• info@bondstonelaw.com

Data Protection Compliance in Uzbekistan

Data Protection Compliance in Uzbekistan

Data Protection Compliance in Uzbekistan

UZBEKISTAN  ·  DATA PROTECTION

Data Protection Compliance in Uzbekistan

Bond Stone advises on data protection compliance programme implementation in Uzbekistan — database registration with the State Register of Personal Data Bases, DPO appointment, breach notification under Presidential Decree No. PP-153 (financial sector), cross-border transfer compliance under ZRU-547 as amended by Law No. 1125 (March 2026), and internal data protection policies for foreign-invested entities.

Primary authority: Law of the Republic of Uzbekistan “On Personal Data” No. ZRU-547 dated 2 July 2019 (as amended by Law No. 1125 dated 26 March 2026). Verify at lex.uz

⚠️ March 2026 Reform

Law No. 1125 dated 26 March 2026 fundamentally changed Uzbekistan’s data localisation rules. Only biometric, genetic, and telecommunications user data must now be stored in Uzbekistan. All other personal data may be stored abroad subject to security requirements.


Key Framework

Database registration — State Register

Organisations processing personal data in Uzbekistan are required to register their personal data databases with the State Register of Personal Data Bases under Resolution No. 71 of the Cabinet of Ministers dated 8 February 2020. The State Personalization Center under the Cabinet of Ministers is the responsible authority. Bond Stone advises on the registration procedure, required documentation, registration timeline, and the categories of databases that are exempt from registration.

DPO appointment

Organisations processing personal data in Uzbekistan must designate a person responsible for data protection — fulfilling the DPO function under ZRU-547. The responsible person oversees compliance with the Law, handles data subject rights requests, manages consent mechanisms, and liaises with the State Personalization Center. Bond Stone advises on DPO appointment, role definition, and minimum competency requirements.

Financial sector — PP-153 obligations

Presidential Decree No. PP-153 dated 30 April 2025 introduced compulsory breach notification obligations and legal liability for data incidents specifically for financial sector entities — banks, payment organisations, micro-finance institutions, and insurance companies. Financial sector entities must implement: mandatory breach notification procedures; technical and organisational security measures against cyber incidents; internal data incident response plans; and regulatory reporting to the Central Bank and State Personalization Center. Bond Stone advises financial sector clients on PP-153 compliance frameworks.

Cross-border transfer compliance — post-reform

Following Law No. 1125 (March 2026), non-restricted personal data may be transferred outside Uzbekistan subject to: (1) the receiving country providing adequate personal data protection (Cabinet of Ministers-approved list); or (2) data subject explicit consent for transfers to non-adequate jurisdictions; or (3) legal or treaty basis. Bond Stone advises on structuring cross-border data transfers within the new framework and drafting data transfer agreements for intercompany data sharing.

Internal compliance programme

A complete data protection compliance programme under ZRU-547 includes: data mapping — identifying all processing activities; database registration; lawful basis analysis; privacy notices for employees and customers; consent management; data processing agreements with processors; data subject rights procedures; breach response plan; DPO function; and post-March 2026 localisation assessment. Bond Stone advises on building and implementing compliance programmes for foreign-invested entities operating in Uzbekistan.


Experience

Database Registration — Market Entry

Compliance · Uzbekistan · Corporate

Advising a foreign company establishing a Uzbek subsidiary on registering its personal data databases with the State Register — identifying registrable databases, preparing registration documentation, and engaging with the State Personalization Center.

PP-153 — Bank Compliance Framework

Compliance · Uzbekistan · Banking

Advising a foreign bank’s Uzbek subsidiary on implementing the PP-153 breach notification and cybersecurity obligations — establishing a data incident response plan, breach classification criteria, notification timeline, and regulatory reporting procedures.

Cross-border Transfer Agreement

Compliance · Uzbekistan · Corporate

Drafting an intragroup cross-border data transfer agreement for a multinational’s Uzbek subsidiary — covering non-restricted data categories eligible for offshore storage, security protocol requirements, and data subject rights provisions under ZRU-547.

Privacy Notice — Digital Platform

Compliance · Uzbekistan · Technology

Drafting a ZRU-547-compliant privacy policy and consent notice for a digital platform operating in Uzbekistan — covering data categories, processing purposes, localisation status post-reform, cross-border transfer disclosure, and data subject rights.

Data Processing Agreement — SaaS

Compliance · Uzbekistan · Technology

Drafting data processing agreements between a Uzbek entity and international SaaS vendors — processor obligations, sub-processing restrictions, breach notification requirements under PP-153, and data deletion provisions.

Compliance Audit — Manufacturing

Compliance · Uzbekistan · Manufacturing

Conducting a data protection compliance audit for a foreign manufacturer’s Uzbek entity — reviewing processing activities against ZRU-547, database registration status, localisation post-reform, consent framework, and PP-153 applicability.

Why Bond Stone

✦  Tashkent office — direct engagement with the State Personalization Center

✦  Ranked Legal 500 EMEA and IFLR1000

Primary authority: lex.uz


Discuss your data protection matter

Contact Bond Stone for a confidential discussion about Data Protection Compliance in Uzbekistan.

📧 info@bondstonelaw.com
📞 +7 (701) 729 76 72

Request a Confidential Consultation
← Data Localisation
← Data Protection Hub
← Data Protection Hub