Skip to the content
Global Data RulesData governance rules, country by country

Uzbekistan

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Uzbekistan — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Waking up

Uzbekistan used to require data about its citizens to sit on machines inside the country. In March 2026 it dropped that blanket rule. You can now store most personal data abroad. You need one of three things. The destination country is on a new government approved list. Or you use an approved contract. Or you meet international standards. Three kinds of data still cannot leave at all.

Data governance in Uzbekistan

The eight things that decide how you handle data about people in Uzbekistan. Same eight on every country page, so you can compare.

Who has to follow these rules

The law covers the handling of personal data, whatever tools you use. It was aimed at foreign online platforms when the storage rules were first tightened in 2021. It sets no size or revenue threshold. A small foreign company is treated the same as a large one. We found no clear wording forcing a foreign company to appoint a representative living in Uzbekistan. We also found no sentence saying the law follows the data outside the country.

Not fully verified — see “What we're not sure about” below.

Where the data is allowed to live

Mostly yes, but you must point to one of three permissions. Face and fingerprint data, genetic data, and data about customers of telephone and internet companies must stay in Uzbekistan. You may store and use everything else abroad in three cases. The destination country is on the government's approved list. Or you sign an approved standard contract, or use approved group rules. Or you follow recognised international data standards.

What you have to do here:
Keep the data in the country

What to do: Get the paperwork for one of the routes below signed before any data leaves Uzbekistan.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

Uzbekistan uses an approved list. Before ordinary personal data leaves the country, you need one of three things. The destination is on the Cabinet of Ministers' list of countries with adequate protection. Or you use the standard contract terms or group rules approved by the data authority. Or you meet recognised international data standards. The country list was signed on 29 July 2026 and started on 3 August 2026, so it is brand new. We could not read which countries are on it. No approved standard contract template appears to have been published yet.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

Not fully verified — see “What we're not sure about” below.

The regulator, and whether it actually acts

The data regulator is the State Centre for Personalization. It sits under the Cabinet of Ministers. It keeps the national register of personal data databases. It can issue orders that companies and people must obey. It is a working government body, and the registration service has run since 2020. But we found no published fines or decisions. So treat enforcement as waking up rather than active. Cyber incidents go to a different body, the State Security Service. Banks answer separately to the Central Bank.

What it costs if you get it wrong:
Criminal liability
Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

The limit on keeping data is clear. You must destroy personal data once you achieve the purpose. You must also destroy it when consent is withdrawn, when the agreed period ends, or when a court orders it. The minimum keeping rules are thinner. Organisations covered by the cybersecurity law must keep backup copies covering at least the last three months. We did not confirm the general tax and accounting minimums. So plan on the usual company record rules as well.

What you have to do here:
Keep data for a minimum period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

There are two deadlines and they are not the same. The privacy law itself has no duty to report a data breach. Not to the regulator, and not to the people affected. We checked the text on 18 August 2026 and found none. Reporting lives in the cybersecurity law instead. Organisations it covers must tell the State Security Service about cyber incidents. Banks also report to the Central Bank under its security rules. We could not confirm a firm deadline in hours for any of these.

What you have to do here:
Report cyber incidents · Secure the data
Not fully verified — see “What we're not sure about” below.

What catches people out

First, you must enter every database of personal data in a national register. It is a notification, it is free and it takes five working days. Skipping it is still a breach. Second, breaking the personal data rules can be a crime, not just a fine. A named person can be prosecuted. Third, the face and fingerprint rule catches ordinary products like fingerprint logins and identity checks, not just spy technology. Fourth, banks may not hand the running of their technology and security systems to an outside supplier. That rules out most managed cloud and outsourced security operations. Fifth, the standard contract route for sending data abroad exists on paper. No approved template appears to have been published.

What you have to do here:
Register or notify
What it costs if you get it wrong:
Criminal liability
Not fully verified — see “What we're not sure about” below.

What's changing next

The big change already happened in March 2026, and the follow-up is still landing. The approved country list started on 3 August 2026. The Cabinet of Ministers can widen or cut it at any time. The approved standard contract for sending data abroad is still missing, so watch for it. A new Tashkent International Financial Centre opened its legal rules on 25 July 2026. Its law also touched the privacy law, so a separate rulebook may appear inside the centre. A national cybersecurity strategy was signed in March 2026.

Ways to send data out:
Official 'this country is safe' decision
Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries5 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Telecoms data must stay in the country

Official name: Закон «О персональных данных», статья 27-1, часть 2 (данные пользователей услуг операторов телекоммуникаций) · Article 27-1(2), third indent; see also Law on Telecommunications ZRU-1015 of 27 December 2024 · Act of parliament

In forceNo — it stays put

Data about people who use telecommunications operators' services must be stored in Uzbekistan. This is the one strict industry rule left in the 2026 rewrite. It catches any operator serving users in Uzbekistan.

In force since 27 March 2026

Enforced by Inspection for Supervision in the Field of Informatisation and Telecommunications (Uzkomnazorat)

How this country controls where data goes: Not allowed

Not fully verified — see “What we're not sure about” below.
Banking

Cloud and outsourcing rules

Official name: Ўзбекистон Республикаси тижорат банклари ахборот хавфсизлиги ва киберхавфсизлигига доир минимал талаблар тўғрисидаги низом · Central Bank Board regulation, registered No. 3669 (August 2025) · Directly binding regulation

In forceYes, with paperwork

Banks are not told to keep customer data in Uzbekistan. But they may not hand the running of their technology and security systems to an outside supplier. They also may not send state secret information over telecommunications networks. That blocks fully managed foreign cloud and outsourced security operations.

In force since 20 November 2025

Enforced by Central Bank of the Republic of Uzbekistan

How this country controls where data goes: Approval each time · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Not fully verified — see “What we're not sure about” below.
Finance

Finance data needs a copy kept in the country

Official name: Кредит бюроларининг ахборот хавфсизлиги ва киберхавфсизлигига доир минимал талаблар тўғрисидаги низом · Central Bank Board regulation, registered No. 3679 on 23 September 2025 · Directly binding regulation

In forceA copy must stay

Credit bureaus must keep people's biometric data inside Uzbekistan. Their other personal data may be handled abroad, using the routes the privacy law allows.

In force since 25 December 2025

Enforced by Central Bank of the Republic of Uzbekistan

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Not fully verified — see “What we're not sure about” below.

Applies to every company5 rules

These bind you whatever business you are in, once the country's rules reach you.

Personal data must stay in the country

Official name: Ўзбекистон Республикасининг Қонуни «Шахсга доир маълумотлар тўғрисида» / Закон Республики Узбекистан «О персональных данных» · ZRU-547 of 2 July 2019, as amended by ZRU-1125 of 26 March 2026 · Act of parliament

In forceYes, with paperwork

This is Uzbekistan's general privacy law. It runs on consent, and you must register every personal data database. Since 27 March 2026 you may store most personal data abroad in three cases. The destination is on the approved country list. Or you use an approved standard contract or group rules. Or you meet international standards.

In force since 1 October 2019Enforced from 27 March 2026

Enforced by State Centre for Personalization under the Cabinet of Ministers

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Important public interest

Personal data must stay in the country (2026)

Official name: Закон «О персональных данных», статья 27-1, часть 2 · Article 27-1(2), as rewritten by ZRU-1125 of 26 March 2026 · Act of parliament

In forceNo — it stays put

Face, fingerprint and other biometric data must be kept inside Uzbekistan. So must genetic data. The article allows storage abroad only for data that is not on this list. So a copy held overseas is not clearly allowed.

In force since 27 March 2026

Enforced by State Centre for Personalization under the Cabinet of Ministers

How this country controls where data goes: Not allowed

Not fully verified — see “What we're not sure about” below.

Telecoms rules

Official name: Постановление Кабинета Министров «Об утверждении Перечня иностранных государств, обеспечивающих адекватную защиту персональных данных» · Cabinet of Ministers Resolution No. 415 of 29 July 2026 · Official “this country is safe” decision

In forceYes, with paperwork

This is the government's list of countries treated as protecting personal data well enough. Sending data to a listed country is the simplest way out of Uzbekistan. We could not read which countries are named, so treat the list as unread. It is a Cabinet resolution and can change at short notice.

In force since 3 August 2026

Enforced by Cabinet of Ministers of the Republic of Uzbekistan

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • Давлат персоналлаштириш маркази / Государственный центр персонализации при Кабинете Министров Республики Узбекистан

    Personal data protection; maintains the State Register of personal data bases; issues binding orders to remedy breaches

    Article 8 of the Law on Personal Data names it as the authorised body. The register service has run as a free five-working-day public service since 2020. We found no published fines or decisions from it. We could not confirm that it has its own public website. So we rate its supervisory activity as waking rather than active.

  • Approves the list of countries with adequate data protection and the register procedure

    Adopted the approved country list on 29 July 2026, in force 3 August 2026.

  • Раqamli texnologiyalar vazirligi

    Digital policy, e-government systems and data centres

  • Axborotlashtirish va telekommunikatsiyalar sohasida nazorat inspeksiyasi

    Supervision of information technology and telecommunications operators, including online services

    Operates under the Ministry of Digital Technologies. It is the body historically linked to restricting access to online services that break the rules. We saw no enforcement items from 2025 or 2026 on its portal page.

  • Ўзбекистон Республикаси Марказий банки

    Banks, credit bureaus, payment system operators — information security and cybersecurity rules

    Issuing binding regulations regularly; two new minimum security regulations took effect in November and December 2025.

  • Давлат хавфсизлик хизмати

    Cybersecurity; receives cyber incident notifications

    Named as the authorised cybersecurity body by the 2022 Law on Cybersecurity. It does not publish enforcement statistics.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Which countries are on the Cabinet of Ministers' list of states with adequate personal data protection (Resolution No. 415 of 29 July 2026)

    The official page on the national legislation database returns only the resolution header and signature block. The appendix with the country names did not load in any language version we tried. Until someone reads the list, assume your destination is not on it.

  • Whether approved standard contractual conditions or binding corporate rules have actually been published

    We searched the full text of the national legislation database on 18 August 2026. Only three documents mention adequate protection of personal data, and none is a contract template. The route exists in the law but looks unusable today.

  • Fine levels under Article 46-1 of the Code on Administrative Liability and the sentence under Article 141-2 of the Criminal Code

    Both articles are confirmed present in the official code texts. Only the article headings loaded, so we could not read the penalty amounts.

  • Whether a copy of biometric, genetic or telecom user data may also be held abroad once a copy is kept in Uzbekistan

    Article 27-1 says these categories must be stored in Uzbekistan. It allows foreign storage only for data not on that list. That reads as a ban on foreign copies, but the article does not say so directly. We record it as closed, which is the cautious reading.

  • Whether the law expressly reaches a foreign company with no presence in Uzbekistan

    The scope article talks about handling data whatever the means, not about territory. The duties attach to owners and operators of databases holding data about citizens of Uzbekistan. That is how foreign platforms were treated in 2021. But there is no express clause saying the law applies to companies with no presence there, of the kind used in Europe.

  • A firm deadline in hours for reporting cyber incidents to the State Security Service

    The cybersecurity law creates the duty to notify. A twenty-four hour figure appears in the law. Our reading found it in a part about officials entering premises. So we do not state it as the incident deadline.

  • Whether the State Centre for Personalization has issued any enforcement decisions or fines

    We could not reach a decisions register or an enforcement page, and could not confirm the centre's own website. We found nothing, but that does not prove nothing exists. The enforcement rating reflects only what we could see.

  • Whether the Tashkent International Financial Centre has its own data protection regime displacing the national law inside the Centre

    The Centre's founding law of 13 July 2026 is listed among the acts amending the Law on Personal Data. It creates a financial services authority with its own rules. The parts about data did not load. This is the most likely place for a separate rulebook to appear.

  • Localisation or storage rules specific to insurance, securities markets, education and online gaming

    We searched the national legislation database on 18 August 2026. We found no rule for these industries about where data must be stored. Finding no rule is not the same as proving there is none. We record this at medium confidence.

  • Minimum keeping periods under tax, accounting and banking record rules

    We did not confirm these. We confirmed only the three-month backup minimum in the cybersecurity law, and the privacy law's duty to destroy data.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.