Country:乌兹别克斯坦 · Data Protection & Compliance
Uzbekistan · Data Protection & Compliance
Uzbekistan personal data protection is framed by the Law on Personal Data (ZRU-547, 2019) and fundamentally loosened by Law No.1125 (passed 2026-03-26, effective 2026-03-27): the previous one-size-fits-all localization requiring 'all citizens' personal data stored domestically' is abolished, leaving only three mandatory-localization categories - biometric data (fingerprints, face/Face ID, iris, voiceprints), genetic data (DNA profiles, medical genetic results) and telecom-operator user data (SIM registration, IMSI/IMEI, connection metadata). Other personal data can be stored and processed cross-border if one of three conditions is met (receiving country on the Cabinet 'adequate protection' list; standard contractual clauses/binding corporate rules approved by the regulator; or international standards approved by the regulator). Database registration is also now limited to the three mandatory-localization database categories. The financial sector is additionally bound by Presidential Decree PP-153 (2025-04-30) on data-breach notification and cybersecurity duties. Chinese enterprises should operate on 'data classification' as the premise: ordinary customer/employee HR data (excluding the three categories) can use global infrastructure, but must establish cross-border transfer compliance mechanisms and wait for secondary legislation such as the Cabinet's 'adequate-protection-country list'; biometric access control, genetic testing and telecom businesses must store domestically and register. Recommend designating a DPO, drafting privacy policies and data-processing agreements, and retaining consent and cross-border transfer evidence.
Key points
- Legislative framework: ZRU-547 (2019) is the base law; Law No.1125 (effective 2026-03-27) reconstructs localization and cross-border transfer - the current core variable.
- Three mandatory-localization categories: only biometric, genetic and telecom-operator user data must be stored in domestic Uzbek databases and registered in the national personal-database register.
- Cross-border opening: other personal data can leave the country, subject to one of three conditions - Cabinet 'adequate protection' country determination, regulator-approved SCCs/BCRs, or compliance with regulator-approved international standards.
- Secondary legislation pending: the Cabinet 'adequate-protection-country list' and regulator 'SCC/international-standard list' are not fully issued; cross-border paths exist in law but practice requires continuous tracking.
- Database registration: previously all databases required registration; now only the three mandatory-localization categories do, sharply reducing general-enterprise burdens.
- Financial-sector special duties: Presidential Decree PP-153 (2025-04-30) sets data-breach notification and cybersecurity duties for banks, payment and financial institutions.
- Compliance actions: data classification, DPO designation, privacy policies and consent mechanisms, cross-border data-transfer agreements (DPA/SCC).
- Penalties and risks: violation processing/cross-border transfer and unregistered mandatory databases subject to administrative penalties; mandatory-localization data (biometric etc.) leakage carries the highest risk.
Procedure
- Data inventory: map personal data types processed in Uzbekistan; classify whether they fall into the three mandatory-localization categories (biometric/genetic/telecom-user).
- Localization decision: the three categories require domestic storage with database registration; other data plan cross-border compliance paths.
- Cross-border mechanism design: await/compare the Cabinet adequate-protection-country list, or prepare SCCs/BCRs and international-standard compliance arguments.
- Policy build: designate a DPO; draft privacy policies, consent mechanisms and data-processing agreements (incl. intra-group cross-border arrangements).
- Financial-sector additional rules: if in finance, implement PP-153 breach notification and cybersecurity duty flows.
- Registration and evidence: register the three database categories in the national register; retain consent and cross-border transfer evidence.
- Continuous monitoring: track Cabinet/regulator secondary legislation issuance; update cross-border and localization arrangements.
Hard requirements
- Personal data classification completed; three mandatory-localization categories identified
- Three-category data stored domestically with national database registration
- Cross-border transfers of non-three-category data satisfy one of three conditions with evidence
- DPO designated with privacy policies
- Data-subject consent obtained with processing records
- Financial sector satisfies PP-153 breach notification and cybersecurity duties
Costs
Data classification, compliance design and DPA/SCC drafting legal and advisory feesDomestic storage and localized database deployment/lease costs (three categories only)DPO and privacy operations headcountFinancial-sector PP-153 compliance and cybersecurity investmentCompliance updates after secondary legislation issuance⏱ ⏱ Timeline:Data inventory and policy build usually weeks to months; three-category database registration before system launch; cross-border mechanisms after Cabinet/regulator secondary legislation clarifies; monitor 2026 issuance continuously.⚠ Common risks
- Misclassifying biometric/genetic/telecom data as general data and transferring out: violates mandatory localization
- Cross-border transfers lack executable paths before secondary legislation; compliance basis unstable
- Unregistered mandatory-localization databases: penalties
- Financial sector without PP-153 breach notification: extra liability
- Missing consent and processing records: disadvantageous evidence in disputes
- Ignoring biometric data in employee HR data (e.g. facial access control) included in mandatory localization
Handbook
📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)
Applies to:Chinese enterprises processing personal data in Uzbekistan (customer, employee and user data), for data classification, localization and cross-border transfer compliance; pure anonymized data or data without Uzbek personal data are out of scope.
Prerequisites
- Personal data scope and flows in Uzbekistan identified
- ZRU-547 and Law No.1125 (effective 2026-03-27) core changes understood
- Whether the business is in strongly regulated industries (PP-153) determined
- DPO designated or planned
- Privacy policy and consent mechanism frameworks prepared
| Step | Action | Owner | Timeline | Cost | Official form / system | Notes & penalties |
|---|---|---|---|---|---|---|
| 1 | Personal data inventory and classification Map personal data collected/processed in Uzbekistan (customers, employees, users); classify each type as biometric, genetic or telecom-user (three mandatory-localization categories) or otherwise; form a data map and classification table | DPO + IT/compliance | 2-4 weeks | Internal/advisory | Data map; classification table | Easily overlooked: employee facial access control, medical genetic testing falling into the three categories |
| 2 | Localization and database registration For the three mandatory-localization categories, deploy domestic storage (servers/local cloud) and register with the national personal-database register; non-three-category data need no registration | IT + DPO | After systems are ready | Local storage and registration costs | Domestic databases; registration receipts | Only the three categories require registration; general-enterprise burdens sharply reduced Penalty:Unregistered mandatory databases: administrative penalties |
| 3 | Cross-border transfer mechanism design For non-three-category data, design compliant cross-border paths: await the Cabinet 'adequate-protection-country list', or prepare regulator-approved SCCs/BCRs, or argue compliance with regulator-approved international standards; sign DPAs for intra-group transfers | Legal + DPO | Continuous (with secondary legislation) | Legal argument and agreement costs | DPA/SCC; compliance argument memos | Before secondary legislation, paths exist in law but practice must be cautious and tracked Penalty:Cross-border transfers without compliant basis: penalties |
| 4 | Privacy policies and consent mechanisms Draft privacy policies; build data-subject consent, access, correction and deletion mechanisms; retain processing records; sign data-processing agreements for outsourced/third-party processing | DPO + legal | Weeks | Policy build costs | Privacy policies; consent records; processing agreements | Consent and records are key evidence in disputes Penalty:Missing consent/records: disadvantageous evidence and penalties |
| 5 | Financial-sector PP-153 additional rules (as applicable) If a bank, payment or financial institution, implement Presidential Decree PP-153 (2025-04-30) data-breach notification deadlines, flows and cybersecurity duties; clarify internal escalation and regulator engagement | Compliance + security | Weeks | Security and process investment | Breach-notification SOPs; security assessments | Financial-sector duties stricter than general industries Penalty:Un-notified breaches: additional legal liability |
| 6 | Monitoring and updates Continuously track Cabinet 'adequate-protection-country list' and regulator SCC/international-standard list issuance; update cross-border and localization arrangements; review the data map annually | DPO + legal | Continuous/annual | Monitoring costs | Compliance update records; annual reviews | 2026 secondary legislation is the key observation window |
✅ Self-check list
⚠ Common pitfalls
Treating biometric/genetic/telecom data as general data transferred out影响:Violates mandatory localization; heavy penalties and high leak risk规避:Classify item by item at inventory; screen employee facial access and genetic tests closely
Cross-border paths relying on un-issued secondary legislation影响:Compliance basis unstable; no evidence under regulatory inquiry规避:Use the most conservative path first and continuously monitor list/clause issuance
Mandatory databases unregistered影响:Administrative penalties规避:Complete three-category database registration before launch
Financial sector missing PP-153 notifications影响:Extra legal liability and reputational loss规避:Build a dedicated breach-notification SOP for finance
Missing consent and processing records影响:Disadvantageous evidence in disputes规避:Full-flow record retention with periodic audits
📅 Ongoing post-incorporation obligations
- Three mandatory-localization categories continuously stored domestically with valid database registration
- Cross-border transfer mechanisms updated as secondary legislation issues; retain evidence
- Annual review of data maps and classification
- Financial sector continuously satisfies PP-153 breach notification and cybersecurity duties
- Privacy policies, consent and processing records continuously maintained and retained
🔗 Official portals
📎 Source:Law on Personal Data (Law No. ZRU-547, 2019-07-02); Law No.1125 (passed 2026-03-26, effective 2026-03-27) fundamentally amending localization and cross-border transfer; Cabinet Resolution No.71 (2020-02-08) state registration of personal databases; Presidential Decree PP-153 (2025-04-30) financial-sector data-breach notification; current legal texts per lex.uz. Practice cross-checked with 2026 compliance interpretations by Bond Stone, Dentons, Nurilla and other firms
Want to turn this into an actionable compliance workflow?
CompliGo · Outbound Compliance Automation
You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.
CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.