Skip to the content
Global Data RulesData governance rules, country by country

Uzbekistan

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Waking up

Uzbekistan used to say that data about its citizens had to sit on machines inside the country. In March 2026 it dropped that blanket rule. Most personal data may now be stored abroad if the destination country is on a new government approved list, or you use an approved contract, or you meet international standards. Three kinds of data still cannot leave at all.

Eight questions about Uzbekistan

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Uzbekistan's rules apply to my company?

The law is written to cover the handling of personal data whatever tools are used, and it was aimed at foreign online platforms when the storage rules were first tightened in 2021. It does not set a size or revenue threshold, so a small foreign company is treated the same as a large one. We found no clear wording that forces a foreign company to appoint a representative living in Uzbekistan, and no explicit sentence saying the law follows the data outside the country.

Medium confidenceNational rulesControllerProcessor

Can I store my users' data outside Uzbekistan?

Mostly yes, but only if you can point to one of three permissions. Face and fingerprint data, genetic data, and data about customers of telephone and internet companies must stay in Uzbekistan. Everything else may be stored and processed abroad if the destination country is on the government's approved list, or you sign an approved standard contract or use approved group rules, or you follow recognised international data standards.

Medium confidenceYes, with paperworkAllowlistKeep the data in the country

What do I need in place before data leaves Uzbekistan?

The model is an approved list. Before ordinary personal data leaves the country you need one of three things: the destination is on the Cabinet of Ministers' list of countries with adequate protection, or you use the standard contract terms or group rules approved by the data authority, or you meet recognised international data standards. The country list was signed on 29 July 2026 and started on 3 August 2026, so it is brand new. We could not read which countries are on it, and no approved standard contract template appears to have been published yet.

Medium confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consent

Who enforces the rules in Uzbekistan, and what can they do?

The data regulator is the State Centre for Personalization, which sits under the Cabinet of Ministers. It keeps the national register of personal data databases and can issue orders that companies and individuals must obey. It is a working government body and the registration service has run since 2020, but we found no published fines or decisions, so treat enforcement as waking up rather than active. Cyber incidents are handled by a different body, the State Security Service, and banks answer separately to the Central Bank.

Medium confidenceWaking upRegulatorCriminal liability

How long do I have to keep the data?

The ceiling is clear: personal data must be destroyed once the purpose is achieved, once consent is withdrawn, once the agreed period ends, or when a court orders it. The floor is thinner. Organisations covered by the cybersecurity law must keep backup copies covering at least the last three months. We did not verify the general tax and accounting minimum keeping periods during this run, so plan on the usual company record rules as well.

Medium confidenceDelete data after a periodKeep data for a minimum periodKeep logs

What happens if there is a breach?

There are two clocks and they are not the same. The privacy law itself contains no duty to report a data breach to the regulator or to the people affected — we checked the text on 18 August 2026 and found none. The cybersecurity law is where reporting lives: organisations covered by it must tell the State Security Service about cyber incidents. Banks also report to the Central Bank under its security rules. We could not confirm a firm deadline in hours for any of these.

Medium confidenceReport cyber incidentsSecure the data

What trips people up in Uzbekistan?

First, every database of personal data has to be entered in a national register — it is a notification, it is free and it takes five working days, but skipping it is still a breach. Second, breaking the personal data rules can be a crime, not just a fine, so a named person can be prosecuted. Third, the face and fingerprint wall catches ordinary products like fingerprint logins and identity checks, not just spy technology. Fourth, banks are banned from handing the running of their technology and security systems to an outside supplier, which rules out most managed cloud and outsourced security operations. Fifth, the standard contract route for sending data abroad exists on paper but no approved template appears to have been published.

Medium confidenceRegister or notifyCriminal liabilityKeep the data in the countryBiometric dataGenetic data

What is changing soon in Uzbekistan?

The big change already happened in March 2026 and the follow-up is still landing. The approved country list started on 3 August 2026 and can be widened or cut by the Cabinet of Ministers at any time. The approved standard contract for sending data abroad is still missing, so watch for it. A new Tashkent International Financial Centre opened its legal regime on 25 July 2026 and its law also touched the privacy law, which may create a separate rulebook inside the centre. A national cybersecurity strategy was signed in March 2026.

Medium confidenceIn forceOfficial 'this country is safe' decision

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    5 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    5 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules5 rules

Ўзбекистон Республикасининг Қонуни «Шахсга доир маълумотлар тўғрисида» / Закон Республики Узбекистан «О персональных данных»

Act of parliament · ZRU-547 of 2 July 2019, as amended by ZRU-1125 of 26 March 2026

In forceYes, with paperwork

Uzbekistan's general privacy law. Consent-led, with a duty to register every personal data database. Since 27 March 2026 most personal data may be stored abroad if the destination is on the approved country list, or an approved standard contract or group rules are used, or international standards are met.

In force since 1 October 2019But only enforceable from 27 March 2026

Enforced by State Centre for Personalization under the Cabinet of Ministers

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Important public interest

High confidence

Закон «О персональных данных», статья 27-1, часть 2

Act of parliament · Article 27-1(2), as rewritten by ZRU-1125 of 26 March 2026

In forceNo — it stays put

Face, fingerprint and other biometric data, and genetic data, must be kept inside Uzbekistan. The article allows storage abroad only for data not on this list, so a copy held overseas is not clearly permitted.

In force since 27 March 2026

Enforced by State Centre for Personalization under the Cabinet of Ministers

Transfer model: Not allowed

Medium confidence

Постановление Кабинета Министров «Об утверждении Перечня иностранных государств, обеспечивающих адекватную защиту персональных данных»

Adequacy decision · Cabinet of Ministers Resolution No. 415 of 29 July 2026

In forceYes, with paperwork

The government's list of countries treated as giving adequate protection to personal data. Sending data to a listed country is the simplest route out of Uzbekistan. We could not read which countries are named, so treat the list as unread. It is a Cabinet resolution and can be changed at short notice.

In force since 3 August 2026

Enforced by Cabinet of Ministers of the Republic of Uzbekistan

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision

Medium confidence

Industry rules5 rules

Закон «О персональных данных», статья 27-1, часть 2 (данные пользователей услуг операторов телекоммуникаций)

Act of parliament · Article 27-1(2), third indent; see also Law on Telecommunications ZRU-1015 of 27 December 2024 · Telecoms

In forceNo — it stays put

Data about people who use the services of telecommunications operators must be stored in Uzbekistan. This is the one hard industry wall in the 2026 rewrite and it catches any operator serving Uzbek users.

In force since 27 March 2026

Enforced by Inspection for Supervision in the Field of Informatisation and Telecommunications (Uzkomnazorat)

Transfer model: Not allowed

Medium confidence

Ўзбекистон Республикаси тижорат банклари ахборот хавфсизлиги ва киберхавфсизлигига доир минимал талаблар тўғрисидаги низом

Directly binding regulation · Central Bank Board regulation, registered No. 3669 (August 2025) · Banking

In forceYes, with paperwork

Banks are not told to keep customer data in Uzbekistan, but they are banned from handing the running of their technology and security systems to an outside supplier, and from sending state secret information over telecommunications networks. In practice that blocks fully managed foreign cloud and outsourced security operations.

In force since 20 November 2025

Enforced by Central Bank of the Republic of Uzbekistan

Transfer model: Approval each time · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Medium confidence

Кредит бюроларининг ахборот хавфсизлиги ва киберхавфсизлигига доир минимал талаблар тўғрисидаги низом

Directly binding regulation · Central Bank Board regulation, registered No. 3679 on 23 September 2025 · Finance

In forceA copy must stay

Credit bureaus must keep individuals' biometric data inside Uzbekistan. Their other personal data may be processed abroad under the routes allowed by the privacy law.

In force since 25 December 2025

Enforced by Central Bank of the Republic of Uzbekistan

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Medium confidence

Who you would hear from

  • Давлат персоналлаштириш маркази / Государственный центр персонализации при Кабинете Министров Республики Узбекистан

    Personal data protection; maintains the State Register of personal data bases; issues binding orders to remedy breaches

    Named as the authorised body in Article 8 of the Law on Personal Data, and the register service has been running as a free five-working-day public service since 2020. We found no published fines or decisions from it during this run, and could not verify a standalone public website, so its supervisory activity is rated as waking rather than active.

  • Approves the list of countries with adequate data protection and the register procedure

    Adopted the adequacy list on 29 July 2026, in force 3 August 2026.

  • Раqamli texnologiyalar vazirligi

    Digital policy, e-government systems and data centres

  • Axborotlashtirish va telekommunikatsiyalar sohasida nazorat inspeksiyasi

    Supervision of information technology and telecommunications operators, including online services

    Operates under the Ministry of Digital Technologies. Historically the body associated with restricting access to non-compliant online services. No 2025-2026 enforcement items were visible on its portal page during this run.

  • Ўзбекистон Республикаси Марказий банки

    Banks, credit bureaus, payment system operators — information security and cybersecurity rules

    Issuing binding regulations regularly; two new minimum security regulations took effect in November and December 2025.

  • Давлат хавфсизлик хизмати

    Cybersecurity; receives cyber incident notifications

    Named as the authorised cybersecurity body by the 2022 Law on Cybersecurity. It does not publish enforcement statistics.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Which countries are on the Cabinet of Ministers' list of states with adequate personal data protection (Resolution No. 415 of 29 July 2026)

    The official page on the national legislation database returns only the resolution header and signature block; the appendix containing the country names did not load in any language version we tried. Until the list is read, assume your destination is not on it.

  • Whether approved standard contractual conditions or binding corporate rules have actually been published

    A full-text search of the national legislation database on 18 August 2026 found only three documents mentioning adequate protection of personal data, none of them a contract template. The route exists in the statute but appears to be unusable in practice today.

  • Fine levels under Article 46-1 of the Code on Administrative Liability and the sentence under Article 141-2 of the Criminal Code

    Both articles are confirmed present in the official code texts, but only the article headings load; the operative text with amounts was not retrievable.

  • Whether a copy of biometric, genetic or telecom user data may also be held abroad once a copy is kept in Uzbekistan

    Article 27-1 says these categories must be stored in Uzbekistan and permits foreign storage only for data not in that list. That reads as a ban on foreign copies, but the article does not say so in terms. Recorded as closed, which is the cautious reading.

  • Whether the law expressly reaches a foreign company with no presence in Uzbekistan

    The scope article speaks to processing regardless of means, not to territory. The obligations attach to owners and operators of databases containing Uzbek citizens' data, which is how foreign platforms were treated in 2021, but there is no express extraterritoriality clause of the kind used in Europe.

  • A firm deadline in hours for reporting cyber incidents to the State Security Service

    The cybersecurity law creates the duty to notify. A twenty-four hour figure appears in the law but our reading located it in a provision about officials entering premises, so we do not assert it as the incident clock.

  • Whether the State Centre for Personalization has issued any enforcement decisions or fines

    No decisions register or enforcement page was reachable, and the centre's own website could not be verified. Absence of evidence is not evidence of absence; the enforcement rating reflects what is observable.

  • Whether the Tashkent International Financial Centre has its own data protection regime displacing the national law inside the Centre

    The Centre's founding law of 13 July 2026 is listed among the acts amending the Law on Personal Data and creates a financial services authority with its own acts, but the data provisions did not load. This is the most likely place for a separate rulebook to appear.

  • Localisation or storage rules specific to insurance, securities markets, education and online gaming

    Searched the national legislation database on 18 August 2026 and found no sector localisation rule for these. No rule found rather than no rule exists; confidence medium.

  • Minimum keeping periods under tax, accounting and banking record rules

    Not verified during this run. Only the cybersecurity three-month backup floor and the privacy law's destruction ceiling were confirmed.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.