Country:乌兹别克斯坦 · Data Protection & Compliance
High confidenceUpdated 2026-08-03Handbook

Uzbekistan · Data Protection & Compliance

Uzbekistan personal data protection is framed by the Law on Personal Data (ZRU-547, 2019) and fundamentally loosened by Law No.1125 (passed 2026-03-26, effective 2026-03-27): the previous one-size-fits-all localization requiring 'all citizens' personal data stored domestically' is abolished, leaving only three mandatory-localization categories - biometric data (fingerprints, face/Face ID, iris, voiceprints), genetic data (DNA profiles, medical genetic results) and telecom-operator user data (SIM registration, IMSI/IMEI, connection metadata). Other personal data can be stored and processed cross-border if one of three conditions is met (receiving country on the Cabinet 'adequate protection' list; standard contractual clauses/binding corporate rules approved by the regulator; or international standards approved by the regulator). Database registration is also now limited to the three mandatory-localization database categories. The financial sector is additionally bound by Presidential Decree PP-153 (2025-04-30) on data-breach notification and cybersecurity duties. Chinese enterprises should operate on 'data classification' as the premise: ordinary customer/employee HR data (excluding the three categories) can use global infrastructure, but must establish cross-border transfer compliance mechanisms and wait for secondary legislation such as the Cabinet's 'adequate-protection-country list'; biometric access control, genetic testing and telecom businesses must store domestically and register. Recommend designating a DPO, drafting privacy policies and data-processing agreements, and retaining consent and cross-border transfer evidence.

Key points

Procedure

  1. Data inventory: map personal data types processed in Uzbekistan; classify whether they fall into the three mandatory-localization categories (biometric/genetic/telecom-user).
  2. Localization decision: the three categories require domestic storage with database registration; other data plan cross-border compliance paths.
  3. Cross-border mechanism design: await/compare the Cabinet adequate-protection-country list, or prepare SCCs/BCRs and international-standard compliance arguments.
  4. Policy build: designate a DPO; draft privacy policies, consent mechanisms and data-processing agreements (incl. intra-group cross-border arrangements).
  5. Financial-sector additional rules: if in finance, implement PP-153 breach notification and cybersecurity duty flows.
  6. Registration and evidence: register the three database categories in the national register; retain consent and cross-border transfer evidence.
  7. Continuous monitoring: track Cabinet/regulator secondary legislation issuance; update cross-border and localization arrangements.

Hard requirements

Costs

Data classification, compliance design and DPA/SCC drafting legal and advisory feesDomestic storage and localized database deployment/lease costs (three categories only)DPO and privacy operations headcountFinancial-sector PP-153 compliance and cybersecurity investmentCompliance updates after secondary legislation issuance⏱ ⏱ Timeline:Data inventory and policy build usually weeks to months; three-category database registration before system launch; cross-border mechanisms after Cabinet/regulator secondary legislation clarifies; monitor 2026 issuance continuously.

⚠ Common risks

  • Misclassifying biometric/genetic/telecom data as general data and transferring out: violates mandatory localization
  • Cross-border transfers lack executable paths before secondary legislation; compliance basis unstable
  • Unregistered mandatory-localization databases: penalties
  • Financial sector without PP-153 breach notification: extra liability
  • Missing consent and processing records: disadvantageous evidence in disputes
  • Ignoring biometric data in employee HR data (e.g. facial access control) included in mandatory localization
Handbook

📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)

Applies to:Chinese enterprises processing personal data in Uzbekistan (customer, employee and user data), for data classification, localization and cross-border transfer compliance; pure anonymized data or data without Uzbek personal data are out of scope.

Prerequisites

  • Personal data scope and flows in Uzbekistan identified
  • ZRU-547 and Law No.1125 (effective 2026-03-27) core changes understood
  • Whether the business is in strongly regulated industries (PP-153) determined
  • DPO designated or planned
  • Privacy policy and consent mechanism frameworks prepared
StepActionOwnerTimelineCostOfficial form / systemNotes & penalties
1Personal data inventory and classification
Map personal data collected/processed in Uzbekistan (customers, employees, users); classify each type as biometric, genetic or telecom-user (three mandatory-localization categories) or otherwise; form a data map and classification table
DPO + IT/compliance2-4 weeksInternal/advisoryData map; classification tableEasily overlooked: employee facial access control, medical genetic testing falling into the three categories
2Localization and database registration
For the three mandatory-localization categories, deploy domestic storage (servers/local cloud) and register with the national personal-database register; non-three-category data need no registration
IT + DPOAfter systems are readyLocal storage and registration costsDomestic databases; registration receiptsOnly the three categories require registration; general-enterprise burdens sharply reduced
Penalty:Unregistered mandatory databases: administrative penalties
3Cross-border transfer mechanism design
For non-three-category data, design compliant cross-border paths: await the Cabinet 'adequate-protection-country list', or prepare regulator-approved SCCs/BCRs, or argue compliance with regulator-approved international standards; sign DPAs for intra-group transfers
Legal + DPOContinuous (with secondary legislation)Legal argument and agreement costsDPA/SCC; compliance argument memosBefore secondary legislation, paths exist in law but practice must be cautious and tracked
Penalty:Cross-border transfers without compliant basis: penalties
4Privacy policies and consent mechanisms
Draft privacy policies; build data-subject consent, access, correction and deletion mechanisms; retain processing records; sign data-processing agreements for outsourced/third-party processing
DPO + legalWeeksPolicy build costsPrivacy policies; consent records; processing agreementsConsent and records are key evidence in disputes
Penalty:Missing consent/records: disadvantageous evidence and penalties
5Financial-sector PP-153 additional rules (as applicable)
If a bank, payment or financial institution, implement Presidential Decree PP-153 (2025-04-30) data-breach notification deadlines, flows and cybersecurity duties; clarify internal escalation and regulator engagement
Compliance + securityWeeksSecurity and process investmentBreach-notification SOPs; security assessmentsFinancial-sector duties stricter than general industries
Penalty:Un-notified breaches: additional legal liability
6Monitoring and updates
Continuously track Cabinet 'adequate-protection-country list' and regulator SCC/international-standard list issuance; update cross-border and localization arrangements; review the data map annually
DPO + legalContinuous/annualMonitoring costsCompliance update records; annual reviews2026 secondary legislation is the key observation window

✅ Self-check list

⚠ Common pitfalls

Treating biometric/genetic/telecom data as general data transferred out影响:Violates mandatory localization; heavy penalties and high leak risk规避:Classify item by item at inventory; screen employee facial access and genetic tests closely
Cross-border paths relying on un-issued secondary legislation影响:Compliance basis unstable; no evidence under regulatory inquiry规避:Use the most conservative path first and continuously monitor list/clause issuance
Mandatory databases unregistered影响:Administrative penalties规避:Complete three-category database registration before launch
Financial sector missing PP-153 notifications影响:Extra legal liability and reputational loss规避:Build a dedicated breach-notification SOP for finance
Missing consent and processing records影响:Disadvantageous evidence in disputes规避:Full-flow record retention with periodic audits

📅 Ongoing post-incorporation obligations

  • Three mandatory-localization categories continuously stored domestically with valid database registration
  • Cross-border transfer mechanisms updated as secondary legislation issues; retain evidence
  • Annual review of data maps and classification
  • Financial sector continuously satisfies PP-153 breach notification and cybersecurity duties
  • Privacy policies, consent and processing records continuously maintained and retained

🔗 Official portals

📎 Source:Law on Personal Data (Law No. ZRU-547, 2019-07-02); Law No.1125 (passed 2026-03-26, effective 2026-03-27) fundamentally amending localization and cross-border transfer; Cabinet Resolution No.71 (2020-02-08) state registration of personal databases; Presidential Decree PP-153 (2025-04-30) financial-sector data-breach notification; current legal texts per lex.uz. Practice cross-checked with 2026 compliance interpretations by Bond Stone, Dentons, Nurilla and other firms
Want to turn this into an actionable compliance workflow?

CompliGo · Outbound Compliance Automation

You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.

CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.