Azerbaijan
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Azerbaijan — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Azerbaijan has had a personal data law since 2010. You can send data abroad. But first you must judge that the destination country protects it as well as Azerbaijan does. You must also declare those transfers up front. The bigger cost is registration. You must register your database with the state before you collect a single record.
Data governance in Azerbaijan
The eight things that decide how you handle data about people in Azerbaijan. Same eight on every country page, so you can compare.
Who has to follow these rules
The law says nothing about foreign companies, and that silence is the answer. Azerbaijan's personal data law has no clause that reaches companies abroad selling to Azerbaijanis. Europe's rules do have one. What Azerbaijan has instead is a duty to register your database with the state before you collect anything. That duty is enforced through the register in Baku. A foreign company with no Azerbaijani entity has no realistic way to register. No regulator has said whether it must. From 2027 one narrow group of foreign firms is named: social network providers serving users in Azerbaijan must set up a local branch or representative office.
- What you have to do here:
- Register or notify · Appoint a representative
The Law 'On Personal Data' (No. 998-IIIQ, 11 May 2010) says what it covers in its preamble and article 1. It covers relations inside the country and 'the personal data section of the national information space'. It has no equivalent of article 3(2) of Europe's General Data Protection Regulation, which reaches companies with no office in Europe. Article 15.1 requires every personal data information system to pass state registration with the authorised executive body. That includes systems that already existed when the law started. Law No. 431-VIIQD of 30 June 2026 adds article 13-5.1 to the Information Law. A provider of an age-restricted social network platform serving users in Azerbaijan must be tax-registered if it is an individual. A foreign company must instead register a branch or representative office with the state. That branch may not carry on business in the provider's name (article 13-5.3). It exists only as a point of contact.
Sources
- Official sourceE-Qanun, legal acts database of the Ministry of JusticeLaw of the Republic of Azerbaijan 'On Personal Data' No. 998-IIIQ of 11 May 2010 — consolidated text, articles 9, 10, 13, 14, 15, 17
e-qanun.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportState Register of Personal Data Information Systems — how registration works and what happens if you skip it
registry.pdp.az
Link checked 18 August 2026
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportLaw No. 431-VIIQD of 30 June 2026 — minimum age 16 for social network accounts, new articles 13-4 and 13-5, and new article 388-4 of the Code of Administrative Offences
mincom.gov.az
Link checked 18 August 2026
Where the data is allowed to live
Yes, with conditions. The condition is a judgement you make yourself. Azerbaijan bans sending personal data abroad in only two situations. The first is where it would threaten national security. The second is where the destination country's law protects the data less well than Azerbaijani law does. Nobody publishes a list of good or bad countries. So you decide, and you carry the risk. If the person has consented, the destination's standard stops mattering. The same is true if the transfer is needed to protect their life or health. We looked hard for industry rules in banking, payments, insurance, securities, telecoms and health. We found none that force data to stay in the country.
- Ways to send data out:
- Official 'this country is safe' decision · Explicit consent · To save someone’s life
Article 14.2 of the Law 'On Personal Data' bans sending personal data abroad in two cases. One: where it creates a threat to the national security of Azerbaijan. Two: where the receiving country's law does not protect the data to the level Azerbaijani law sets. Article 14.3 switches that test off where the person has consented. It also switches it off where the transfer is needed to protect the person's life and health. Article 14.4 makes the owner or operator responsible for keeping the data secure in transit. Azerbaijan publishes no list of safe countries and no list of banned countries. So the judgement is entirely yours. Industry checks done on 18 August 2026: we read the Law on Payment Services and Payment Systems and all eleven payment rules in force published by the Central Bank. None of them say where data must be held. The Central Bank's requirements for payment institutions cover physical security of the server room and penetration testing, not location. Government is the one place where location is fixed. That comes from how the systems are built, not from an express ban. State information systems are being moved into the domestic Government Cloud. We searched for location rules in health, education, telecoms and mapping and found none. See the unconfirmed list.
Sources
- Official sourceE-Qanun, legal acts database of the Ministry of JusticeLaw of the Republic of Azerbaijan 'On Personal Data' No. 998-IIIQ of 11 May 2010 — consolidated text, articles 9, 10, 13, 14, 15, 17
e-qanun.az
Link checked 18 August 2026
- Official sourceCentral Bank of the Republic of AzerbaijanLaw on Payment Services and Payment Systems — full text as published by the Central Bank (checked for storage-location rules, none found)
uploads.cbar.az
Link checked 18 August 2026
- Official sourceCentral Bank of the Republic of AzerbaijanCentral Bank — complete list of payment sector rules in force (no data-storage-location rule among them)
cbar.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportMinistry of Digital Development and Transport — Government Cloud (G-Cloud), created by Presidential Decree No. 718 of 3 June 2019
mincom.gov.az
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Azerbaijan.
Sending data out of the country
There is no form to file and no approval to get. You need three things instead. First, a lawful reason to use the data at all. Second, your own written assessment that the destination country protects the data well enough. Third, a declaration of the transfer in your entry on the state register. That third point is the one people miss. The registration form asks you to list the types of personal data you send to other countries and to international organisations. So an undeclared transfer is also a registration failure.
- What you have to do here:
- Put a transfer safeguard in place · Register or notify · Get consent
Article 15.4.13 of the Law 'On Personal Data' governs the registration application. It must state 'the categories of personal data transferred across borders to other states and to international organisations'. Article 15.5 requires you to report any change to the registered details in writing within 3 working days. So starting a new transfer route means a new filing. Article 13.1 separately requires the person's written consent before their data goes to any third party. That consent can be given through the Electronic Government Information System. Article 13.2 sets narrow exceptions for open-category data, for state bodies doing their statutory jobs, and for protecting life and health. So the model works like this. You may send data anywhere except banned countries. No country has ever been banned. Every transfer must still be declared.
Sources
- Official sourceE-Qanun, legal acts database of the Ministry of JusticeLaw of the Republic of Azerbaijan 'On Personal Data' No. 998-IIIQ of 11 May 2010 — consolidated text, articles 9, 10, 13, 14, 15, 17
e-qanun.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportState Register of Personal Data Information Systems — how registration works and what happens if you skip it
registry.pdp.az
Link checked 18 August 2026
The regulator, and whether it actually acts
This changed three months ago. On 3 June 2026 the President abolished the Electronic Security Service. In its place he created the National Cybersecurity Agency. It sits under the Ministry of Digital Development and Transport and has express powers over personal data as well as cyber security. The agency is real and working. It runs the state register. It takes complaints about data misuse through its website. It publishes advisories most weeks. It signed a cooperation agreement with Latvia's data protection inspectorate in July 2026. It is not independent of government, and we found no published fines. The register is the strongest sign that it works. It lists 444 systems, and the most recent approval is dated 7 August 2026.
The decree of 3 June 2026 creates the National Cybersecurity Agency (Milli Kibertehlukesizlik Agentliyi) as a public legal entity. It is the legal successor of the Electronic Security Service and 'operating in the field of protection of personal data'. Its charter lists, among others: running the state registration and state register of personal data resources and systems (clause 3.1.25); looking into complaints from people whose rights were breached by unlawful collection, use or poor security of their personal data (3.1.24); requiring breaches of the Law 'On Personal Data' to be fixed (3.1.28); joint inspection of registered systems against their declared purposes (3.1.29); auditing owners and operators on request (3.1.30); and taking action under the Code of Administrative Offences where it finds an offence (3.1.26). Some systems are left out. Those are the systems of top-category state bodies, of bodies protecting guarded persons and strategic objects, and of intelligence and counter-intelligence bodies. Personal data classified as a state secret is also left out. Separately, the Computer Incident Response Centre of the Special Communication and Information Security State Service, at cert.gov.az, is active and publishing. The Central Bank runs FinCERT for the financial sector, with its own portal for high-severity incidents. One warning about day-to-day status. The register site still names the abolished Electronic Security Service and gives a registry@cert.az contact address. Government pages have not all caught up with the June 2026 reorganisation.
Sources
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportPresidential Decree of 3 June 2026 creating the National Cybersecurity Agency and giving it the personal data register, complaints and inspection functions
mincom.gov.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportMinistry of Digital Development and Transport — list of presidential decrees, showing the 3 June 2026 cybersecurity governance decree
mincom.gov.az
Link checked 18 August 2026
- Official sourceNational Cybersecurity AgencyNational Cybersecurity Agency — official site, with separate reporting channels for cyber incidents and for personal data violations
cert.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportState Register of Personal Data Information Systems — the live list of registered systems
registry.pdp.az
Link checked 18 August 2026
- Official sourceSpecial Communication and Information Security State ServiceComputer Incident Response Centre of the Special Communication and Information Security State Service — active advisories dated 18 August 2026
cert.gov.az
Link checked 18 August 2026
- Official sourceCentral Bank of the Republic of AzerbaijanCentral Bank — FinCERT, the financial sector incident response centre, with its high-severity incident reporting portal
cbar.az
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a strict rule on deleting data and almost no rule on keeping it. Once you have achieved the purpose you collected the data for, and no longer need it, you must destroy it without delay. If your registration is cancelled, everything in that system must be blocked immediately and destroyed. Sensitive data must go as soon as the reason for holding it disappears. The exception is where the person agrees to it being stored or archived. Going the other way, the personal data law sets no minimum keeping period. The clearest minimum we could verify is new. From 2026, records of a digital forensic investigation into a cyber incident must be kept for at least three years.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period · Keep logs
Deletion rules. Article 9.4 of the Law 'On Personal Data' requires destruction without delay once two things are true. You have achieved the purposes for collecting and using the data. And you no longer need to store it. Article 9.8 requires sensitive data to be blocked and destroyed without delay once the ground for holding it falls away, unless the person agrees to storage or archiving. Article 15.6 requires immediate blocking and destruction where state registration of the system is cancelled. Article 5.10 leaves archiving rules to separate archive legislation. Minimum keeping periods. Article 20-12.6 was added by Law No. 454-VIIQD of 14 July 2026. The research centre must keep the record and results of a digital investigation, plus the supporting documents, for not less than 3 years. Article 9.12 of the personal data law requires control and audit logs to be kept, but sets no period. We did not verify general tax and accounting minimum periods in this pass, so they are on the unconfirmed list.
Sources
- Official sourceE-Qanun, legal acts database of the Ministry of JusticeLaw of the Republic of Azerbaijan 'On Personal Data' No. 998-IIIQ of 11 May 2010 — consolidated text, articles 9, 10, 13, 14, 15, 17
e-qanun.az
Link checked 18 August 2026
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportLaw No. 454-VIIQD of 14 July 2026 amending the Law on Information, Informatisation and Protection of Information — new articles 20-7 to 20-12
mincom.gov.az
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
There is no duty to report a personal data breach at all. The 2010 law never created one, and nothing since has added one. So losing customer records means no report to any regulator and no letter to the people affected. What does exist is a duty to report cyber incidents, and it is fast. Since August 2026, organisations that run information infrastructure must pass information about cyber threats, attacks and incidents to the National Computer Emergency Response Team immediately. Once that team asks you something, you have 24 hours to answer a threat research request. You have 5 working days to answer a digital investigation request. Financial firms have a second deadline through the Central Bank's FinCERT portal.
- What you have to do here:
- Report cyber incidents · Secure the data
The Law 'On Personal Data' has no article on reporting breaches. Article 5.8 requires technical and organisational measures against accidental and unauthorised destruction, loss, unlawful interference and alteration. It attaches no duty to tell anyone. The Cabinet-approved Requirements for the Protection of Personal Data require you to detect unlawful interference in good time and to write an internal finding after a confidentiality breach. Again, nothing has to be reported outside. The incident deadlines come from Law No. 454-VIIQD of 14 July 2026. Article 20-9.1.8 requires cyber threat, attack and incident information to go to the National Computer Emergency Response Team immediately, with statistics kept and analytical reports filed quarterly. Article 20-9.1.2 gives 24 hours for proactive cybersecurity research requests and 5 working days for digital investigation requests. Article 20-10.9 sets the same 24-hour and 5-working-day deadlines for internet providers, hosting providers and owners of internet information resources. The National Cybersecurity Agency has been named as the National Computer Emergency Response Team.
Sources
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportLaw No. 454-VIIQD of 14 July 2026 amending the Law on Information, Informatisation and Protection of Information — new articles 20-7 to 20-12
mincom.gov.az
Link checked 18 August 2026
- Official sourcePresident of the Republic of AzerbaijanPresidential decree of 10 August 2026 implementing Law No. 454-VIIQD of 14 July 2026
president.az
Link checked 18 August 2026
- Official sourceNational Cybersecurity AgencyNational Cybersecurity Agency, 10 August 2026 — the agency is designated as the National CERT under the new cybersecurity law
cert.az
Link checked 18 August 2026
- Official sourceCabinet of Ministers, published by the Ministry of Digital Development and TransportRequirements for the Protection of Personal Data (approved under Presidential Decree No. 275 of 4 June 2010)
registry.pdp.az
Link checked 18 August 2026
- Official sourceCentral Bank of the Republic of AzerbaijanCentral Bank — FinCERT, the financial sector incident response centre, with its high-severity incident reporting portal
cbar.az
Link checked 18 August 2026
What catches people out
Five. One: you cannot start. Collecting or using personal data in an unregistered system is an offence, and registration takes up to a month. Two: the security rules are engineering specifications, not principles. They include a minimum 256-bit encryption key, an archive system housed in a separate building, and state expert review of your system design documents. Three: every operator must set things up so that police and intelligence bodies can carry out surveillance, and must keep the methods secret. Four: the fine for breaking the data law is 300 to 500 manat, roughly 175 to 290 US dollars. That tells you the real risk is being ordered to stop, not being fined. Five: the law says data system work needs a special licence, and no matching licence scheme appears to be running.
- What you have to do here:
- Register or notify · Secure the data · Hold a security certificate
- What it costs if you get it wrong:
- Fixed maximum fine · Order to stop
(1) Article 15.2 of the Law 'On Personal Data' bars collecting or using data in a system that should be registered but is not. Article 15.4 gives the authority one month to register it. Cabinet Decision No. 237 of 17 December 2010 exempts state secret systems, employee records and site-access systems. It also exempts a set of categories, but only while they hold fewer than 1,000 people. So an ordinary customer database is usually covered. (2) The Requirements for the Protection of Personal Data set out 23 mandatory measures at clause 2.1. They are numbered. 2.1.17: the data centre archive system must sit in a separate building. 2.1.21: encryption key length not less than 256 bits. 2.1.18: licensed software only. 2.1.20: users must reach the system through their own protection servers. 2.1.23: state review of the system's design documents. Controlling bodies check compliance at least once a year. (3) Article 10.5 of the personal data law puts three duties on the operator. Create the conditions for intelligence, counter-intelligence and operational search measures. Sort out the organisational and technical issues. And keep the methods used confidential. (4) Article 375 of the Code of Administrative Offences sets 300 to 500 manat for using an unregistered system and for failing to secure or destroy data. Article 379 sets 3,000 to 4,000 manat on companies for using an uncertified information system or database. (5) Article 9.14 says that building personal data resources, creating information systems and providing services to them may be done only under a special permission (licence). We found no licence scheme matching this, so it reads as text on the books that nobody runs.
Sources
- Official sourceE-Qanun, legal acts database of the Ministry of JusticeLaw of the Republic of Azerbaijan 'On Personal Data' No. 998-IIIQ of 11 May 2010 — consolidated text, articles 9, 10, 13, 14, 15, 17
e-qanun.az
Link checked 18 August 2026
- Official sourceCabinet of Ministers, published by the Ministry of Digital Development and TransportRequirements for the Protection of Personal Data (approved under Presidential Decree No. 275 of 4 June 2010)
registry.pdp.az
Link checked 18 August 2026
- Official sourceCabinet of Ministers, published by the Ministry of Digital Development and TransportCabinet of Ministers Decision No. 237 of 17 December 2010 — personal data information systems that do not have to be registered
registry.pdp.az
Link checked 18 August 2026
- Official sourceE-Qanun, Ministry of JusticeCode of Administrative Offences of the Republic of Azerbaijan, 29 December 2015 — articles 375, 379, 388-1
e-qanun.az
Link checked 18 August 2026
What's changing next
One big date and one big gap. The big date is roughly August 2027, twelve months after publication. That is when Azerbaijan's minimum age of 16 for social network accounts starts. Providers must check age using a bank card, an email address and a mobile number. They must delete what they collected for that check immediately. They must also open a local branch. The penalty ladder ends with a court ordering the platform's traffic in Azerbaijan cut by 90 per cent. The big gap is the July 2026 cybersecurity law. It leaves the important lists and technical requirements to ministries, and they are not out yet.
- What you have to do here:
- Get a parent's consent for children
- What it costs if you get it wrong:
- Fixed maximum fine
Law No. 431-VIIQD of 30 June 2026 amends the Information Law, the Law on Protection of Children from Harmful Information and the Code of Administrative Offences. Article 4.1 says the law starts twelve months after the day it is published. The presidential decree putting it into effect is dated 5 August 2026, so it starts around August 2027. Before it starts, providers must have the technical means for age checks in place and must tell the designated body (article 4.2). After it starts, they must block and delete accounts of under-16s who cannot prove their age (article 4.3). Age-check data may not be stored in the provider's own system. It may not be passed to third parties. It may not be used for commercial or targeted advertising. It must be deleted the moment the check finishes (articles 13-4.8 and 13-4.9). Penalties under article 13-5.6 run in steps: a written warning, then 100,000 manat (about 59,000 US dollars), then 300,000 manat (about 176,000 US dollars). Next comes a ban on state bodies and Azerbaijani taxpayers advertising on the platform. Then a court orders traffic slowed by 20 per cent, then 50 per cent, then 90 per cent. New article 388-4 of the Code of Administrative Offences adds fines on companies of up to 40,000 manat (about 23,500 US dollars). Four things can change without warning or consultation. The list of platforms caught by the age rule is set by a body the executive picks. The government may at any time treat a named country as failing the article 14.2 protection test, because nothing has to be published. The National Cybersecurity Agency's charter lets it restrict a seller's activity in the country for e-commerce disclosure failures. And the list of internet resources carrying prohibited information, which providers must block immediately, is decided administratively.
Sources
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportLaw No. 431-VIIQD of 30 June 2026 — minimum age 16 for social network accounts, new articles 13-4 and 13-5, and new article 388-4 of the Code of Administrative Offences
mincom.gov.az
Link checked 18 August 2026
- Official sourceNational Cybersecurity AgencyNational Cybersecurity Agency, 6 August 2026 — explanation of the minimum age 16 rule for social network accounts
cert.az
Link checked 18 August 2026
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportLaw No. 454-VIIQD of 14 July 2026 amending the Law on Information, Informatisation and Protection of Information — new articles 20-7 to 20-12
mincom.gov.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportMinistry of Digital Development and Transport — list of presidential decrees, showing the 3 June 2026 cybersecurity governance decree
mincom.gov.az
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Payment data rules
Official name: Azərbaycan Respublikasının İnzibati Xətalar Məcəlləsində, “İnformasiya, informasiyalaşdırma və informasiyanın mühafizəsi haqqında” və “Uşaqların zərərli informasiyadan qorunması haqqında” Azərbaycan Respublikasının qanunlarında dəyişiklik edilməsi barədə Qanun · Law No. 431-VIIQD of 30 June 2026; implementing presidential decree of 5 August 2026; commences twelve months after publication · Act of parliament
Passed, not yet in force. From about August 2027, nobody under 16 may hold a social network account in Azerbaijan. Providers must check age with a bank card, email and mobile number. They must delete what they collect immediately and open a local branch. If they do not, a court can order their traffic slowed.
Enforced by National Cybersecurity Agency
How this country controls where data goes: Not allowed
What you have to do
- Get a parent's consent for children — applies at: under 16 banned outright; 16 to 18 need a legal representative's consent, from 5 August 2027
- No tracking or ads to children — from 5 August 2027Age-verification data may not be used for commercial purposes or targeted advertising, and geolocation visibility on 16 to 18 accounts must be restricted.
- Delete data after a period — from 5 August 2027Age-verification data may not be stored in the provider's own system or passed to third parties, and must be deleted the moment the check finishes.
- Let people delete their data — from 5 August 2027Everything a user posted before turning 18 must be deletable on request by the user, their legal representative or the designated state body.
- Appoint a representative — from 5 August 2027A foreign provider must set up a branch or representative office and register it. The branch may not trade in the provider's name.
- Publish a complaints contact — within 120 hours, from 5 August 2027A contact centre reachable in Azerbaijani, and 5 working days to answer requests from the designated state body.
What it costs if you get it wrong
- Fixed maximum fine: 300,000 manat — about $176 thousandSecond failure to establish a local branch or registration within 30 days of the first sanction
- Fixed maximum fine: 40,000 manat — about $24 thousandLegal person breaching the safe-use requirements, including storing age-check data (new article 388-4 of the Code of Administrative Offences)
- Order to stopEscalating court-ordered throttling of the platform's Azerbaijani traffic by 20, then 50, then 90 per cent, preceded by a ban on state bodies and Azerbaijani taxpayers advertising on it
Sources
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportLaw No. 431-VIIQD of 30 June 2026 — minimum age 16 for social network accounts, new articles 13-4 and 13-5, and new article 388-4 of the Code of Administrative Offences
mincom.gov.az
Link checked 18 August 2026
- Official sourceNational Cybersecurity AgencyNational Cybersecurity Agency, 6 August 2026 — explanation of the minimum age 16 rule for social network accounts
cert.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportMinistry of Digital Development and Transport — list of presidential decrees, showing the 3 June 2026 cybersecurity governance decree
mincom.gov.az
Link checked 18 August 2026
Government data needs a copy kept in the country
Official name: “Hökumət buludu”nun (G-cloud) yaradılması və “bulud” xidmətlərinin göstərilməsi sahəsində tədbirlər haqqında Azərbaycan Respublikası Prezidentinin Fərmanı · Presidential Decree No. 718 of 3 June 2019, implementing measure 2.4.5 of the Strategic Road Map approved by Presidential Decree No. 1138 of 6 December 2016 · Government policy document
If you sell to the Azerbaijani state, the data has to stay in Azerbaijan. Government information systems are being moved into a domestic Government Cloud of four data centres. The state protection service helps secure them. No law expressly bans foreign hosting. It is how the systems are built and bought that fixes the location.
Enforced by Ministry of Digital Development and Transport
What you have to do
- Keep the data in the countryState information systems and resources are consolidated onto a domestic platform of four data centres (active, backup, archive and test) inside Azerbaijan.
- Hold a security certificateThe data centres are built to Uptime Institute Tier III, ISO 20000 and ISO 27001.
- Prove the data stays under local controlPhysical security and cyber security of the Government Cloud are handled jointly with the Special State Protection Service.
Sources
- Official sourceMinistry of Digital Development and TransportMinistry of Digital Development and Transport — Government Cloud (G-Cloud), created by Presidential Decree No. 718 of 3 June 2019
mincom.gov.az
Link checked 18 August 2026
Telecoms rules
Official name: Azərbaycan Respublikasının İnzibati Xətalar Məcəlləsi, maddə 388-1 · Code of Administrative Offences article 388-1, read with the Law on Information, Informatisation and Protection of Information · Act of parliament
Telecoms has no rule forcing data to stay in Azerbaijan. It does have a takedown duty. Once the state adds a website to its list of prohibited resources, hosting and internet providers must cut access immediately. Delay brings fines. The list is decided administratively and can grow without notice.
Enforced by National Cybersecurity Agency
What you have to do
- Secure the dataHosting providers and internet providers must restrict access to a resource immediately once it is added to the state List of Information Resources Containing Prohibited Information.
What it costs if you get it wrong
- Fixed maximum fine: 2,500 manat — about $1 thousandLegal person failing to restrict access immediately after a resource is listed (article 388-1.2)
Sources
- Official sourceE-Qanun, Ministry of JusticeCode of Administrative Offences of the Republic of Azerbaijan, 29 December 2015 — articles 375, 379, 388-1
e-qanun.az
Link checked 18 August 2026
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportPresidential Decree of 3 June 2026 creating the National Cybersecurity Agency and giving it the personal data register, complaints and inspection functions
mincom.gov.az
Link checked 18 August 2026
Applies to every company5 rules
These bind you whatever business you are in, once the country's rules reach you.
State and security data rules
Official name: Fərdi məlumatlar haqqında Azərbaycan Respublikasının Qanunu · Law No. 998-IIIQ of 11 May 2010, as amended to 28 June 2024 · Act of parliament
Azerbaijan's main privacy law. You can send data abroad unless it threatens national security. You also cannot send it to a country that protects it worse than Azerbaijan does. You apply that test yourself. Consent overrides it. The heavier duty is registration. No personal data system may run until the state has registered it.
Enforced by National Cybersecurity Agency
How this country controls where data goes: Any country except banned ones (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent, To save someone’s life
What you have to do
- Register or notifyEvery personal data information system must pass state registration before you collect or use any data. Registration takes up to one month.
- Get consentWritten consent is the main legal reason to use the data. It can be given through the Electronic Government Information System. You need consent again before data goes to any third party.
- Tell people what you doWhen you collect data you must tell the person who you are and why you want it. You must also tell them the protection level of the system, whether it is certified, who will use the data, and what rights they have.
- Let people see their data — within 168 hours7 working days to answer, extendable by another 7 where a third party must be asked.
- Let people correct their data
- Let people delete their data
- Secure the dataTechnical and organisational measures against loss, unlawful interference and alteration.
- Delete data after a periodDestroy without delay once the purpose is achieved and there is no further need to store.
- Put a transfer safeguard in placeYou judge for yourself whether the destination country's law protects the data to the Azerbaijani standard.
- Written vendor contractAn owner may hand the work to an operator only by contract, and only if protection is assured.
- Extra vendor secrecy termsAnyone working with personal data must sign a written promise not to disclose it. The promise binds them during and after employment.
- Keep logsYou must keep control and audit logs of data use, requests and system administration. No time period is set.
What it costs if you get it wrong
- Fixed maximum fine: 500 manat — about $294Processing in an unregistered system, failing to secure data, failing to destroy it when required, or failing to stop processing when required (Code of Administrative Offences article 375)
- Order to stopThe supervisor may require removal of breaches; cancellation of registration forces immediate blocking and destruction of everything in the system
- Claims by individualsCourts determine material and moral damage caused to the subject, payable by the owner (article 10.1)
Sources
- Official sourceE-Qanun, legal acts database of the Ministry of JusticeLaw of the Republic of Azerbaijan 'On Personal Data' No. 998-IIIQ of 11 May 2010 — consolidated text, articles 9, 10, 13, 14, 15, 17
e-qanun.az
Link checked 18 August 2026
- Official sourceE-Qanun, Ministry of JusticeLaw 'On Personal Data' No. 998-IIIQ — record card showing status 'in force', adopted 11 May 2010, registered 1 July 2011
e-qanun.az
Link checked 18 August 2026
- Official sourceE-Qanun, Ministry of JusticeCode of Administrative Offences of the Republic of Azerbaijan, 29 December 2015 — articles 375, 379, 388-1
e-qanun.az
Link checked 18 August 2026
State and security data rules (2010)
Official name: Dövlət qeydiyyatı tələb olunmayan fərdi məlumatların informasiya sistemləri · Cabinet of Ministers Decision No. 237 of 17 December 2010, made under Presidential Decree No. 275 of 4 June 2010 · Directly binding regulation
You may not collect personal data until your system is on the state register. The exemptions are narrow. They cover state secrets, staff records, and a few categories, but only while they hold fewer than 1,000 people. The register is public. It holds 444 systems and was last added to on 7 August 2026.
Enforced by National Cybersecurity Agency
How this country controls where data goes: Any country except banned ones (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision
What you have to do
- Register or notify — applies at: All personal data systems except state secret systems, employee and site-access systems, and named categories holding fewer than 1,000 data subjectsYour application must set out the legal basis and the purposes. It must list the types of data, the types of people involved and the users. It must also list the audit methods, connected systems, and the types of data you send to other countries.
- Keep records of how you use dataAny change to the registered particulars must be notified in writing within 3 working days.
- Put a transfer safeguard in placeYou must list the types of data you send to other countries on the registration form.
What it costs if you get it wrong
- Fixed maximum fine: 500 manat — about $294Collecting or processing personal data in a system that should be registered and is not (article 375.0.1)
Sources
- Official sourceCabinet of Ministers, published by the Ministry of Digital Development and TransportCabinet of Ministers Decision No. 237 of 17 December 2010 — personal data information systems that do not have to be registered
registry.pdp.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportState Register of Personal Data Information Systems — how registration works and what happens if you skip it
registry.pdp.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportState Register of Personal Data Information Systems — the live list of registered systems
registry.pdp.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportMinistry of Digital Development and Transport — Registers page, linking the State Register of Personal Data Information Systems
mincom.gov.az
Link checked 18 August 2026
Secrecy duties for regulated professions
Official name: Fərdi məlumatların mühafizəsinə dair Tələblər · Requirements for the Protection of Personal Data, approved by the Cabinet of Ministers under Presidential Decree No. 275 of 4 June 2010 · Directly binding regulation
Azerbaijan does not stop at 'appropriate measures'. A Cabinet decision sets 23 specific engineering requirements. They include a 256-bit minimum encryption key and an archive system in its own building. The state must also review your system design before you build.
Enforced by National Cybersecurity Agency
What you have to do
- Secure the dataThere are 23 mandatory measures. They include a minimum 256-bit encryption key, the data centre archive system housed in a separate building, licensed software only, and backup power and fire alarms. Users must also reach the system only through their own protection servers.
- Hold a security certificateThe design documents of a personal data information system must pass state review. Systems that need certification must be certified.
- Independent audit — 1 yearSupervisory bodies monitor whether protection is correctly organised at least once a year.
- Extra vendor secrecy termsEveryone who handles the data must sign a written promise not to disclose it. The promise still applies after they leave.
What it costs if you get it wrong
- Fixed maximum fine: 4,000 manat — about $2 thousandLegal person using an information system or database that should be certified and is not (Code of Administrative Offences article 379)
Sources
- Official sourceCabinet of Ministers, published by the Ministry of Digital Development and TransportRequirements for the Protection of Personal Data (approved under Presidential Decree No. 275 of 4 June 2010)
registry.pdp.az
Link checked 18 August 2026
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportPresidential Decree No. 275 of 4 June 2010 on implementing the Law 'On Personal Data'
registry.pdp.az
Link checked 18 August 2026
- Official sourceE-Qanun, Ministry of JusticeCode of Administrative Offences of the Republic of Azerbaijan, 29 December 2015 — articles 375, 379, 388-1
e-qanun.az
Link checked 18 August 2026
Cyber security rules
Official name: Kibertəhlükəsizlik sahəsində idarəetmənin təkmilləşdirilməsi ilə bağlı tədbirlər haqqında Azərbaycan Respublikası Prezidentinin Fərmanı · Presidential Decree of 3 June 2026 creating the National Cybersecurity Agency and approving its charter · Directly binding regulation
The regulator changed in June 2026. The Electronic Security Service was abolished and the National Cybersecurity Agency took its place. It runs the register, takes complaints, inspects, audits and brings administrative cases. It sits inside the ministry and is not independent of it.
Enforced by National Cybersecurity Agency
What you have to do
- Register or notifyThe register of personal data systems now sits with the National Cybersecurity Agency.
- Independent auditThe agency may audit an owner or operator on request, and inspect registered systems jointly with other state bodies against their declared purposes.
- Publish a complaints contactPeople complain to the agency directly, through a dedicated channel on its website.
What it costs if you get it wrong
- Order to stopThe agency may demand removal of breaches of the personal data law and may restrict an online seller's activity in Azerbaijan for e-commerce disclosure failures
Sources
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportPresidential Decree of 3 June 2026 creating the National Cybersecurity Agency and giving it the personal data register, complaints and inspection functions
mincom.gov.az
Link checked 18 August 2026
- Official sourceMinistry of Digital Development and TransportMinistry of Digital Development and Transport — list of presidential decrees, showing the 3 June 2026 cybersecurity governance decree
mincom.gov.az
Link checked 18 August 2026
- Official sourceNational Cybersecurity AgencyNational Cybersecurity Agency — official site, with separate reporting channels for cyber incidents and for personal data violations
cert.az
Link checked 18 August 2026
Cyber security rules (2026)
Official name: “İnformasiya, informasiyalaşdırma və informasiyanın mühafizəsi haqqında” Azərbaycan Respublikasının Qanununda dəyişiklik edilməsi barədə Qanun · Law No. 454-VIIQD of 14 July 2026, implemented by presidential decree of 10 August 2026 · Act of parliament
Azerbaijan's first real cybersecurity law, signed in July 2026 and published in August. It creates a National Computer Emergency Response Team. It defines critical and publicly significant information infrastructure. The deadlines are very short. You report incidents immediately and answer the response team within 24 hours.
Enforced by National Cybersecurity Agency
What you have to do
- Report cyber incidentsInformation about cyber threats, attacks and incidents goes to the National Computer Emergency Response Team immediately. You also file analytical reports every quarter.
- Report cyber incidents — within 24 hoursYou must answer questions from the National Computer Emergency Response Team about your cyber security or about threat research within 24 hours. Digital investigation requests get 5 working days. Internet providers, hosting providers and owners of internet resources are named in the law.
- Secure the dataOperators of information infrastructure performing publicly significant functions must run continuous real-time monitoring and a centralised incident management system.
- Keep data for a minimum period — 3 yearsDigital investigation records and supporting documents kept at least 3 years.
- Keep records of how you use dataThe list of information infrastructure performing publicly significant functions is compiled by sector regulators and sent to the National CERT within 10 working days of any update.
Sources
- Official sourcePresident of the Republic of Azerbaijan, published by the Ministry of Digital Development and TransportLaw No. 454-VIIQD of 14 July 2026 amending the Law on Information, Informatisation and Protection of Information — new articles 20-7 to 20-12
mincom.gov.az
Link checked 18 August 2026
- Official sourcePresident of the Republic of AzerbaijanLaw amending the Law on Information, Informatisation and Protection of Information, published on the President's official site, 10 August 2026
president.az
Link checked 18 August 2026
- Official sourcePresident of the Republic of AzerbaijanPresidential decree of 10 August 2026 implementing Law No. 454-VIIQD of 14 July 2026
president.az
Link checked 18 August 2026
- Official sourceNational Cybersecurity AgencyNational Cybersecurity Agency, 10 August 2026 — the agency is designated as the National CERT under the new cybersecurity law
cert.az
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether the Law 'On Personal Data' binds a foreign company that has no presence in Azerbaijan but sells to Azerbaijani consumers
The law says nothing either way about whether it reaches companies abroad. We found no regulator guidance or decision on the point. Registration is the main duty, and it assumes you are filing from inside Azerbaijan. Treat this as unsettled. Do not assume you are safe.
The exact date Law No. 431-VIIQD of 30 June 2026 was published, and therefore the exact date the minimum age of 16 for social network accounts starts
The law starts twelve months after it is published. We could not confirm the official gazette publication date. We have the presidential decree dated 5 August 2026 and the ministry's publication of the law dated 30 June 2026. Plan for the earlier date, around 30 June 2027.
Whether Law No. 454-VIIQD of 14 July 2026 is fully operative or waiting on secondary acts
We could not find an article in the law saying when it starts. The law also leaves several things to rules that were still unpublished on 18 August 2026. Those are the list of publicly significant information infrastructure, the general cyber security requirements, and the rules for the register of incident response teams and security operations centres. We have recorded the law as partly in force for that reason.
General minimum retention periods under tax, accounting and company law
We could not confirm how long tax and accounting law makes you keep records. The personal data law says when you must delete data but sets no minimum keeping period. That minimum almost certainly comes from tax and accounting law. Do not assume there is no minimum. Check before you delete.
Sector storage rules in health, insurance, education, gaming, geospatial mapping and defence
We found no rule of this kind on government sources, checked 18 August 2026. We cannot rule one out. Mapping and survey data in particular is probably restricted by state secrets law, which we did not read. Check before you rely on this.
Whether Azerbaijan has ratified the modernised Council of Europe data convention, known as Convention 108+
We could not confirm whether Azerbaijan has ratified the 2018 protocol that amends the 1981 convention. The register site publishes the original 1981 convention and the Azerbaijani law approving it. Nothing about the 2018 protocol appears on an Azerbaijani government site.
Whether the licence for creating personal data information resources and systems, required by article 9.14 of the personal data law, actually exists
The law is clear that this work may only be done under a special permission. We could not find a matching licence type on the ministry's licensing pages. It looks like text on the books with no working scheme behind it. Check this before you rely on it.
Whether the National Cybersecurity Agency has issued any administrative penalty for a personal data breach
We could not confirm what the agency does to enforce the law. Its site publishes advisories and news about international cooperation, not decisions. Its charter requires a yearly statistical report on cyber security and personal data protection. We found no such report published.
Which government body operates the register day to day since the June 2026 reorganisation
We could not confirm who now runs the register day to day. The register site still names the abolished Electronic Security Service and gives a registry@cert.az address. The June 2026 decree moves that job to the National Cybersecurity Agency. The government pages disagree with each other.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.