Azerbaijan
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Azerbaijan has had a personal data law since 2010. Data may leave the country, but only if you decide the destination protects it as well as Azerbaijan does, and you must declare those exports up front. The real cost is not the export rule. It is that you must register your database with the state before you collect a single record.
Eight questions about Azerbaijan
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Azerbaijan's rules apply to my company?
The law is silent about foreign companies, and that silence is the answer. Unlike Europe's rules, Azerbaijan's personal data law has no clause reaching organisations abroad that sell to Azerbaijanis. What it does have is a duty on the 'owner' of a database to register it with the state before collecting anything, and that duty is enforced through the register in Baku. A foreign company with no Azerbaijani entity has no realistic way to register, and no regulator has said whether it must. From 2027 one narrow group of foreign firms is caught by name: social network providers offering services to users in Azerbaijan must set up a local branch or representative office.
The Law 'On Personal Data' (No. 998-IIIQ, 11 May 2010) defines its subject matter in the preamble and article 1 by reference to relations inside the country and to 'the personal data section of the national information space'. There is no article equivalent to GDPR article 3(2). Article 15.1 requires every personal data information system, including those existing before the law commenced, to pass state registration with the authorised executive body. Law No. 431-VIIQD of 30 June 2026 adds article 13-5.1 to the Information Law, requiring a provider of an age-restricted social network platform serving users in Azerbaijan to be tax-registered if an individual, or state-registered through a branch or representative office if a foreign legal entity. That branch may not carry on business in the provider's name (article 13-5.3); it exists to be a point of contact.
Sources
- Official sourceE-Qanun, legal acts database of the Ministry of JusticeLaw of the Republic of Azerbaijan 'On Personal Data' No. 998-IIIQ of 11 May 2010 — consolidated text, articles 9, 10, 13, 14, 15, 17
e-qanun.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportState Register of Personal Data Information Systems — how registration works and what happens if you skip it
registry.pdp.az
Link checked 18 August 2026
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportLaw No. 431-VIIQD of 30 June 2026 — minimum age 16 for social network accounts, new articles 13-4 and 13-5, and new article 388-4 of the Code of Administrative Offences
mincom.gov.az
Link checked 18 August 2026
Can I store my users' data outside Azerbaijan?
Yes, with conditions, and the condition is a judgement call you make yourself. Azerbaijan bans sending personal data abroad in only two situations: where it would threaten national security, or where the destination country's law does not protect the data to the standard Azerbaijani law sets. Nobody publishes a list of good or bad countries, so you decide, and you carry the risk. If the person has consented, or if the transfer is needed to protect their life or health, the destination's standard stops mattering at all. We looked hard for industry walls in banking, payments, insurance, securities, telecoms and health and found none that force data to stay in the country.
Article 14.2 of the Law 'On Personal Data' prohibits cross-border transfer where it creates a threat to the national security of Azerbaijan, or where the legislation of the receiving country does not ensure legal protection of the data at the level established by Azerbaijani legislation. Article 14.3 disapplies that test where the subject has consented or where the transfer is necessary to protect the subject's life and health. Article 14.4 puts security of the data in transit on the owner or operator. There is no published adequacy list and no published blacklist, so the assessment is entirely self-executed. Sector checks performed on 18 August 2026: the Law on Payment Services and Payment Systems and all eleven payment rules in force published by the Central Bank were read in full and contain no data-location requirement; the Central Bank's requirements for payment institutions cover physical security of the server room and penetration testing, not geography. Government is the one place where location is effectively fixed, by architecture rather than by an express ban: state information systems are being consolidated into the domestic Government Cloud. Health, education, telecom and geospatial sector location rules were searched for and none were found; see the unconfirmed list.
Sources
- Official sourceE-Qanun, legal acts database of the Ministry of JusticeLaw of the Republic of Azerbaijan 'On Personal Data' No. 998-IIIQ of 11 May 2010 — consolidated text, articles 9, 10, 13, 14, 15, 17
e-qanun.az
Link checked 18 August 2026
- Official sourceCentral Bank of the Republic of AzerbaijanLaw on Payment Services and Payment Systems — full text as published by the Central Bank (checked for storage-location rules, none found)
uploads.cbar.az
Link checked 18 August 2026
- Official sourceCentral Bank of the Republic of AzerbaijanCentral Bank — complete list of payment sector rules in force (no data-storage-location rule among them)
cbar.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportMinistry of Digital Development and Transport — Government Cloud (G-Cloud), created by Presidential Decree No. 718 of 3 June 2019
mincom.gov.az
Link checked 18 August 2026
What do I need in place before data leaves Azerbaijan?
There is no form to file and no approval to get. You need three things instead: a lawful basis for the processing in the first place, your own written assessment that the destination country protects the data well enough, and a declaration of the transfer in your entry on the state register. That last point is the one people miss. The registration form asks you to list the categories of personal data you send to other countries and to international organisations, so an undeclared export is also a registration failure.
Article 15.4.13 of the Law 'On Personal Data' requires the registration application to state 'the categories of personal data transferred across borders to other states and to international organisations'. Article 15.5 requires any change to the registered particulars to be notified in writing within 3 working days, so starting a new export route triggers a filing. Article 13.1 separately requires the subject's written consent, including consent given through the Electronic Government Information System, before personal data is passed to any third party, subject to narrow exceptions in article 13.2 for open-category data, for state bodies performing statutory functions, and for protecting life and health. The model is therefore best described as a blacklist that has never been populated, wrapped in a mandatory declaration.
Sources
- Official sourceE-Qanun, legal acts database of the Ministry of JusticeLaw of the Republic of Azerbaijan 'On Personal Data' No. 998-IIIQ of 11 May 2010 — consolidated text, articles 9, 10, 13, 14, 15, 17
e-qanun.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportState Register of Personal Data Information Systems — how registration works and what happens if you skip it
registry.pdp.az
Link checked 18 August 2026
Who enforces the rules in Azerbaijan, and what can they do?
This changed three months ago. On 3 June 2026 the President abolished the Electronic Security Service and created the National Cybersecurity Agency in its place, under the Ministry of Digital Development and Transport, with express powers over personal data as well as cyber security. The agency is real and working: it runs the state register, takes complaints about data misuse through its website, publishes advisories most weeks, and signed a cooperation agreement with Latvia's data protection inspectorate in July 2026. It is not independent of government, and we found no published fines. The register itself is the strongest evidence it functions: 444 systems are listed and the most recent approval is dated 7 August 2026.
The decree of 3 June 2026 creates the National Cybersecurity Agency (Milli Kibertehlukesizlik Agentliyi) as a public legal entity, the legal successor of the Electronic Security Service, 'operating in the field of protection of personal data'. Its charter lists, among others: maintaining the state registration and state register of personal data information resources and systems (clause 3.1.25); examining and investigating complaints from data subjects whose rights were breached by unlawful collection, processing or failure to secure personal data (3.1.24); requiring removal of breaches of the Law 'On Personal Data' (3.1.28); joint inspection of registered systems against their declared purposes (3.1.29); auditing owners and operators on request (3.1.30); and taking measures under the Code of Administrative Offences where it finds an offence (3.1.26). Certain systems are carved out: those of top-category state bodies, of bodies protecting guarded persons and strategic objects, of intelligence and counter-intelligence bodies, and personal data classified as state secret. Separately, the Computer Incident Response Centre of the Special Communication and Information Security State Service, at cert.gov.az, is active and publishing, and the Central Bank runs FinCERT for the financial sector with its own high-severity incident portal. One caveat on operational status: the register site still names the abolished Electronic Security Service and gives a registry@cert.az contact address, so government pages have not all caught up with the June 2026 reorganisation.
Sources
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportPresidential Decree of 3 June 2026 creating the National Cybersecurity Agency and giving it the personal data register, complaints and inspection functions
mincom.gov.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportMinistry of Digital Development and Transport — list of presidential decrees, showing the 3 June 2026 cybersecurity governance decree
mincom.gov.az
Link checked 18 August 2026
- Official sourceNational Cybersecurity AgencyNational Cybersecurity Agency — official site, with separate reporting channels for cyber incidents and for personal data violations
cert.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportState Register of Personal Data Information Systems — the live list of registered systems
registry.pdp.az
Link checked 18 August 2026
- Official sourceSpecial Communication and Information Security State ServiceComputer Incident Response Centre of the Special Communication and Information Security State Service — active advisories dated 18 August 2026
cert.gov.az
Link checked 18 August 2026
- Official sourceCentral Bank of the Republic of AzerbaijanCentral Bank — FinCERT, the financial sector incident response centre, with its high-severity incident reporting portal
cbar.az
Link checked 18 August 2026
How long do I have to keep the data?
The ceiling is strict and the floor is thin. Once you have achieved the purpose you collected the data for, and there is no longer a need to keep it, you must destroy it without delay. If your registration is cancelled, everything in that system must be blocked immediately and destroyed. Sensitive data must go as soon as the reason for holding it disappears, unless the person agrees to it staying or being archived. In the other direction, the personal data law itself sets no minimum keeping period. The clearest floor we could verify is new: from 2026, records of a digital forensic investigation into a cyber incident must be kept for at least three years.
Ceilings: article 9.4 of the Law 'On Personal Data' requires destruction without delay once the collection and processing purposes are achieved and the need to store the data has passed; article 9.8 requires special-category data to be blocked and destroyed without delay once the ground for holding it falls away, unless the subject consents to storage or archiving; article 15.6 requires immediate blocking and destruction where state registration of the system is cancelled. Article 5.10 defers archiving rules to separate archive legislation. Floors: article 20-12.6 inserted by Law No. 454-VIIQD of 14 July 2026 requires the formalisation and results of a digital investigation, together with the supporting documents, to be kept by the research centre for not less than 3 years. Article 9.12 of the personal data law requires control and audit logs of processing operations to be maintained, but sets no period. General tax and accounting retention floors were not verified in this pass and are listed as unconfirmed.
Sources
- Official sourceE-Qanun, legal acts database of the Ministry of JusticeLaw of the Republic of Azerbaijan 'On Personal Data' No. 998-IIIQ of 11 May 2010 — consolidated text, articles 9, 10, 13, 14, 15, 17
e-qanun.az
Link checked 18 August 2026
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportLaw No. 454-VIIQD of 14 July 2026 amending the Law on Information, Informatisation and Protection of Information — new articles 20-7 to 20-12
mincom.gov.az
Link checked 18 August 2026
What happens if there is a breach?
There is no personal data breach notification duty at all. The 2010 law never created one, and nothing since has added one, so losing customer records triggers no report to any regulator and no letter to the people affected. What does exist is a cyber incident duty, and it is fast: since August 2026, organisations that run information infrastructure must pass information about cyber threats, attacks and incidents to the National CERT immediately. Once the National CERT asks you something, you have 24 hours to answer a threat research request and 5 working days to answer a digital investigation request. Financial firms have a second clock through the Central Bank's FinCERT portal.
The Law 'On Personal Data' contains no breach reporting article; article 5.8 requires technical and organisational measures against accidental and unauthorised destruction, loss, unlawful interference and alteration, but with no notification consequence. The Cabinet-approved Requirements for the Protection of Personal Data require timely detection of unlawful interference and an internal written finding after a confidentiality breach, again with no external report. The incident clocks come from Law No. 454-VIIQD of 14 July 2026, which inserts article 20-9.1.8 (pass cyber threat, attack and incident information to the National CERT immediately, keep statistics and file analytical reports quarterly), article 20-9.1.2 (24 hours for proactive cybersecurity research requests, 5 working days for digital investigation requests) and article 20-10.9 (the same 24-hour and 5-working-day clocks for internet providers, hosting providers and owners of internet information resources). The National Cybersecurity Agency has been designated as the National CERT.
Sources
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportLaw No. 454-VIIQD of 14 July 2026 amending the Law on Information, Informatisation and Protection of Information — new articles 20-7 to 20-12
mincom.gov.az
Link checked 18 August 2026
- Official sourcePresident of the Republic of AzerbaijanPresidential decree of 10 August 2026 implementing Law No. 454-VIIQD of 14 July 2026
president.az
Link checked 18 August 2026
- Official sourceNational Cybersecurity AgencyNational Cybersecurity Agency, 10 August 2026 — the agency is designated as the National CERT under the new cybersecurity law
cert.az
Link checked 18 August 2026
- Official sourceCabinet of Ministers, published by the Ministry of Digital Development and TransportRequirements for the Protection of Personal Data (approved under Presidential Decree No. 275 of 4 June 2010)
registry.pdp.az
Link checked 18 August 2026
- Official sourceCentral Bank of the Republic of AzerbaijanCentral Bank — FinCERT, the financial sector incident response centre, with its high-severity incident reporting portal
cbar.az
Link checked 18 August 2026
What trips people up in Azerbaijan?
Five. One: you cannot start. Collecting or processing personal data in an unregistered system is an offence, and registration takes up to a month. Two: the security rules are engineering specifications, not principles, and include a minimum 256-bit encryption key, a data centre archive system housed in a separate building, and state expert review of your system design documents. Three: every operator must set things up so that police and intelligence bodies can carry out surveillance, and must keep the methods secret. Four: the fine for breaking the data law is 300 to 500 manat, roughly 175 to 290 US dollars, which tells you the real risk is being ordered to stop, not being fined. Five: the law says data system work needs a special licence, and no licensing regime matching it appears to be running.
(1) Article 15.2 of the Law 'On Personal Data' bars collection and processing in a system that should be registered but is not; article 15.4 gives the authority one month to register. Cabinet Decision No. 237 of 17 December 2010 exempts state secret systems, employee and site-access systems, and a set of categories only where they hold fewer than 1,000 subjects, so an ordinary customer database is generally in scope. (2) The Requirements for the Protection of Personal Data set out 23 mandatory measures at clause 2.1, including 2.1.17 (archive system of the data centre located in a separate building), 2.1.21 (encryption key length not less than 256 bits), 2.1.18 (licensed software only), 2.1.20 (users must reach the system through their own protection servers) and 2.1.23 (state expertise of the system's design documents). Controlling bodies monitor compliance at least once a year. (3) Article 10.5 of the personal data law requires the operator to create the conditions for intelligence, counter-intelligence and operational search measures, resolve the organisational and technical issues, and observe the confidentiality of the methods used. (4) Article 375 of the Code of Administrative Offences sets 300 to 500 manat for processing in an unregistered system and for failing to secure or destroy data; article 379 sets 3,000 to 4,000 manat on legal persons for using an uncertified information system or database. (5) Article 9.14 states that forming personal data information resources, creating information systems and providing services to them may be carried out only under a special permission (licence); we found no operating licence scheme matching this, so it reads as unenforced text.
Sources
- Official sourceE-Qanun, legal acts database of the Ministry of JusticeLaw of the Republic of Azerbaijan 'On Personal Data' No. 998-IIIQ of 11 May 2010 — consolidated text, articles 9, 10, 13, 14, 15, 17
e-qanun.az
Link checked 18 August 2026
- Official sourceCabinet of Ministers, published by the Ministry of Digital Development and TransportRequirements for the Protection of Personal Data (approved under Presidential Decree No. 275 of 4 June 2010)
registry.pdp.az
Link checked 18 August 2026
- Official sourceCabinet of Ministers, published by the Ministry of Digital Development and TransportCabinet of Ministers Decision No. 237 of 17 December 2010 — personal data information systems that do not have to be registered
registry.pdp.az
Link checked 18 August 2026
- Official sourceE-Qanun, Ministry of JusticeCode of Administrative Offences of the Republic of Azerbaijan, 29 December 2015 — articles 375, 379, 388-1
e-qanun.az
Link checked 18 August 2026
What is changing soon in Azerbaijan?
One big date and one big gap. The big date is roughly August 2027, twelve months after publication, when Azerbaijan's minimum age of 16 for social network accounts starts. Providers must verify age using a bank card, an email address and a mobile number, must delete what they collected for that check immediately, and must open a local branch. The penalty ladder ends with a court ordering the platform's traffic in Azerbaijan cut by 90 per cent. The big gap is that the July 2026 cybersecurity law leaves the important lists and technical requirements to be written by ministries, and they are not out yet.
Law No. 431-VIIQD of 30 June 2026 amends the Information Law, the Law on Protection of Children from Harmful Information and the Code of Administrative Offences. Article 4.1 provides that the law enters into force twelve months after the day it is published; the implementing presidential decree is dated 5 August 2026, so commencement falls around August 2027. Before commencement, providers must have the technical means for age checks in place and must tell the designated body (article 4.2); after commencement they must block and delete accounts of under-16s who cannot prove their age (article 4.3). The age-verification data may not be stored in the provider's own system, may not be passed to third parties, may not be used for commercial or targeted advertising, and must be deleted the moment the check finishes (articles 13-4.8 and 13-4.9). Enforcement under article 13-5.6 runs: written warning, then 100,000 manat (about 59,000 US dollars), then 300,000 manat (about 176,000 US dollars), then a ban on state bodies and Azerbaijani taxpayers advertising on the platform, then court-ordered traffic throttling of 20 per cent, then 50 per cent, then 90 per cent. New article 388-4 of the Code of Administrative Offences adds fines on legal persons of up to 40,000 manat (about 23,500 US dollars). Dormant switches to watch, all of which can move without consultation: the list of platforms caught by the age rule is set by a body the executive designates; the government may at any time treat a named country as failing the article 14.2 protection test, since nothing has to be published; the National Cybersecurity Agency's charter lets it restrict a seller's activity in the country for e-commerce disclosure failures; and the list of internet resources carrying prohibited information, which providers must block immediately, is administrative.
Sources
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportLaw No. 431-VIIQD of 30 June 2026 — minimum age 16 for social network accounts, new articles 13-4 and 13-5, and new article 388-4 of the Code of Administrative Offences
mincom.gov.az
Link checked 18 August 2026
- Official sourceNational Cybersecurity AgencyNational Cybersecurity Agency, 6 August 2026 — explanation of the minimum age 16 rule for social network accounts
cert.az
Link checked 18 August 2026
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportLaw No. 454-VIIQD of 14 July 2026 amending the Law on Information, Informatisation and Protection of Information — new articles 20-7 to 20-12
mincom.gov.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportMinistry of Digital Development and Transport — list of presidential decrees, showing the 3 June 2026 cybersecurity governance decree
mincom.gov.az
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
5 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
3 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules5 rules
Fərdi məlumatlar haqqında Azərbaycan Respublikasının Qanunu
Act of parliament · Law No. 998-IIIQ of 11 May 2010, as amended to 28 June 2024
Azerbaijan's core privacy law. Data may go abroad unless it threatens national security or the destination protects it worse than Azerbaijan does, a test you apply yourself. Consent overrides the test. The heavier duty is that no personal data system may operate until the state has registered it.
Enforced by National Cybersecurity Agency
Transfer model: Blocklist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Someone's life is at risk
What it makes you do
- Register or notifyEvery personal data information system must pass state registration before any collection or processing begins. Registration takes up to one month.
- Get consentWritten consent, including through the Electronic Government Information System, is the main basis, and is required again before data goes to any third party.
- Tell people what you doAt collection you must tell the person who you are, why you want the data, the protection level of the system, whether it is certified, who will use the data and what rights they have.
- Let people see their data — within 168 hours7 working days to answer, extendable by another 7 where a third party must be asked.
- Let people correct their data
- Let people delete their data
- Secure the dataTechnical and organisational measures against loss, unlawful interference and alteration.
- Delete data after a periodDestroy without delay once the purpose is achieved and there is no further need to store.
- Put a transfer safeguard in placeSelf-assessment that the destination's law protects data to the Azerbaijani standard.
- Written vendor contractAn owner may delegate processing to an operator only by contract and only on condition that protection is assured.
- Extra vendor secrecy termsIndividuals working with personal data must sign a written undertaking not to disclose it, binding during and after employment.
- Keep logsControl and audit journals of processing, requests and system administration must be kept. No period is stated.
What it costs if you get it wrong
- Fixed maximum fine: 500 manat — about $294Processing in an unregistered system, failing to secure data, failing to destroy it when required, or failing to stop processing when required (Code of Administrative Offences article 375)
- Order to stopThe supervisor may require removal of breaches; cancellation of registration forces immediate blocking and destruction of everything in the system
- Claims by individualsCourts determine material and moral damage caused to the subject, payable by the owner (article 10.1)
Sources
- Official sourceE-Qanun, legal acts database of the Ministry of JusticeLaw of the Republic of Azerbaijan 'On Personal Data' No. 998-IIIQ of 11 May 2010 — consolidated text, articles 9, 10, 13, 14, 15, 17
e-qanun.az
Link checked 18 August 2026
- Official sourceE-Qanun, Ministry of JusticeLaw 'On Personal Data' No. 998-IIIQ — record card showing status 'in force', adopted 11 May 2010, registered 1 July 2011
e-qanun.az
Link checked 18 August 2026
- Official sourceE-Qanun, Ministry of JusticeCode of Administrative Offences of the Republic of Azerbaijan, 29 December 2015 — articles 375, 379, 388-1
e-qanun.az
Link checked 18 August 2026
Dövlət qeydiyyatı tələb olunmayan fərdi məlumatların informasiya sistemləri
Directly binding regulation · Cabinet of Ministers Decision No. 237 of 17 December 2010, made under Presidential Decree No. 275 of 4 June 2010
The register is the gate. You may not collect personal data until your system is on it. The exemptions are narrow: state secrets, staff records, and a handful of categories only while they hold fewer than 1,000 people. The register is public, holds 444 systems, and was last added to on 7 August 2026.
Enforced by National Cybersecurity Agency
Transfer model: Blocklist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision
What it makes you do
- Register or notify — applies at: All personal data systems except state secret systems, employee and site-access systems, and named categories holding fewer than 1,000 data subjectsThe application must set out the legal basis, purposes, data categories, subject categories, users, audit mechanisms, connected systems and the categories of data sent to other countries.
- Keep records of processingAny change to the registered particulars must be notified in writing within 3 working days.
- Put a transfer safeguard in placeCross-border transfer categories must be declared on the registration form.
What it costs if you get it wrong
- Fixed maximum fine: 500 manat — about $294Collecting or processing personal data in a system that should be registered and is not (article 375.0.1)
Sources
- Official sourceCabinet of Ministers, published by the Ministry of Digital Development and TransportCabinet of Ministers Decision No. 237 of 17 December 2010 — personal data information systems that do not have to be registered
registry.pdp.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportState Register of Personal Data Information Systems — how registration works and what happens if you skip it
registry.pdp.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportState Register of Personal Data Information Systems — the live list of registered systems
registry.pdp.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportMinistry of Digital Development and Transport — Registers page, linking the State Register of Personal Data Information Systems
mincom.gov.az
Link checked 18 August 2026
Fərdi məlumatların mühafizəsinə dair Tələblər
Directly binding regulation · Requirements for the Protection of Personal Data, approved by the Cabinet of Ministers under Presidential Decree No. 275 of 4 June 2010
Azerbaijan does not stop at 'appropriate measures'. A Cabinet instrument sets 23 specific engineering requirements, including a 256-bit minimum encryption key and an archive system in its own building, and requires the state to review your system design before you build.
Enforced by National Cybersecurity Agency
What it makes you do
- Secure the data23 mandatory measures, including a minimum 256-bit encryption key, the data centre archive system housed in a separate building, licensed software only, backup power and fire alarms, and users reaching the system only through their own protection servers.
- Hold a security certificateThe design documents of a personal data information system must pass state expertise, and systems requiring certification must be certified.
- Independent audit — 1 yearSupervisory bodies monitor whether protection is correctly organised at least once a year.
- Extra vendor secrecy termsWritten non-disclosure undertakings from every individual handling the data, effective after they leave.
What it costs if you get it wrong
- Fixed maximum fine: 4,000 manat — about $2 thousandLegal person using an information system or database that should be certified and is not (Code of Administrative Offences article 379)
Sources
- Official sourceCabinet of Ministers, published by the Ministry of Digital Development and TransportRequirements for the Protection of Personal Data (approved under Presidential Decree No. 275 of 4 June 2010)
registry.pdp.az
Link checked 18 August 2026
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportPresidential Decree No. 275 of 4 June 2010 on implementing the Law 'On Personal Data'
registry.pdp.az
Link checked 18 August 2026
- Official sourceE-Qanun, Ministry of JusticeCode of Administrative Offences of the Republic of Azerbaijan, 29 December 2015 — articles 375, 379, 388-1
e-qanun.az
Link checked 18 August 2026
Kibertəhlükəsizlik sahəsində idarəetmənin təkmilləşdirilməsi ilə bağlı tədbirlər haqqında Azərbaycan Respublikası Prezidentinin Fərmanı
Directly binding regulation · Presidential Decree of 3 June 2026 creating the National Cybersecurity Agency and approving its charter
The supervisor changed in June 2026. The Electronic Security Service was abolished and the National Cybersecurity Agency took its place, with express personal data functions: running the register, taking complaints, inspecting, auditing and bringing administrative cases. It is inside the ministry, not independent of it.
Enforced by National Cybersecurity Agency
What it makes you do
- Register or notifyThe register of personal data systems now sits with the National Cybersecurity Agency.
- Independent auditThe agency may audit an owner or operator on request, and inspect registered systems jointly with other state bodies against their declared purposes.
- Publish a complaints contactData subjects complain to the agency directly, through a dedicated channel on its website.
What it costs if you get it wrong
- Order to stopThe agency may demand removal of breaches of the personal data law and may restrict an online seller's activity in Azerbaijan for e-commerce disclosure failures
Sources
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportPresidential Decree of 3 June 2026 creating the National Cybersecurity Agency and giving it the personal data register, complaints and inspection functions
mincom.gov.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportMinistry of Digital Development and Transport — list of presidential decrees, showing the 3 June 2026 cybersecurity governance decree
mincom.gov.az
Link checked 18 August 2026
- Official sourceNational Cybersecurity AgencyNational Cybersecurity Agency — official site, with separate reporting channels for cyber incidents and for personal data violations
cert.az
Link checked 18 August 2026
“İnformasiya, informasiyalaşdırma və informasiyanın mühafizəsi haqqında” Azərbaycan Respublikasının Qanununda dəyişiklik edilməsi barədə Qanun
Act of parliament · Law No. 454-VIIQD of 14 July 2026, implemented by presidential decree of 10 August 2026
Azerbaijan's first real cybersecurity framework, signed in July 2026 and published in August. It creates a National CERT, defines critical and publicly significant information infrastructure, and sets very short clocks: report incidents immediately, answer the National CERT in 24 hours.
Enforced by National Cybersecurity Agency
What it makes you do
- Report cyber incidentsInformation about cyber threats, attacks and incidents goes to the National CERT immediately, with quarterly analytical reports on top.
- Report cyber incidents — within 24 hoursRequests from the National CERT about cyber security posture or proactive threat research must be answered within 24 hours; digital investigation requests within 5 working days. Internet providers, hosting providers and owners of internet resources are caught by name.
- Secure the dataOperators of information infrastructure performing publicly significant functions must run continuous real-time monitoring and a centralised incident management system.
- Keep data for a minimum period — 3 yearsDigital investigation records and supporting documents kept at least 3 years.
- Keep records of processingThe list of information infrastructure performing publicly significant functions is compiled by sector regulators and sent to the National CERT within 10 working days of any update.
Sources
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportLaw No. 454-VIIQD of 14 July 2026 amending the Law on Information, Informatisation and Protection of Information — new articles 20-7 to 20-12
mincom.gov.az
Link checked 18 August 2026
- Official sourcePresident of the Republic of AzerbaijanLaw amending the Law on Information, Informatisation and Protection of Information, published on the President's official site, 10 August 2026
president.az
Link checked 18 August 2026
- Official sourcePresident of the Republic of AzerbaijanPresidential decree of 10 August 2026 implementing Law No. 454-VIIQD of 14 July 2026
president.az
Link checked 18 August 2026
- Official sourceNational Cybersecurity AgencyNational Cybersecurity Agency, 10 August 2026 — the agency is designated as the National CERT under the new cybersecurity law
cert.az
Link checked 18 August 2026
Industry rules3 rules
Azərbaycan Respublikasının İnzibati Xətalar Məcəlləsində, “İnformasiya, informasiyalaşdırma və informasiyanın mühafizəsi haqqında” və “Uşaqların zərərli informasiyadan qorunması haqqında” Azərbaycan Respublikasının qanunlarında dəyişiklik edilməsi barədə Qanun
Act of parliament · Law No. 431-VIIQD of 30 June 2026; implementing presidential decree of 5 August 2026; commences twelve months after publication · Social media and online platforms
Passed, not yet in force. From about August 2027 nobody under 16 may hold a social network account in Azerbaijan. Providers must check age with a bank card, email and mobile number, delete what they collect immediately, and open a local branch, or watch their traffic throttled by court order.
Enforced by National Cybersecurity Agency
Transfer model: Not allowed
What it makes you do
- Get a parent's consent for children — applies at: under 16 banned outright; 16 to 18 need a legal representative's consent, from 5 August 2027
- No tracking or ads to children — from 5 August 2027Age-verification data may not be used for commercial purposes or targeted advertising, and geolocation visibility on 16 to 18 accounts must be restricted.
- Delete data after a period — from 5 August 2027Age-verification data may not be stored in the provider's own system or passed to third parties, and must be deleted the moment the check finishes.
- Let people delete their data — from 5 August 2027Everything a user posted before turning 18 must be deletable on request by the user, their legal representative or the designated state body.
- Appoint a local representative — from 5 August 2027A foreign provider must set up a branch or representative office and register it. The branch may not trade in the provider's name.
- Publish a complaints contact — within 120 hours, from 5 August 2027A contact centre reachable in Azerbaijani, and 5 working days to answer requests from the designated state body.
What it costs if you get it wrong
- Fixed maximum fine: 300,000 manat — about $176 thousandSecond failure to establish a local branch or registration within 30 days of the first sanction
- Fixed maximum fine: 40,000 manat — about $24 thousandLegal person breaching the safe-use requirements, including storing age-check data (new article 388-4 of the Code of Administrative Offences)
- Order to stopEscalating court-ordered throttling of the platform's Azerbaijani traffic by 20, then 50, then 90 per cent, preceded by a ban on state bodies and Azerbaijani taxpayers advertising on it
Sources
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportLaw No. 431-VIIQD of 30 June 2026 — minimum age 16 for social network accounts, new articles 13-4 and 13-5, and new article 388-4 of the Code of Administrative Offences
mincom.gov.az
Link checked 18 August 2026
- Official sourceNational Cybersecurity AgencyNational Cybersecurity Agency, 6 August 2026 — explanation of the minimum age 16 rule for social network accounts
cert.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportMinistry of Digital Development and Transport — list of presidential decrees, showing the 3 June 2026 cybersecurity governance decree
mincom.gov.az
Link checked 18 August 2026
“Hökumət buludu”nun (G-cloud) yaradılması və “bulud” xidmətlərinin göstərilməsi sahəsində tədbirlər haqqında Azərbaycan Respublikası Prezidentinin Fərmanı
Government policy document · Presidential Decree No. 718 of 3 June 2019, implementing measure 2.4.5 of the Strategic Road Map approved by Presidential Decree No. 1138 of 6 December 2016 · Government
If you sell to the Azerbaijani state, location is effectively fixed. Government information systems are being consolidated into a domestic Government Cloud of four data centres, secured jointly with the state protection service. This is architecture and procurement rather than an express statutory ban on foreign hosting.
Enforced by Ministry of Digital Development and Transport
What it makes you do
- Keep the data in the countryState information systems and resources are consolidated onto a domestic platform of four data centres (active, backup, archive and test) inside Azerbaijan.
- Hold a security certificateThe data centres are built to Uptime Institute Tier III, ISO 20000 and ISO 27001.
- Prove the data stays under local controlPhysical security and cyber security of the Government Cloud are handled jointly with the Special State Protection Service.
Sources
- Official sourceMinistry of Digital Development and TransportMinistry of Digital Development and Transport — Government Cloud (G-Cloud), created by Presidential Decree No. 718 of 3 June 2019
mincom.gov.az
Link checked 18 August 2026
Azərbaycan Respublikasının İnzibati Xətalar Məcəlləsi, maddə 388-1
Act of parliament · Code of Administrative Offences article 388-1, read with the Law on Information, Informatisation and Protection of Information · Telecoms
Telecoms carries no storage rule, but it does carry a takedown reflex. Once the state adds a website to its list of prohibited resources, hosting and internet providers must cut access immediately, with fines for delay. The list is administrative and can grow without notice.
Enforced by National Cybersecurity Agency
What it makes you do
- Secure the dataHosting providers and internet providers must restrict access to a resource immediately once it is added to the state List of Information Resources Containing Prohibited Information.
What it costs if you get it wrong
- Fixed maximum fine: 2,500 manat — about $1 thousandLegal person failing to restrict access immediately after a resource is listed (article 388-1.2)
Sources
- Official sourceE-Qanun, Ministry of JusticeCode of Administrative Offences of the Republic of Azerbaijan, 29 December 2015 — articles 375, 379, 388-1
e-qanun.az
Link checked 18 August 2026
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportPresidential Decree of 3 June 2026 creating the National Cybersecurity Agency and giving it the personal data register, complaints and inspection functions
mincom.gov.az
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether the Law 'On Personal Data' binds a foreign company that has no presence in Azerbaijan but sells to Azerbaijani consumers
The law has no territorial scope article either way, and we found no regulator guidance or decision on the point. Registration is the operative duty and it presumes a filer in-country. Treat as unsettled rather than as a safe harbour.
The exact date Law No. 431-VIIQD of 30 June 2026 was published, and therefore the exact date the minimum age of 16 for social network accounts starts
The law commences twelve months after publication. We have the implementing presidential decree dated 5 August 2026 and the ministry's publication of the law dated 30 June 2026, but not the gazette publication date itself. Plan to the earlier of the two, around 30 June 2027.
Whether Law No. 454-VIIQD of 14 July 2026 is fully operative or waiting on secondary acts
The law itself contains no commencement article that we could locate, and it leaves the list of publicly significant information infrastructure, the general cyber security requirements and the CERT and SOC register rules to instruments that had not been published by 18 August 2026. We have recorded it as partly in force for that reason.
General minimum retention periods under tax, accounting and company law
Not checked in this pass. The personal data law sets a ceiling but no floor, so the practical floor almost certainly comes from tax and accounting law, which we did not verify against an official source. Do not assume there is no floor.
Sector storage rules in health, insurance, education, gaming, geospatial mapping and defence
Searched for on 18 August 2026 and none found on official sources. This is a negative finding at medium confidence, not proof of absence. Mapping and geodetic data in particular is likely restricted through state secrets legislation, which we did not read.
Whether Azerbaijan has ratified the modernised Council of Europe data convention, known as Convention 108+
The register site publishes the original 1981 convention and the Azerbaijani ratification law. Nothing on the ratification of the 2018 amending protocol was found on an Azerbaijani government domain.
Whether the licence for creating personal data information resources and systems, required by article 9.14 of the personal data law, actually exists
The text is clear that this work may only be done under a special permission, but we found no matching licence type in the ministry's licensing pages. It reads as text on the books with no live scheme behind it, which is a finding worth re-checking.
Whether the National Cybersecurity Agency has issued any administrative penalty for a personal data breach
The agency's site publishes advisories and international cooperation news, not decisions. Its charter requires an annual statistical report on cyber security and personal data protection; we could not find one published yet.
Which government body operates the register day to day since the June 2026 reorganisation
The register site still names the abolished Electronic Security Service and gives a registry@cert.az address, while the June 2026 decree moves the function to the National Cybersecurity Agency. The government pages disagree with each other.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.
Compare with
- Azerbaijan versus Argentina
- Azerbaijan versus Armenia
- Azerbaijan versus Australia
- Azerbaijan versus Austria
- Azerbaijan versus Brazil
- Azerbaijan versus Bulgaria
- Azerbaijan versus Cambodia
- Azerbaijan versus Canada
- Azerbaijan versus China
- Azerbaijan versus Croatia
- Azerbaijan versus Cyprus
- Azerbaijan versus Estonia
- Azerbaijan versus France
- Azerbaijan versus Georgia
- Azerbaijan versus Germany
- Azerbaijan versus Greece
- Azerbaijan versus Hong Kong SAR
- Azerbaijan versus Hungary
- Azerbaijan versus Iceland
- Azerbaijan versus India
- Azerbaijan versus Indonesia
- Azerbaijan versus Ireland
- Azerbaijan versus Israel
- Azerbaijan versus Italy
- Azerbaijan versus Japan
- Azerbaijan versus Latvia
- Azerbaijan versus Lithuania
- Azerbaijan versus Luxembourg
- Azerbaijan versus Malta
- Azerbaijan versus Mexico
- Azerbaijan versus Mongolia
- Azerbaijan versus Nepal
- Azerbaijan versus Netherlands
- Azerbaijan versus Poland
- Azerbaijan versus Russia
- Azerbaijan versus Saudi Arabia
- Azerbaijan versus Serbia
- Azerbaijan versus Singapore
- Azerbaijan versus Slovakia
- Azerbaijan versus Slovenia
- Azerbaijan versus South Korea
- Azerbaijan versus Spain
- Azerbaijan versus Sri Lanka
- Azerbaijan versus Sweden
- Azerbaijan versus Switzerland
- Azerbaijan versus Taiwan
- Azerbaijan versus Thailand
- Azerbaijan versus Turkey
- Azerbaijan versus Ukraine
- Azerbaijan versus United Arab Emirates
- Azerbaijan versus United Kingdom
- Azerbaijan versus United States
- Azerbaijan versus Uzbekistan