Uzbekistan
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Uzbekistan — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Uzbekistan used to require data about its citizens to sit on machines inside the country. In March 2026 it dropped that blanket rule. You can now store most personal data abroad. You need one of three things. The destination country is on a new government approved list. Or you use an approved contract. Or you meet international standards. Three kinds of data still cannot leave at all.
Data governance in Uzbekistan
The eight things that decide how you handle data about people in Uzbekistan. Same eight on every country page, so you can compare.
Who has to follow these rules
The law covers the handling of personal data, whatever tools you use. It was aimed at foreign online platforms when the storage rules were first tightened in 2021. It sets no size or revenue threshold. A small foreign company is treated the same as a large one. We found no clear wording forcing a foreign company to appoint a representative living in Uzbekistan. We also found no sentence saying the law follows the data outside the country.
The Law of the Republic of Uzbekistan 'On Personal Data' is ZRU-547 of 2 July 2019. Its Article 3 says the law applies to the handling and protection of personal data, whatever means are used. There is no express sentence saying the law reaches companies with no presence in the country. The link is indirect. Two articles carry the weight. They are the storage article (Article 27-1) and the registration duty in Article 20. Both attach to any owner or operator of a database holding personal data of citizens of Uzbekistan. In 2021 the authorities treated foreign social platforms as caught by that duty. We could not find a scope sentence like the one in the EU General Data Protection Regulation. We found no duty to appoint a local representative either. So we record scope at medium confidence.
Sources
- Official sourceNational Database of Legislation of the Republic of Uzbekistan (Ministry of Justice)Law on Personal Data (ZRU-547, 2 July 2019), Article 3 — scope
lex.uz
“Действие настоящего Закона распространяется на отношения, возникающие при обработке и защите персональных данных, независимо от применяемых средств обработки”
Link checked 18 August 2026
Where the data is allowed to live
Mostly yes, but you must point to one of three permissions. Face and fingerprint data, genetic data, and data about customers of telephone and internet companies must stay in Uzbekistan. You may store and use everything else abroad in three cases. The destination country is on the government's approved list. Or you sign an approved standard contract, or use approved group rules. Or you follow recognised international data standards.
- What you have to do here:
- Keep the data in the country
Article 27-1 of the Law on Personal Data was rewritten by Law ZRU-1125 of 26 March 2026. Part 2 lists the data that must stay on Uzbek soil. That is biometric data about people, genetic data about people, and data about people who use telecommunications operators' services. Part 3 allows all other personal data to be stored and used outside Uzbekistan where one of three conditions is met. The old blanket requirement is gone. It said data about citizens of Uzbekistan had to be handled on equipment physically located in the country. That rule drove the blocking of foreign platforms in 2021. It no longer appears in the article. Industry overrides follow. Telecoms data must stay in the country by law. Banks are not told where to keep data. But the Central Bank forbids them from outsourcing the running of their technology and security systems. Credit bureaus must keep biometric data in the country. Detailed mapping and survey material is classified under state-secrecy rules. Government systems run on the state e-government data centre. We found no rule about where data must sit for insurance, securities, education or online gaming, checked 18 August 2026.
Sources
- Official sourceNational Database of Legislation of the Republic of UzbekistanLaw ZRU-1125 of 26 March 2026 amending the Law on Personal Data — new Article 27-1
lex.uz
“Обязательному хранению на территории Республики Узбекистан подлежат следующие персональные данные: биометрические данные физических лиц; генетические данные физических лиц; данные физических лиц — пользователей услуг операторов телекоммуникаций”
Link checked 18 August 2026
- Official sourceNational Database of Legislation of the Republic of UzbekistanLaw on Personal Data (ZRU-547), Article 15 — cross-border transfer
lex.uz
“Трансграничной передачей персональных данных является передача персональных данных собственником и (или) оператором за пределы территории Республики Узбекистан.”
Link checked 18 August 2026
- Official sourceCentral Bank of the Republic of Uzbekistan, published on the National Database of LegislationCentral Bank regulation No. 3679 — minimum information and cyber security requirements for credit bureaus (biometric data must be held in Uzbekistan)
lex.uz
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Uzbekistan.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
Uzbekistan uses an approved list. Before ordinary personal data leaves the country, you need one of three things. The destination is on the Cabinet of Ministers' list of countries with adequate protection. Or you use the standard contract terms or group rules approved by the data authority. Or you meet recognised international data standards. The country list was signed on 29 July 2026 and started on 3 August 2026, so it is brand new. We could not read which countries are on it. No approved standard contract template appears to have been published yet.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent
Article 15 of the Law on Personal Data allows transfers to states that adequately protect the rights of the people the data is about. Transfers to other states are allowed with the person's consent. They are also allowed where needed to protect constitutional order, public order, health or morals, or under an international treaty. Article 15 also lets the state restrict or ban cross-border transfers. It can do so to protect constitutional foundations, morality, health, citizens' rights and state security. Article 27-1 part 3, as amended in March 2026, adds three routes for storing data abroad. They are the approved country list, standard contract conditions or binding corporate rules, and meeting international data management standards. The list of approved states is Cabinet of Ministers Resolution No. 415 of 29 July 2026, in force 3 August 2026. We searched the full text of the national legislation database on 18 August 2026. Only three documents mention adequate protection of personal data. They are the law, the 2026 amending law and Resolution 415. That suggests no separate act approving standard contract conditions has been published yet.
Sources
- Official sourceNational Database of Legislation of the Republic of UzbekistanCabinet of Ministers Resolution No. 415 of 29 July 2026 approving the List of foreign states ensuring adequate protection of personal data
lex.uz
Link checked 18 August 2026
- Official sourceNational Database of Legislation of the Republic of UzbekistanLaw ZRU-1125 of 26 March 2026 — three conditions for storing personal data abroad
lex.uz
“Персональные данные, не предусмотренные частью второй настоящей статьи, могут храниться и обрабатываться за пределами территории Республики Узбекистан при выполнении одного из следующих условий”
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
Not fully verified — see “What we're not sure about” below.The regulator, and whether it actually acts
The data regulator is the State Centre for Personalization. It sits under the Cabinet of Ministers. It keeps the national register of personal data databases. It can issue orders that companies and people must obey. It is a working government body, and the registration service has run since 2020. But we found no published fines or decisions. So treat enforcement as waking up rather than active. Cyber incidents go to a different body, the State Security Service. Banks answer separately to the Central Bank.
- What it costs if you get it wrong:
- Criminal liability
Article 8 of the Law on Personal Data names the authorised state body. It is the State Centre for Personalization under the Cabinet of Ministers of the Republic of Uzbekistan. Its listed powers include issuing binding orders to companies and people to fix breaches of personal data law. It also maintains the State Register of personal data bases. Cabinet of Ministers Resolution No. 71 of 8 February 2020 sets up the register as a free public service. It must be decided within five working days. It can be refused only for inaccurate or incomplete information. Penalties exist in two places. The Code on Administrative Liability, Article 46-1, covers breach of personal data law. The Criminal Code, Article 141-2, does the same. We confirmed both are present in the official texts. Separately, the State Security Service is the authorised body for cybersecurity under Law ZRU-764 of 15 April 2022. Uzkomnazorat is the inspection body under the Ministry of Digital Technologies. It supervises the information technology and telecommunications industry. We found no published enforcement decisions on personal data from any of them.
Sources
- Official sourceNational Database of Legislation of the Republic of UzbekistanLaw on Personal Data, Article 8 — the authorised state body and its powers
lex.uz
“Уполномоченным государственным органом в области персональных данных является Государственный центр персонализации при Кабинете Министров Республики Узбекистан”
Link checked 18 August 2026
- Official sourceNational Database of Legislation of the Republic of UzbekistanCabinet of Ministers Resolution No. 71 of 8 February 2020 — administrative regulation for the State Register of personal data bases
lex.uz
Link checked 18 August 2026
- Official sourceGovernment Portal of the Republic of UzbekistanUzkomnazorat — Inspection for Supervision in the Field of Informatisation and Telecommunications under the Ministry of Digital Technologies
gov.uz
Link checked 18 August 2026
How long you must keep it — and when to delete it
The limit on keeping data is clear. You must destroy personal data once you achieve the purpose. You must also destroy it when consent is withdrawn, when the agreed period ends, or when a court orders it. The minimum keeping rules are thinner. Organisations covered by the cybersecurity law must keep backup copies covering at least the last three months. We did not confirm the general tax and accounting minimums. So plan on the usual company record rules as well.
- What you have to do here:
- Keep data for a minimum period
Article 10 of the Law on Personal Data ties the storage period to the date you achieve the purposes you collected the data for. Article 17 requires you to destroy personal data when you achieve the purpose. You must also destroy it when consent is withdrawn. Or when the period set in the consent expires. Or when a court decision takes legal effect. Law ZRU-764 of 15 April 2022 on Cybersecurity requires a backup copy covering at least the last three months. Sometimes a duty to keep data under tax, accounting or banking rules clashes with the duty to destroy it. The specific keeping duty usually wins. We found no single sentence in the law that states that tie-breaker.
Sources
- Official sourceNational Database of Legislation of the Republic of UzbekistanLaw on Personal Data, Articles 10 and 17 — storage period and destruction
lex.uz
“Персональные данные подлежат уничтожению собственником и (или) оператором... при достижении цели обработки персональных данных; при наличии отзыва согласия субъекта”
Link checked 18 August 2026
- Official sourceNational Database of Legislation of the Republic of UzbekistanLaw on Cybersecurity (ZRU-764, 15 April 2022) — backup copies kept for at least the last three months
lex.uz
“резервной копии данных, срок хранения которой не должен быть менее трех последних месяцев”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
There are two deadlines and they are not the same. The privacy law itself has no duty to report a data breach. Not to the regulator, and not to the people affected. We checked the text on 18 August 2026 and found none. Reporting lives in the cybersecurity law instead. Organisations it covers must tell the State Security Service about cyber incidents. Banks also report to the Central Bank under its security rules. We could not confirm a firm deadline in hours for any of these.
- What you have to do here:
- Report cyber incidents · Secure the data
Law ZRU-764 of 15 April 2022 on Cybersecurity makes the State Security Service the authorised body. It requires the organisations it covers to tell that service about cybersecurity incidents that have happened. A twenty-four hour figure appears in the law. Our reading found it in a different part of the law, so we do not state it as the incident deadline. The Law on Personal Data has no breach notification article. So a company hacked in Uzbekistan reports up the security chain, not to the privacy regulator. People affected have no legal right to be told.
Sources
- Official sourceNational Database of Legislation of the Republic of UzbekistanLaw on Cybersecurity (ZRU-764), Articles 11 and 16 — authorised body and duty to notify incidents
lex.uz
“Служба государственной безопасности Республики Узбекистан является уполномоченным государственным органом в сфере кибербезопасности”
Link checked 18 August 2026
- Official sourceNational Database of Legislation of the Republic of UzbekistanLaw on Personal Data — full text checked for a breach notification duty on 18 August 2026; none found
lex.uz
Link checked 18 August 2026
What catches people out
First, you must enter every database of personal data in a national register. It is a notification, it is free and it takes five working days. Skipping it is still a breach. Second, breaking the personal data rules can be a crime, not just a fine. A named person can be prosecuted. Third, the face and fingerprint rule catches ordinary products like fingerprint logins and identity checks, not just spy technology. Fourth, banks may not hand the running of their technology and security systems to an outside supplier. That rules out most managed cloud and outsourced security operations. Fifth, the standard contract route for sending data abroad exists on paper. No approved template appears to have been published.
- What you have to do here:
- Register or notify
- What it costs if you get it wrong:
- Criminal liability
Trap 1. Article 20 of the Law on Personal Data requires registration in the State Register of personal data bases. Cabinet Resolution No. 71 of 2020 makes it a free notification service, decided in five working days. It can be refused only for inaccurate or incomplete information. Trap 2. Administrative liability sits in Article 46-1 of the Code on Administrative Liability. Criminal liability sits in Article 141-2 of the Criminal Code. Both are headed 'breach of personal data legislation'. We confirmed both articles exist in the official texts, but could not read the penalty figures. Trap 3. Biometric and genetic data must be held inside Uzbekistan. The Central Bank has applied that specifically to credit bureaus from 25 December 2025. Trap 4. The Central Bank set minimum information security and cybersecurity requirements for commercial banks, effective 20 November 2025. Banks may not outsource the running of their information and communication technology infrastructure. They may not outsource the running of their information security and cybersecurity systems. They also may not send state secret information over telecommunications networks. Trap 5. Only three documents in the national legislation database mention adequate protection of personal data. So the standard contract conditions promised by the March 2026 amendment do not appear to have been issued yet.
Sources
- Official sourceNational Database of Legislation of the Republic of UzbekistanCabinet of Ministers Resolution No. 71 of 8 February 2020 — State Register of personal data bases, five working days, no fee
lex.uz
Link checked 18 August 2026
- Official sourceNational Database of Legislation of the Republic of UzbekistanCriminal Code of the Republic of Uzbekistan, Article 141-2 — breach of personal data legislation
lex.uz
“Статья 141 2 . Нарушение законодательства о персональных данных”
Link checked 18 August 2026
- Official sourceCentral Bank of the Republic of Uzbekistan, published on the National Database of LegislationCentral Bank regulation No. 3669 — minimum information and cyber security requirements for commercial banks (outsourcing prohibition)
lex.uz
“ахборот-коммуникация технологиялари инфратузилмалари ҳамда ахборот хавфсизлиги ва киберхавфсизликни таъминлаш тизимларини бошқариш... вазифаларини шартнома асосида хизмат кўрсатувчи тадбиркорлик субъектларига (аутсорсинг) бериш тақиқланади”
Link checked 18 August 2026
What's changing next
The big change already happened in March 2026, and the follow-up is still landing. The approved country list started on 3 August 2026. The Cabinet of Ministers can widen or cut it at any time. The approved standard contract for sending data abroad is still missing, so watch for it. A new Tashkent International Financial Centre opened its legal rules on 25 July 2026. Its law also touched the privacy law, so a separate rulebook may appear inside the centre. A national cybersecurity strategy was signed in March 2026.
- Ways to send data out:
- Official 'this country is safe' decision
Powers already held that you should watch. First, Article 15 of the Law on Personal Data lets the state restrict or ban cross-border transfers. It can do so to protect constitutional foundations, morality, health, citizens' rights and state security. No consultation is needed. Second, the approved country list is a Cabinet of Ministers resolution. Countries can be added or removed by a single act. Third, Article 27-1 part 2 lists the data that must stay in the country. Adding a category means amending one sentence. New or pending laws follow. Cabinet of Ministers Resolution No. 415 of 29 July 2026 is the approved country list, in force 3 August 2026. Law ZRU-1158 of 13 July 2026 on the Tashkent International Financial Centre came into force on 25 July 2026. It is listed among the acts amending the Law on Personal Data. It creates a Financial Services Authority with its own rules. Presidential Decree UP-38 of 10 March 2026 approved the Cybersecurity Strategy and improved cybercrime prevention.
Sources
- Official sourceNational Database of Legislation of the Republic of UzbekistanLaw ZRU-1158 of 13 July 2026 on the Tashkent International Financial Centre (in force 25 July 2026)
lex.uz
Link checked 18 August 2026
- Official sourceNational Database of Legislation of the Republic of UzbekistanPresidential Decree UP-38 of 10 March 2026 on the Cybersecurity Strategy of the Republic of Uzbekistan
lex.uz
Link checked 18 August 2026
- Official sourceNational Database of Legislation of the Republic of UzbekistanCabinet of Ministers Resolution No. 415 of 29 July 2026 — the adequacy list, changeable by resolution
lex.uz
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries5 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Telecoms data must stay in the country
Official name: Закон «О персональных данных», статья 27-1, часть 2 (данные пользователей услуг операторов телекоммуникаций) · Article 27-1(2), third indent; see also Law on Telecommunications ZRU-1015 of 27 December 2024 · Act of parliament
Data about people who use telecommunications operators' services must be stored in Uzbekistan. This is the one strict industry rule left in the 2026 rewrite. It catches any operator serving users in Uzbekistan.
Enforced by Inspection for Supervision in the Field of Informatisation and Telecommunications (Uzkomnazorat)
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the country
Sources
- Official sourceNational Database of Legislation of the Republic of UzbekistanLaw ZRU-1125 of 26 March 2026 — telecommunications users' data must be stored in Uzbekistan
lex.uz
“данные физических лиц — пользователей услуг операторов телекоммуникаций”
Link checked 18 August 2026
- Official sourceNational Database of Legislation of the Republic of UzbekistanLaw on Telecommunications (ZRU-1015 of 27 December 2024), in force 28 December 2024
lex.uz
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Ўзбекистон Республикаси тижорат банклари ахборот хавфсизлиги ва киберхавфсизлигига доир минимал талаблар тўғрисидаги низом · Central Bank Board regulation, registered No. 3669 (August 2025) · Directly binding regulation
Banks are not told to keep customer data in Uzbekistan. But they may not hand the running of their technology and security systems to an outside supplier. They also may not send state secret information over telecommunications networks. That blocks fully managed foreign cloud and outsourced security operations.
Enforced by Central Bank of the Republic of Uzbekistan
How this country controls where data goes: Approval each time · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Secure the data
- Written vendor contractBanks may not outsource the running of their technology infrastructure. They may not outsource their information security and cybersecurity systems either.
Sources
- Official sourceCentral Bank of the Republic of Uzbekistan, published on the National Database of LegislationRegulation on minimum information security and cybersecurity requirements for commercial banks (reg. No. 3669)
lex.uz
“Телекоммуникация тармоғи орқали давлат сирларини ташкил этувчи маълумотларнинг узатилиши тақиқланади”
Link checked 18 August 2026
Finance data needs a copy kept in the country
Official name: Кредит бюроларининг ахборот хавфсизлиги ва киберхавфсизлигига доир минимал талаблар тўғрисидаги низом · Central Bank Board regulation, registered No. 3679 on 23 September 2025 · Directly binding regulation
Credit bureaus must keep people's biometric data inside Uzbekistan. Their other personal data may be handled abroad, using the routes the privacy law allows.
Enforced by Central Bank of the Republic of Uzbekistan
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Keep the data in the countryBiometric data of individuals must be held on Uzbek territory.
- Secure the data
Sources
- Official sourceCentral Bank of the Republic of Uzbekistan, published on the National Database of LegislationRegulation on minimum information security and cybersecurity requirements for credit bureaus (reg. No. 3679)
lex.uz
“жисмоний шахсларнинг биометрик маълумотлари Ўзбекистон Республикаси ҳудудида сақланиши шарт”
Link checked 18 August 2026
State and security data rules
Official name: Положение о порядке установления ограничительных грифов картографических и геодезических материалов (данных) · Cabinet of Ministers Resolution No. 22 of 14 January 2020; Law on Geodetic and Cartographic Activity ZRU-626 of 2 July 2020 · Directly binding regulation
Detailed mapping and survey material can be given a restricted classification mark. It is then handled under state secrecy rules, and you need permission before releasing it. We could not read the scale and accuracy thresholds. Treat this as a warning rather than a measured limit.
Enforced by Cabinet of Ministers of the Republic of Uzbekistan
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryApplies to mapping and survey material carrying a restrictive classification mark.
Sources
- Official sourceNational Database of Legislation of the Republic of UzbekistanCabinet of Ministers Resolution No. 22 of 14 January 2020 on restrictive classification marks for cartographic and geodetic materials
lex.uz
Link checked 18 August 2026
- Official sourceNational Database of Legislation of the Republic of UzbekistanLaw on Geodetic and Cartographic Activity (ZRU-626 of 2 July 2020)
lex.uz
Link checked 18 August 2026
Government data needs a copy kept in the country
Official name: О мерах по организации деятельности Центра обработки данных системы «Электронное правительство» · Cabinet of Ministers Resolution No. 107 of 14 March 2023 · Directly binding regulation
Government information systems run through the state's own e-government data centre in Uzbekistan. If you sell to the public sector, expect hosting inside the country rather than your own cloud region.
Enforced by Ministry of Digital Technologies
What you have to do
- Keep the data in the countryGovernment systems are served by the national e-government data centre inside Uzbekistan.
Sources
- Official sourceNational Database of Legislation of the Republic of UzbekistanCabinet of Ministers Resolution No. 107 of 14 March 2023 on the Data Processing Centre of the E-Government system
lex.uz
Link checked 18 August 2026
Applies to every company5 rules
These bind you whatever business you are in, once the country's rules reach you.
Personal data must stay in the country
Official name: Ўзбекистон Республикасининг Қонуни «Шахсга доир маълумотлар тўғрисида» / Закон Республики Узбекистан «О персональных данных» · ZRU-547 of 2 July 2019, as amended by ZRU-1125 of 26 March 2026 · Act of parliament
This is Uzbekistan's general privacy law. It runs on consent, and you must register every personal data database. Since 27 March 2026 you may store most personal data abroad in three cases. The destination is on the approved country list. Or you use an approved standard contract or group rules. Or you meet international standards.
Enforced by State Centre for Personalization under the Cabinet of Ministers
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Important public interest
What you have to do
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Secure the data
- Register or notifyYou must enter every personal data base in the State Register of personal data bases. Report changes within ten calendar days.
- Delete data after a periodDestroy it when you achieve the purpose, when consent is withdrawn, when the agreed period expires, or when a court orders it.
- Put a transfer safeguard in place — from 27 March 2026
- Keep the data in the country — from 27 March 2026Only for biometric data, genetic data and telecommunications users' data.
What it costs if you get it wrong
- Criminal liabilityBreach of personal data legislation — Criminal Code Article 141-2. Penalty figures not verified.
- Fixed maximum fineBreach of personal data legislation — Code on Administrative Liability Article 46-1. Fine amounts not verified.
Sources
- Official sourceNational Database of Legislation of the Republic of UzbekistanLaw on Personal Data (ZRU-547 of 2 July 2019), consolidated text
lex.uz
Link checked 18 August 2026
- Official sourceNational Database of Legislation of the Republic of UzbekistanLaw ZRU-1125 of 26 March 2026 amending the Law on Personal Data
lex.uz
Link checked 18 August 2026
Personal data must stay in the country (2026)
Official name: Закон «О персональных данных», статья 27-1, часть 2 · Article 27-1(2), as rewritten by ZRU-1125 of 26 March 2026 · Act of parliament
Face, fingerprint and other biometric data must be kept inside Uzbekistan. So must genetic data. The article allows storage abroad only for data that is not on this list. So a copy held overseas is not clearly allowed.
Enforced by State Centre for Personalization under the Cabinet of Ministers
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the country
Sources
- Official sourceNational Database of Legislation of the Republic of UzbekistanLaw ZRU-1125 of 26 March 2026 — Article 27-1(2), mandatory storage in Uzbekistan
lex.uz
“Обязательному хранению на территории Республики Узбекистан подлежат следующие персональные данные: биометрические данные физических лиц; генетические данные физических лиц”
Link checked 18 August 2026
Telecoms rules
Official name: Постановление Кабинета Министров «Об утверждении Перечня иностранных государств, обеспечивающих адекватную защиту персональных данных» · Cabinet of Ministers Resolution No. 415 of 29 July 2026 · Official “this country is safe” decision
This is the government's list of countries treated as protecting personal data well enough. Sending data to a listed country is the simplest way out of Uzbekistan. We could not read which countries are named, so treat the list as unread. It is a Cabinet resolution and can change at short notice.
Enforced by Cabinet of Ministers of the Republic of Uzbekistan
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision
What you have to do
- Put a transfer safeguard in place — from 3 August 2026
Sources
- Official sourceNational Database of Legislation of the Republic of UzbekistanCabinet of Ministers Resolution No. 415 of 29 July 2026 approving the List of foreign states ensuring adequate protection of personal data
lex.uz
Link checked 18 August 2026
General data protection law
Official name: Административный регламент оказания государственной услуги по ведению Государственного реестра баз персональных данных · Cabinet of Ministers Resolution No. 71 of 8 February 2020 · Directly binding regulation
Owners and operators of personal data databases must notify the State Register. The service is free and must be dealt with in five working days. The authority may only refuse if the form is wrong or incomplete.
Enforced by State Centre for Personalization under the Cabinet of Ministers
What you have to do
- Register or notifyA free notification service, decided in five working days. It can be refused only for inaccurate or incomplete information.
- Keep records of how you use data
Sources
- Official sourceNational Database of Legislation of the Republic of UzbekistanCabinet of Ministers Resolution No. 71 of 8 February 2020 — administrative regulation for the State Register of personal data bases
lex.uz
“Отказ в оказании государственных услуг по иным основаниям... не допускается”
Link checked 18 August 2026
Cyber security rules
Official name: Закон Республики Узбекистан «О кибербезопасности» · ZRU-764 of 15 April 2022 · Act of parliament
The cybersecurity law puts the State Security Service in charge. You must report cyber incidents to it. You must also keep backup copies covering at least the last three months.
Enforced by State Security Service
What you have to do
- Report cyber incidentsThe organisations it covers must tell the State Security Service about incidents. We could not confirm a deadline in hours.
- Secure the data
- Keep logs — 3 monthsBackup copy covering at least the last three months.
Sources
- Official sourceNational Database of Legislation of the Republic of UzbekistanLaw on Cybersecurity (ZRU-764 of 15 April 2022)
lex.uz
“уведомлять уполномоченный государственный орган о произошедших инцидентах кибербезопасности”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Which countries are on the Cabinet of Ministers' list of states with adequate personal data protection (Resolution No. 415 of 29 July 2026)
The official page on the national legislation database returns only the resolution header and signature block. The appendix with the country names did not load in any language version we tried. Until someone reads the list, assume your destination is not on it.
Whether approved standard contractual conditions or binding corporate rules have actually been published
We searched the full text of the national legislation database on 18 August 2026. Only three documents mention adequate protection of personal data, and none is a contract template. The route exists in the law but looks unusable today.
Fine levels under Article 46-1 of the Code on Administrative Liability and the sentence under Article 141-2 of the Criminal Code
Both articles are confirmed present in the official code texts. Only the article headings loaded, so we could not read the penalty amounts.
Whether a copy of biometric, genetic or telecom user data may also be held abroad once a copy is kept in Uzbekistan
Article 27-1 says these categories must be stored in Uzbekistan. It allows foreign storage only for data not on that list. That reads as a ban on foreign copies, but the article does not say so directly. We record it as closed, which is the cautious reading.
Whether the law expressly reaches a foreign company with no presence in Uzbekistan
The scope article talks about handling data whatever the means, not about territory. The duties attach to owners and operators of databases holding data about citizens of Uzbekistan. That is how foreign platforms were treated in 2021. But there is no express clause saying the law applies to companies with no presence there, of the kind used in Europe.
A firm deadline in hours for reporting cyber incidents to the State Security Service
The cybersecurity law creates the duty to notify. A twenty-four hour figure appears in the law. Our reading found it in a part about officials entering premises. So we do not state it as the incident deadline.
Whether the State Centre for Personalization has issued any enforcement decisions or fines
We could not reach a decisions register or an enforcement page, and could not confirm the centre's own website. We found nothing, but that does not prove nothing exists. The enforcement rating reflects only what we could see.
Whether the Tashkent International Financial Centre has its own data protection regime displacing the national law inside the Centre
The Centre's founding law of 13 July 2026 is listed among the acts amending the Law on Personal Data. It creates a financial services authority with its own rules. The parts about data did not load. This is the most likely place for a separate rulebook to appear.
Localisation or storage rules specific to insurance, securities markets, education and online gaming
We searched the national legislation database on 18 August 2026. We found no rule for these industries about where data must be stored. Finding no rule is not the same as proving there is none. We record this at medium confidence.
Minimum keeping periods under tax, accounting and banking record rules
We did not confirm these. We confirmed only the three-month backup minimum in the cybersecurity law, and the privacy law's duty to destroy data.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.