Skip to the content
Global Data RulesData governance rules, country by country

Azerbaijan

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Waking up

Azerbaijan has had a personal data law since 2010. Data may leave the country, but only if you decide the destination protects it as well as Azerbaijan does, and you must declare those exports up front. The real cost is not the export rule. It is that you must register your database with the state before you collect a single record.

Eight questions about Azerbaijan

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Azerbaijan's rules apply to my company?

The law is silent about foreign companies, and that silence is the answer. Unlike Europe's rules, Azerbaijan's personal data law has no clause reaching organisations abroad that sell to Azerbaijanis. What it does have is a duty on the 'owner' of a database to register it with the state before collecting anything, and that duty is enforced through the register in Baku. A foreign company with no Azerbaijani entity has no realistic way to register, and no regulator has said whether it must. From 2027 one narrow group of foreign firms is caught by name: social network providers offering services to users in Azerbaijan must set up a local branch or representative office.

Medium confidenceNational rulesRegister or notifyAppoint a local representative

Can I store my users' data outside Azerbaijan?

Yes, with conditions, and the condition is a judgement call you make yourself. Azerbaijan bans sending personal data abroad in only two situations: where it would threaten national security, or where the destination country's law does not protect the data to the standard Azerbaijani law sets. Nobody publishes a list of good or bad countries, so you decide, and you carry the risk. If the person has consented, or if the transfer is needed to protect their life or health, the destination's standard stops mattering at all. We looked hard for industry walls in banking, payments, insurance, securities, telecoms and health and found none that force data to stay in the country.

High confidenceYes, with paperworkBlocklistOfficial 'this country is safe' decisionExplicit consentSomeone's life is at risk

What do I need in place before data leaves Azerbaijan?

There is no form to file and no approval to get. You need three things instead: a lawful basis for the processing in the first place, your own written assessment that the destination country protects the data well enough, and a declaration of the transfer in your entry on the state register. That last point is the one people miss. The registration form asks you to list the categories of personal data you send to other countries and to international organisations, so an undeclared export is also a registration failure.

High confidenceBlocklistPut a transfer safeguard in placeRegister or notifyGet consent

Who enforces the rules in Azerbaijan, and what can they do?

This changed three months ago. On 3 June 2026 the President abolished the Electronic Security Service and created the National Cybersecurity Agency in its place, under the Ministry of Digital Development and Transport, with express powers over personal data as well as cyber security. The agency is real and working: it runs the state register, takes complaints about data misuse through its website, publishes advisories most weeks, and signed a cooperation agreement with Latvia's data protection inspectorate in July 2026. It is not independent of government, and we found no published fines. The register itself is the strongest evidence it functions: 444 systems are listed and the most recent approval is dated 7 August 2026.

High confidenceWaking upRegulator

How long do I have to keep the data?

The ceiling is strict and the floor is thin. Once you have achieved the purpose you collected the data for, and there is no longer a need to keep it, you must destroy it without delay. If your registration is cancelled, everything in that system must be blocked immediately and destroyed. Sensitive data must go as soon as the reason for holding it disappears, unless the person agrees to it staying or being archived. In the other direction, the personal data law itself sets no minimum keeping period. The clearest floor we could verify is new: from 2026, records of a digital forensic investigation into a cyber incident must be kept for at least three years.

Medium confidenceDelete data after a periodKeep data for a minimum periodKeep logs

What happens if there is a breach?

There is no personal data breach notification duty at all. The 2010 law never created one, and nothing since has added one, so losing customer records triggers no report to any regulator and no letter to the people affected. What does exist is a cyber incident duty, and it is fast: since August 2026, organisations that run information infrastructure must pass information about cyber threats, attacks and incidents to the National CERT immediately. Once the National CERT asks you something, you have 24 hours to answer a threat research request and 5 working days to answer a digital investigation request. Financial firms have a second clock through the Central Bank's FinCERT portal.

High confidenceReport cyber incidentsSecure the data

What trips people up in Azerbaijan?

Five. One: you cannot start. Collecting or processing personal data in an unregistered system is an offence, and registration takes up to a month. Two: the security rules are engineering specifications, not principles, and include a minimum 256-bit encryption key, a data centre archive system housed in a separate building, and state expert review of your system design documents. Three: every operator must set things up so that police and intelligence bodies can carry out surveillance, and must keep the methods secret. Four: the fine for breaking the data law is 300 to 500 manat, roughly 175 to 290 US dollars, which tells you the real risk is being ordered to stop, not being fined. Five: the law says data system work needs a special licence, and no licensing regime matching it appears to be running.

High confidenceRegister or notifySecure the dataHold a security certificateFixed maximum fineOrder to stop

What is changing soon in Azerbaijan?

One big date and one big gap. The big date is roughly August 2027, twelve months after publication, when Azerbaijan's minimum age of 16 for social network accounts starts. Providers must verify age using a bank card, an email address and a mobile number, must delete what they collected for that check immediately, and must open a local branch. The penalty ladder ends with a court ordering the platform's traffic in Azerbaijan cut by 90 per cent. The big gap is that the July 2026 cybersecurity law leaves the important lists and technical requirements to be written by ministries, and they are not out yet.

High confidencePassed, not yet fully in forceGet a parent's consent for childrenAppoint a local representativeFixed maximum fine

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    5 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    3 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules5 rules

Fərdi məlumatlar haqqında Azərbaycan Respublikasının Qanunu

Act of parliament · Law No. 998-IIIQ of 11 May 2010, as amended to 28 June 2024

In forceYes, with paperwork

Azerbaijan's core privacy law. Data may go abroad unless it threatens national security or the destination protects it worse than Azerbaijan does, a test you apply yourself. Consent overrides the test. The heavier duty is that no personal data system may operate until the state has registered it.

In force since 6 June 2010

Enforced by National Cybersecurity Agency

Transfer model: Blocklist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Someone's life is at risk

High confidence

Dövlət qeydiyyatı tələb olunmayan fərdi məlumatların informasiya sistemləri

Directly binding regulation · Cabinet of Ministers Decision No. 237 of 17 December 2010, made under Presidential Decree No. 275 of 4 June 2010

In forceYes, with paperwork

The register is the gate. You may not collect personal data until your system is on it. The exemptions are narrow: state secrets, staff records, and a handful of categories only while they hold fewer than 1,000 people. The register is public, holds 444 systems, and was last added to on 7 August 2026.

In force since 17 December 2010

Enforced by National Cybersecurity Agency

Transfer model: Blocklist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision

High confidence

Fərdi məlumatların mühafizəsinə dair Tələblər

Directly binding regulation · Requirements for the Protection of Personal Data, approved by the Cabinet of Ministers under Presidential Decree No. 275 of 4 June 2010

In forceYes, with paperwork

Azerbaijan does not stop at 'appropriate measures'. A Cabinet instrument sets 23 specific engineering requirements, including a 256-bit minimum encryption key and an archive system in its own building, and requires the state to review your system design before you build.

In force since 4 June 2010But only enforceable from 4 December 2010

Enforced by National Cybersecurity Agency

High confidence

Industry rules3 rules

Azərbaycan Respublikasının İnzibati Xətalar Məcəlləsində, “İnformasiya, informasiyalaşdırma və informasiyanın mühafizəsi haqqında” və “Uşaqların zərərli informasiyadan qorunması haqqında” Azərbaycan Respublikasının qanunlarında dəyişiklik edilməsi barədə Qanun

Act of parliament · Law No. 431-VIIQD of 30 June 2026; implementing presidential decree of 5 August 2026; commences twelve months after publication · Social media and online platforms

Passed, not yet fully in forceYes, with paperwork

Passed, not yet in force. From about August 2027 nobody under 16 may hold a social network account in Azerbaijan. Providers must check age with a bank card, email and mobile number, delete what they collect immediately, and open a local branch, or watch their traffic throttled by court order.

In force since 5 August 2027

Enforced by National Cybersecurity Agency

Transfer model: Not allowed

High confidence

“Hökumət buludu”nun (G-cloud) yaradılması və “bulud” xidmətlərinin göstərilməsi sahəsində tədbirlər haqqında Azərbaycan Respublikası Prezidentinin Fərmanı

Government policy document · Presidential Decree No. 718 of 3 June 2019, implementing measure 2.4.5 of the Strategic Road Map approved by Presidential Decree No. 1138 of 6 December 2016 · Government

In forceA copy must stay

If you sell to the Azerbaijani state, location is effectively fixed. Government information systems are being consolidated into a domestic Government Cloud of four data centres, secured jointly with the state protection service. This is architecture and procurement rather than an express statutory ban on foreign hosting.

In force since 3 June 2019

Enforced by Ministry of Digital Development and Transport

Medium confidence

Azərbaycan Respublikasının İnzibati Xətalar Məcəlləsi, maddə 388-1

Act of parliament · Code of Administrative Offences article 388-1, read with the Law on Information, Informatisation and Protection of Information · Telecoms

In forceYes, with paperwork

Telecoms carries no storage rule, but it does carry a takedown reflex. Once the state adds a website to its list of prohibited resources, hosting and internet providers must cut access immediately, with fines for delay. The list is administrative and can grow without notice.

In force since 1 March 2016

Enforced by National Cybersecurity Agency

High confidence

Who you would hear from

  • Milli Kibertəhlükəsizlik Agentliyi

    Personal data protection, the state register of personal data information systems, cyber security, and the National CERT function

    Created on 3 June 2026 as the legal successor of the Electronic Security Service. Working: it maintains the state register (444 systems, most recent approval 7 August 2026), runs a public channel for reporting personal data violations, publishes advisories most weeks, and signed a cooperation memorandum with Latvia's State Data Inspectorate on 31 July 2026. No published fines or enforcement decisions were found, and the maximum administrative fine under the personal data law is 500 manat, about 294 US dollars. It sits under the ministry and is not independent.

  • Rəqəmsal İnkişaf və Nəqliyyat Nazirliyi

    Policy and rule-making for information technology, e-government, telecoms and the Government Cloud; parent of the National Cybersecurity Agency

    Renamed from the Ministry of Transport, Communications and High Technologies by Presidential Decree No. 1464 of 11 October 2021. Publishes laws and decrees promptly; the July 2026 cybersecurity law appeared on its site in August 2026.

  • Xüsusi Rabitə və İnformasiya Təhlükəsizliyi Dövlət Xidmətinin Kompüter İnsidentlərinə qarşı Mübarizə Mərkəzi

    Cyber incident response for state bodies and protected objects; publishes a national blacklist of phishing domains

    Active. Advisories published up to 18 August 2026. Runs an incident reporting channel and a domain blacklist tool.

  • Azərbaycan Respublikasının Mərkəzi Bankı

    Banks, payment institutions, electronic money institutions, insurers and capital markets; runs FinCERT for the financial sector

    Fully operational and issuing rules. Its payment sector rulebook was last added to in March 2026. FinCERT has a live portal for high-severity incident reports. Notably, none of its rules impose a data-storage-location requirement.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether the Law 'On Personal Data' binds a foreign company that has no presence in Azerbaijan but sells to Azerbaijani consumers

    The law has no territorial scope article either way, and we found no regulator guidance or decision on the point. Registration is the operative duty and it presumes a filer in-country. Treat as unsettled rather than as a safe harbour.

  • The exact date Law No. 431-VIIQD of 30 June 2026 was published, and therefore the exact date the minimum age of 16 for social network accounts starts

    The law commences twelve months after publication. We have the implementing presidential decree dated 5 August 2026 and the ministry's publication of the law dated 30 June 2026, but not the gazette publication date itself. Plan to the earlier of the two, around 30 June 2027.

  • Whether Law No. 454-VIIQD of 14 July 2026 is fully operative or waiting on secondary acts

    The law itself contains no commencement article that we could locate, and it leaves the list of publicly significant information infrastructure, the general cyber security requirements and the CERT and SOC register rules to instruments that had not been published by 18 August 2026. We have recorded it as partly in force for that reason.

  • General minimum retention periods under tax, accounting and company law

    Not checked in this pass. The personal data law sets a ceiling but no floor, so the practical floor almost certainly comes from tax and accounting law, which we did not verify against an official source. Do not assume there is no floor.

  • Sector storage rules in health, insurance, education, gaming, geospatial mapping and defence

    Searched for on 18 August 2026 and none found on official sources. This is a negative finding at medium confidence, not proof of absence. Mapping and geodetic data in particular is likely restricted through state secrets legislation, which we did not read.

  • Whether Azerbaijan has ratified the modernised Council of Europe data convention, known as Convention 108+

    The register site publishes the original 1981 convention and the Azerbaijani ratification law. Nothing on the ratification of the 2018 amending protocol was found on an Azerbaijani government domain.

  • Whether the licence for creating personal data information resources and systems, required by article 9.14 of the personal data law, actually exists

    The text is clear that this work may only be done under a special permission, but we found no matching licence type in the ministry's licensing pages. It reads as text on the books with no live scheme behind it, which is a finding worth re-checking.

  • Whether the National Cybersecurity Agency has issued any administrative penalty for a personal data breach

    The agency's site publishes advisories and international cooperation news, not decisions. Its charter requires an annual statistical report on cyber security and personal data protection; we could not find one published yet.

  • Which government body operates the register day to day since the June 2026 reorganisation

    The register site still names the abolished Electronic Security Service and gives a registry@cert.az address, while the June 2026 decree moves the function to the National Cybersecurity Agency. The government pages disagree with each other.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.