Skip to the content
Global Data RulesData governance rules, country by country

Azerbaijan

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Azerbaijan — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Waking up

Azerbaijan has had a personal data law since 2010. You can send data abroad. But first you must judge that the destination country protects it as well as Azerbaijan does. You must also declare those transfers up front. The bigger cost is registration. You must register your database with the state before you collect a single record.

Data governance in Azerbaijan

The eight things that decide how you handle data about people in Azerbaijan. Same eight on every country page, so you can compare.

Who has to follow these rules

The law says nothing about foreign companies, and that silence is the answer. Azerbaijan's personal data law has no clause that reaches companies abroad selling to Azerbaijanis. Europe's rules do have one. What Azerbaijan has instead is a duty to register your database with the state before you collect anything. That duty is enforced through the register in Baku. A foreign company with no Azerbaijani entity has no realistic way to register. No regulator has said whether it must. From 2027 one narrow group of foreign firms is named: social network providers serving users in Azerbaijan must set up a local branch or representative office.

What you have to do here:
Register or notify · Appoint a representative
Not fully verified — see “What we're not sure about” below.

Where the data is allowed to live

Yes, with conditions. The condition is a judgement you make yourself. Azerbaijan bans sending personal data abroad in only two situations. The first is where it would threaten national security. The second is where the destination country's law protects the data less well than Azerbaijani law does. Nobody publishes a list of good or bad countries. So you decide, and you carry the risk. If the person has consented, the destination's standard stops mattering. The same is true if the transfer is needed to protect their life or health. We looked hard for industry rules in banking, payments, insurance, securities, telecoms and health. We found none that force data to stay in the country.

Ways to send data out:
Official 'this country is safe' decision · Explicit consent · To save someone’s life

What to do: Get the paperwork for one of the routes below signed before any data leaves Azerbaijan.

Sending data out of the country

There is no form to file and no approval to get. You need three things instead. First, a lawful reason to use the data at all. Second, your own written assessment that the destination country protects the data well enough. Third, a declaration of the transfer in your entry on the state register. That third point is the one people miss. The registration form asks you to list the types of personal data you send to other countries and to international organisations. So an undeclared transfer is also a registration failure.

What you have to do here:
Put a transfer safeguard in place · Register or notify · Get consent

The regulator, and whether it actually acts

This changed three months ago. On 3 June 2026 the President abolished the Electronic Security Service. In its place he created the National Cybersecurity Agency. It sits under the Ministry of Digital Development and Transport and has express powers over personal data as well as cyber security. The agency is real and working. It runs the state register. It takes complaints about data misuse through its website. It publishes advisories most weeks. It signed a cooperation agreement with Latvia's data protection inspectorate in July 2026. It is not independent of government, and we found no published fines. The register is the strongest sign that it works. It lists 444 systems, and the most recent approval is dated 7 August 2026.

How long you must keep it — and when to delete it

There is a strict rule on deleting data and almost no rule on keeping it. Once you have achieved the purpose you collected the data for, and no longer need it, you must destroy it without delay. If your registration is cancelled, everything in that system must be blocked immediately and destroyed. Sensitive data must go as soon as the reason for holding it disappears. The exception is where the person agrees to it being stored or archived. Going the other way, the personal data law sets no minimum keeping period. The clearest minimum we could verify is new. From 2026, records of a digital forensic investigation into a cyber incident must be kept for at least three years.

What you have to do here:
Delete data after a period · Keep data for a minimum period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

There is no duty to report a personal data breach at all. The 2010 law never created one, and nothing since has added one. So losing customer records means no report to any regulator and no letter to the people affected. What does exist is a duty to report cyber incidents, and it is fast. Since August 2026, organisations that run information infrastructure must pass information about cyber threats, attacks and incidents to the National Computer Emergency Response Team immediately. Once that team asks you something, you have 24 hours to answer a threat research request. You have 5 working days to answer a digital investigation request. Financial firms have a second deadline through the Central Bank's FinCERT portal.

What you have to do here:
Report cyber incidents · Secure the data

What catches people out

Five. One: you cannot start. Collecting or using personal data in an unregistered system is an offence, and registration takes up to a month. Two: the security rules are engineering specifications, not principles. They include a minimum 256-bit encryption key, an archive system housed in a separate building, and state expert review of your system design documents. Three: every operator must set things up so that police and intelligence bodies can carry out surveillance, and must keep the methods secret. Four: the fine for breaking the data law is 300 to 500 manat, roughly 175 to 290 US dollars. That tells you the real risk is being ordered to stop, not being fined. Five: the law says data system work needs a special licence, and no matching licence scheme appears to be running.

What you have to do here:
Register or notify · Secure the data · Hold a security certificate
What it costs if you get it wrong:
Fixed maximum fine · Order to stop

What's changing next

One big date and one big gap. The big date is roughly August 2027, twelve months after publication. That is when Azerbaijan's minimum age of 16 for social network accounts starts. Providers must check age using a bank card, an email address and a mobile number. They must delete what they collected for that check immediately. They must also open a local branch. The penalty ladder ends with a court ordering the platform's traffic in Azerbaijan cut by 90 per cent. The big gap is the July 2026 cybersecurity law. It leaves the important lists and technical requirements to ministries, and they are not out yet.

What you have to do here:
Get a parent's consent for children
What it costs if you get it wrong:
Fixed maximum fine

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Social media and online platforms

Payment data rules

Official name: Azərbaycan Respublikasının İnzibati Xətalar Məcəlləsində, “İnformasiya, informasiyalaşdırma və informasiyanın mühafizəsi haqqında” və “Uşaqların zərərli informasiyadan qorunması haqqında” Azərbaycan Respublikasının qanunlarında dəyişiklik edilməsi barədə Qanun · Law No. 431-VIIQD of 30 June 2026; implementing presidential decree of 5 August 2026; commences twelve months after publication · Act of parliament

Passed, not yet fully in forceYes, with paperwork

Passed, not yet in force. From about August 2027, nobody under 16 may hold a social network account in Azerbaijan. Providers must check age with a bank card, email and mobile number. They must delete what they collect immediately and open a local branch. If they do not, a court can order their traffic slowed.

In force since 5 August 2027

Enforced by National Cybersecurity Agency

How this country controls where data goes: Not allowed

Government

Government data needs a copy kept in the country

Official name: “Hökumət buludu”nun (G-cloud) yaradılması və “bulud” xidmətlərinin göstərilməsi sahəsində tədbirlər haqqında Azərbaycan Respublikası Prezidentinin Fərmanı · Presidential Decree No. 718 of 3 June 2019, implementing measure 2.4.5 of the Strategic Road Map approved by Presidential Decree No. 1138 of 6 December 2016 · Government policy document

In forceA copy must stay

If you sell to the Azerbaijani state, the data has to stay in Azerbaijan. Government information systems are being moved into a domestic Government Cloud of four data centres. The state protection service helps secure them. No law expressly bans foreign hosting. It is how the systems are built and bought that fixes the location.

In force since 3 June 2019

Enforced by Ministry of Digital Development and Transport

Not fully verified — see “What we're not sure about” below.
Telecoms

Telecoms rules

Official name: Azərbaycan Respublikasının İnzibati Xətalar Məcəlləsi, maddə 388-1 · Code of Administrative Offences article 388-1, read with the Law on Information, Informatisation and Protection of Information · Act of parliament

In forceYes, with paperwork

Telecoms has no rule forcing data to stay in Azerbaijan. It does have a takedown duty. Once the state adds a website to its list of prohibited resources, hosting and internet providers must cut access immediately. Delay brings fines. The list is decided administratively and can grow without notice.

In force since 1 March 2016

Enforced by National Cybersecurity Agency

Applies to every company5 rules

These bind you whatever business you are in, once the country's rules reach you.

State and security data rules

Official name: Fərdi məlumatlar haqqında Azərbaycan Respublikasının Qanunu · Law No. 998-IIIQ of 11 May 2010, as amended to 28 June 2024 · Act of parliament

In forceYes, with paperwork

Azerbaijan's main privacy law. You can send data abroad unless it threatens national security. You also cannot send it to a country that protects it worse than Azerbaijan does. You apply that test yourself. Consent overrides it. The heavier duty is registration. No personal data system may run until the state has registered it.

In force since 6 June 2010

Enforced by National Cybersecurity Agency

How this country controls where data goes: Any country except banned ones (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent, To save someone’s life

State and security data rules (2010)

Official name: Dövlət qeydiyyatı tələb olunmayan fərdi məlumatların informasiya sistemləri · Cabinet of Ministers Decision No. 237 of 17 December 2010, made under Presidential Decree No. 275 of 4 June 2010 · Directly binding regulation

In forceYes, with paperwork

You may not collect personal data until your system is on the state register. The exemptions are narrow. They cover state secrets, staff records, and a few categories, but only while they hold fewer than 1,000 people. The register is public. It holds 444 systems and was last added to on 7 August 2026.

In force since 17 December 2010

Enforced by National Cybersecurity Agency

How this country controls where data goes: Any country except banned ones (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision

Secrecy duties for regulated professions

Official name: Fərdi məlumatların mühafizəsinə dair Tələblər · Requirements for the Protection of Personal Data, approved by the Cabinet of Ministers under Presidential Decree No. 275 of 4 June 2010 · Directly binding regulation

In forceYes, with paperwork

Azerbaijan does not stop at 'appropriate measures'. A Cabinet decision sets 23 specific engineering requirements. They include a 256-bit minimum encryption key and an archive system in its own building. The state must also review your system design before you build.

In force since 4 June 2010Enforced from 4 December 2010

Enforced by National Cybersecurity Agency

Who you would hear from

  • Milli Kibertəhlükəsizlik Agentliyi

    Personal data protection, the state register of personal data information systems, cyber security, and the National CERT function

    Created on 3 June 2026 as the legal successor of the Electronic Security Service. It is working. It keeps the state register, which holds 444 systems, with the most recent approval on 7 August 2026. It runs a public channel for reporting personal data violations. It publishes advisories most weeks. It signed a cooperation memorandum with Latvia's State Data Inspectorate on 31 July 2026. We found no published fines or enforcement decisions. The maximum administrative fine under the personal data law is 500 manat, about 294 US dollars. It sits under the ministry and is not independent.

  • Rəqəmsal İnkişaf və Nəqliyyat Nazirliyi

    Policy and rule-making for information technology, e-government, telecoms and the Government Cloud; parent of the National Cybersecurity Agency

    Renamed from the Ministry of Transport, Communications and High Technologies by Presidential Decree No. 1464 of 11 October 2021. Publishes laws and decrees promptly; the July 2026 cybersecurity law appeared on its site in August 2026.

  • Xüsusi Rabitə və İnformasiya Təhlükəsizliyi Dövlət Xidmətinin Kompüter İnsidentlərinə qarşı Mübarizə Mərkəzi

    Cyber incident response for state bodies and protected objects; publishes a national blacklist of phishing domains

    Active. Advisories published up to 18 August 2026. Runs an incident reporting channel and a domain blacklist tool.

  • Azərbaycan Respublikasının Mərkəzi Bankı

    Banks, payment institutions, electronic money institutions, insurers and capital markets; runs FinCERT for the financial sector

    Fully operational and issuing rules. Its payment sector rulebook was last added to in March 2026. FinCERT has a live portal for high-severity incident reports. None of its rules require data to be stored in a particular place.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether the Law 'On Personal Data' binds a foreign company that has no presence in Azerbaijan but sells to Azerbaijani consumers

    The law says nothing either way about whether it reaches companies abroad. We found no regulator guidance or decision on the point. Registration is the main duty, and it assumes you are filing from inside Azerbaijan. Treat this as unsettled. Do not assume you are safe.

  • The exact date Law No. 431-VIIQD of 30 June 2026 was published, and therefore the exact date the minimum age of 16 for social network accounts starts

    The law starts twelve months after it is published. We could not confirm the official gazette publication date. We have the presidential decree dated 5 August 2026 and the ministry's publication of the law dated 30 June 2026. Plan for the earlier date, around 30 June 2027.

  • Whether Law No. 454-VIIQD of 14 July 2026 is fully operative or waiting on secondary acts

    We could not find an article in the law saying when it starts. The law also leaves several things to rules that were still unpublished on 18 August 2026. Those are the list of publicly significant information infrastructure, the general cyber security requirements, and the rules for the register of incident response teams and security operations centres. We have recorded the law as partly in force for that reason.

  • General minimum retention periods under tax, accounting and company law

    We could not confirm how long tax and accounting law makes you keep records. The personal data law says when you must delete data but sets no minimum keeping period. That minimum almost certainly comes from tax and accounting law. Do not assume there is no minimum. Check before you delete.

  • Sector storage rules in health, insurance, education, gaming, geospatial mapping and defence

    We found no rule of this kind on government sources, checked 18 August 2026. We cannot rule one out. Mapping and survey data in particular is probably restricted by state secrets law, which we did not read. Check before you rely on this.

  • Whether Azerbaijan has ratified the modernised Council of Europe data convention, known as Convention 108+

    We could not confirm whether Azerbaijan has ratified the 2018 protocol that amends the 1981 convention. The register site publishes the original 1981 convention and the Azerbaijani law approving it. Nothing about the 2018 protocol appears on an Azerbaijani government site.

  • Whether the licence for creating personal data information resources and systems, required by article 9.14 of the personal data law, actually exists

    The law is clear that this work may only be done under a special permission. We could not find a matching licence type on the ministry's licensing pages. It looks like text on the books with no working scheme behind it. Check this before you rely on it.

  • Whether the National Cybersecurity Agency has issued any administrative penalty for a personal data breach

    We could not confirm what the agency does to enforce the law. Its site publishes advisories and news about international cooperation, not decisions. Its charter requires a yearly statistical report on cyber security and personal data protection. We found no such report published.

  • Which government body operates the register day to day since the June 2026 reorganisation

    We could not confirm who now runs the register day to day. The register site still names the abolished Electronic Security Service and gives a registry@cert.az address. The June 2026 decree moves that job to the National Cybersecurity Agency. The government pages disagree with each other.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.