministers. It keeps the national register of personal data databases and can issue orders that companies and individuals must obey. It is a working government body and the registration service has run since 2020, but we found no published fines or decisions, so treat enforcement as waking up rather than active. Cyber incidents are handled by a different body, the State Security Service, and banks answer separately to the Central Bank.Medium confidence
How long must I keep it, and when must I delete it?
The ceiling is clear: personal data must be destroyed once the purpose is achieved, once consent is withdrawn, once the agreed period ends, or when a court orders it. The floor is thinner. Organisations covered by the cybersecurity law must keep backup copies covering at least the last three months. We did not verify the general tax and accounting minimum keeping periods during this run, so plan on the usual company record rules as well.Medium confidence
What happens when something goes wrong?
There are two clocks and they are not the same. The privacy law itself contains no duty to report a data breach to the regulator or to the people affected — we checked the text on 18 August 2026 and found none. The cybersecurity law is where reporting lives: organisations covered by it must tell the State Security Service about cyber incidents. Banks also report to the Central Bank under its security rules. We could not confirm a firm deadline in hours for any of these.Medium confidence
What's the trap?
First, every database of personal data has to be entered in a national register — it is a notification, it is free and it takes five working days, but skipping it is still a breach. Second, breaking the personal data rules can be a crime, not just a fine, so a named person can be prosecuted. Third, the face and fingerprint wall catches ordinary products like fingerprint logins and identity checks, not just spy technology. Fourth, banks are banned from handing the running of their technology and security systems to an outside supplier, which rules out most managed cloud and outsourced security operations. Fifth, the standard contract route for sending data abroad exists on paper but no approved template appears to have been published.Medium confidence
What's about to change?
The big change already happened in March 2026 and the follow-up is still landing. The approved country list started on 3 August 2026 and can be widened or cut by the Cabinet of Ministers at any time. The approved standard contract for sending data abroad is still missing, so watch for it. A new Tashkent International Financial Centre opened its legal regime on 25 July 2026 and its law also touched the privacy law, which may create a separate rulebook inside the centre. A national cybersecurity strategy was signed in March 2026.Medium confidence
Hardest industry wall
  • All industries Закон «О персональных данных», статья 27-1, часть 2
  • Telecoms Закон «О персональных данных», статья 27-1, часть 2 (данные пользователей услуг операторов телекоммуникаций)
  • Finance Кредит бюроларининг ахборот хавфсизлиги ва киберхавфсизлигига доир минимал талаблар тўғрисидаги низом
  • Mapping and location Положение о порядке установления ограничительных грифов картографических и геодезических материалов (данных)
  • Government О мерах по организации деятельности Центра обработки данных системы «Электронное правительство»
TurkeyChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Turkey lets personal data leave, but only after you build the paperwork yourself. The regulator has never declared a single country safe, so the approved-destination list is empty. Most companies use a government-published standard contract and must file it within five working days. The regulator is busy: it fined 876 organisations in 2025.
The catch
The general rule is 'paperwork, then you may send it'. That stops being true the moment you touch payments, banking, telecoms networks, public-sector systems or critical infrastructure. Payment and electronic money firms must keep their systems, their backups and their data inside Turkey, and may only use cloud providers the central bank has approved by name.
Does this apply to me?
Yes. A company with no office in Turkey is still caught, and it is caught harder than a local one. Any organisation based outside Turkey that decides why and how Turkish people's data is used must appoint a representative inside Turkey and sign up to the public register of data controllers before it starts processing. That representative has to be a company set up in Turkey or a Turkish citizen. Turkish small businesses can escape the register if they have fewer than 50 staff and a balance sheet under 100 million lira, but there is no such let-off for foreign companies.High confidence
Can the data leave the country?
It depends entirely on your industry, which is why Turkey is rated 'sectoral'. Under the general privacy law data may leave, but only after you put an approved safeguard in place, because the regulator has not yet declared any country safe. In payments and banking the answer flips to no: systems, backups and data have to sit inside Turkey. Public bodies, critical infrastructure, telecoms networks and health records all carry their own extra restrictions on top.High confidence
What do I have to do to send it abroad?
The model is an approved-destination list, and the list is empty. Nobody can rely on their country being blessed, so almost everyone uses one of the safeguards instead. The usual route is signing one of four standard contracts the regulator publishes, then telling the regulator within five working days of signing. Group companies can instead get binding corporate rules approved, and there is a permission route for bespoke undertakings, but that route almost always fails.High confidence
Who enforces this — and are they actually working?
The Personal Data Protection Authority, and it is fully up and running. In 2025 its board met 42 times, took 2,528 decisions, handled 12,512 complaints and fined 876 organisations a combined 352.5 million lira, which is roughly 8 million US dollars. It publishes named breach announcements most weeks. Financial, telecoms and insurance regulators enforce their own rules alongside it, and a new Cybersecurity Directorate has taken over the national cyber incident centre.High confidence
How long must I keep it, and when must I delete it?
Both directions apply, and the ceiling is unusual. Turkey does not give you a fixed number of months to delete by. Instead, once your reason for holding data runs out, you must erase it at your next scheduled clear-out, and any organisation on the public register has to publish a written retention and destruction policy setting those dates. The floor comes from ordinary commercial and tax law, which forces you to keep books and invoices for years.Medium confidence
What happens when something goes wrong?
There are at least three clocks. The privacy one is 72 hours: from the moment you learn that data has been taken unlawfully, you have three days to tell the Personal Data Protection Board, and you must tell the affected people as soon as you reasonably can. If you miss the 72 hours you must still report and explain why you were late. Companies based abroad have to report too, if people in Turkey are affected.High confidence
What's the trap?
Five things bite people. One: most fines are for paperwork, not privacy. Two thirds of the organisations fined in 2025 were punished for the public register, not for mishandling anyone's data. Two: the bespoke permission route for sending data abroad is close to a dead end, with 76 of 89 applications refused in 2025. Three: filing your standard contract invites inspection rather than closing the file. Four: your representative in Turkey must be Turkish. Five: no country is on the safe list, so there is no shortcut.High confidence
What's about to change?
Two dated items and one direction of travel. Retailers running loyalty cards have until 28 February 2027 to build a way of checking that the person at the till really owns the card, after the regulator extended the original deadline in July 2026. Public bodies are working to a July 2026 ruling on what they may publish online. And the government is pushing openly on data sovereignty, with the President chairing a cyber security meeting in May 2026 that treated data as a strategic asset.High confidence
Hardest industry wall
  • Payments Odeme ve Elektronik Para Kuruluslarinin Bilgi Sistemleri ile Odeme Hizmeti Saglayicilarinin Odeme Hizmetleri Alanindaki Veri Paylasim Servislerine Iliskin Teblig
  • Banking Bankalarin Bilgi Sistemleri ve Elektronik Bankacilik Hizmetleri Hakkinda Yonetmelik
  • Government 2019/12 sayili Bilgi ve Iletisim Guvenligi Tedbirleri Genelgesi ve Bilgi ve Iletisim Guvenligi Rehberi