HomeServicesData ProtectionUzbekistan

Data Protection in Uzbekistan

A European technology company entering the Uzbek market signs a data-sharing agreement with a local partner, transfers customer records to servers in Tashkent, and assumes that its existing GDPR-compliant processes will satisfy local requirements. Within weeks, the company receives a formal inquiry from the regulatory authority – an inquiry that triggers a compliance audit, a mandatory notification obligation, and potential suspension of its data processing activities. The gap between what the company assumed and what Uzbek data protection law actually requires can be costly and time-consuming to close.

Data protection in Uzbekistan is governed by a dedicated body of privacy and personal data legislation that imposes registration obligations on data controllers. Requires localisation of personal data belonging to Uzbek citizens. Additionally, establishes a consent mechanism for processing sensitive categories of information. Foreign businesses must complete registration with the authorised state body before processing commences. Non-compliance can result in suspension of data operations and administrative sanctions.

This page explains the regulatory system, the key procedural steps for international businesses, common pitfalls encountered by foreign operators, and the cross-border considerations that arise when Uzbek data flows intersect with EU and Russian requirements.

The regulatory system governing personal data in Uzbekistan

Uzbekistan's personal data regime is built on a dedicated legislative foundation within its broader civil and commercial law system. The core obligations are established through data protection legislation and supplemented by implementing regulations issued by the authorised state body. Unlike many civil law jurisdictions in Central Asia, Uzbekistan has developed a standalone regulatory structure rather than embedding privacy rules within general civil procedure rules or commercial legislation.

The authorised supervisory body – the Agentlik (Agency for Personal Data Protection, the Uzbek DPA) – was established to oversee compliance. Maintain a register of data controllers and data processors, investigate complaints. Additionally, issue guidance on lawful processing. This institutional structure gives Uzbekistan one of the more developed personal data enforcement environments among CIS jurisdictions.

Personal data legislation in Uzbekistan classifies data by sensitivity. Ordinary personal data, special categories such as health and biometric information, and data relating to minors are each subject to distinct processing conditions. The law defines a data controller as any entity that determines the purposes and means of processing, and a data processor as any entity that processes personal data on behalf of a controller. Both categories face registration and operational obligations.

The data localisation requirement is one of the most operationally significant rules. Personal data relating to Uzbek citizens must be stored and processed on servers physically located within Uzbekistan. Cross-border data transfer to servers in the EU, Russia, or elsewhere is permitted only after the localisation obligation has been satisfied and subject to additional conditions. In practice, businesses that attempt to run Uzbek customer data through centralised offshore infrastructure without establishing local storage first face an immediate compliance deficiency.

Practitioners in Uzbekistan note that the DPA has increased its supervisory activity in recent years. International companies operating digital platforms, e-commerce services, fintech products, and human resources systems are among the categories most frequently reviewed. Failure to register or to establish adequate localisation infrastructure before commencing operations is the most common reason for enforcement inquiries.

Key instruments and procedures for compliance

Compliance under Uzbek data protection law involves several sequential procedures. Each carries its own timeline, documentary requirements, and risk of delay if handled incorrectly.

Step 1 – Determine controller or processor status. The first step is to establish whether the foreign business qualifies as a data controller, a data processor, or both under Uzbek legislation. This classification determines the scope of obligations. A company collecting data directly from Uzbek users is a controller. A company processing data on behalf of a local business is a processor. Many international businesses occupy both roles simultaneously.

Step 2 – Register with the DPA. Data controllers must submit a registration application to the Agency for Personal Data Protection before commencing processing activities. The application requires a description of the categories of personal data to be processed, the purposes of processing, the data subjects affected. The legal basis for processing, the security measures in place. Additionally, the identity of any processors engaged. Registration is not instantaneous. Processing the application typically takes several weeks, and incomplete submissions are returned for correction, which resets the timeline. The registration must be renewed when processing activities materially change.

Step 3 – Establish lawful processing grounds. Uzbek data protection legislation recognises several lawful bases for processing personal data. The most commonly relied upon is the consent mechanism – explicit, informed, freely given, and documented consent from the data subject. Other lawful bases include performance of a contract, compliance with a legal obligation, and the legitimate interests of the controller, subject to conditions. For sensitive categories, explicit consent is the primary available basis. A non-obvious risk arises here: consent documents drafted to EU GDPR standards are not automatically sufficient under Uzbek law, because the formal requirements for consent language, medium, and documentation differ.

Step 4 – Implement localisation infrastructure. Before processing begins, the business must establish that personal data relating to Uzbek citizens is stored on servers located within Uzbekistan. This requires either entering into an agreement with a local hosting provider or deploying physical infrastructure within Uzbekistan. The localisation obligation applies even if the business is incorporated outside Uzbekistan and serves Uzbek users remotely. Many international businesses underestimate the lead time required to identify a compliant local host, negotiate terms, and migrate data.

Step 5 – Appoint a responsible person. Uzbek legislation requires that organisations engaged in processing designate a responsible person for personal data protection. This individual serves as the internal compliance contact and the point of contact with the DPA. The responsible person does not need to be a Uzbek national, but must be accessible to the authority and capable of responding to regulatory inquiries in a timely manner.

Step 6 – Implement security measures and internal documentation. Data protection legislation requires that controllers and processors implement technical and organisational security measures proportionate to the sensitivity and volume of data processed. Internal documentation must include a personal data processing policy, records of processing activities, consent documentation, and data-sharing agreements with processors. Audits by the DPA can and do request this documentation as a primary step.

For a tailored strategy on data protection compliance in Uzbekistan, reach out to info@ferrazwhitmore.com.

International businesses that also operate AI-driven data processing tools should review the emerging obligations under AI law in Uzbekistan, which intersects with personal data obligations in significant ways.

Practical pitfalls for international operators

The gap between formal compliance and effective compliance in Uzbekistan is wider than many international businesses anticipate. Several categories of error arise consistently.

Assuming GDPR compliance is sufficient. This is the most damaging misconception. GDPR compliance establishes a strong baseline, but Uzbek data protection legislation has distinct requirements for registration, localisation, consent language, and documentation that the GDPR does not address in the same way. A company that relies on its EU data protection officer and EU-standard privacy policy without adapting them to the Uzbek system will have incomplete compliance from the outset.

Underestimating the localisation obligation. Some companies interpret the localisation rule narrowly, assuming it applies only to databases containing large volumes of consumer data. In practice, the rule applies to any personal data of Uzbek citizens, including employee data, vendor contact information, and business-to-business contract records that contain individual names and contact details. Identifying all data flows touching Uzbek citizens is a necessary precondition to localisation compliance.

Treating processor agreements as boilerplate. Agreements with local hosting providers, HR platforms, customer relationship management vendors, and other processors must comply with Uzbek data protection legislation. Generic EU-style data processing agreements do not satisfy the local requirements. The responsible person must ensure that all processor agreements are reviewed and adapted.

Ignoring the notification obligation. Uzbek legislation requires notification to the DPA in the event of a personal data breach. The notification timeline is short. Businesses that lack internal incident response procedures – or that route all incidents through a headquarters team unfamiliar with Uzbek obligations – frequently miss the notification window. Missing the notification deadline is itself a compliance violation that can increase the severity of the regulatory response.

Failing to update registration after operational changes. The DPA registration reflects the processing activities described at the time of application. If the business expands its data processing – adding new categories of data, new purposes, or new processors – the registration must be updated. Many businesses treat registration as a one-off exercise and fail to maintain it. This leaves them technically non-compliant for all activities beyond the original scope.

Cross-border data transfer: EU and Russia dimensions

Uzbekistan's position as a major trade and investment corridor between Europe, Russia, and Asia means that cross-border data transfer questions arise in almost every international business context. The legal conditions for transferring personal data out of Uzbekistan are distinct from EU rules and from Russian data localisation requirements. Additionally. The three regimes must be managed in parallel for businesses operating across all three markets.

Transfers to EU-based entities. Uzbekistan does not have an adequacy decision from the European Commission, and the EU does not have an adequacy finding for Uzbekistan. This means that cross-border data transfer from Uzbekistan to the EU requires a separate legal basis under Uzbek law. typically contractual safeguards or explicit consent. in addition to whatever mechanism is used under GDPR for the reverse flow. Businesses that have configured their data architecture for GDPR-compliant inbound transfers must also configure it for Uzbek-compliant outbound transfers. The two analyses are not symmetrical.

Transfers to Russia. Russia has its own personal data localisation legislation, which imposes overlapping requirements on businesses that process Russian citizens' data. For a detailed comparison of the Russian regime, see our analysis of data protection in Russia. Companies operating in both markets face a dual localisation obligation: separate databases or storage infrastructure may be required in each jurisdiction. Cloud-based unified data architectures frequently fail to satisfy both regimes simultaneously without structural adjustment.

Regional treaty context. Uzbekistan is a member of the Commonwealth of Independent States and participates in several regional frameworks that touch on data exchange. These frameworks can affect the conditions under which government data, law enforcement data, and financial data are transferred between member states. Private sector data transfers are not directly governed by these frameworks. However, businesses operating in regulated sectors. banking, telecommunications. Healthcare. must verify that their data transfer arrangements are consistent with sector-specific rules as well as general data protection legislation.

Contractual mechanisms for cross-border transfer. Where a business needs to transfer personal data of Uzbek citizens to a foreign entity. a parent company. A service provider. Alternatively, a partner. Uzbek legislation requires that the transfer be supported by adequate contractual safeguards and that the transfer not undermine the rights of data subjects. Drafting transfer agreements that satisfy this standard requires familiarity with both the Uzbek legislative requirements and the legal system of the receiving jurisdiction.

A detailed breakdown of company formation and operational structure options in Uzbekistan is available in our guide to company formation in Uzbekistan, which addresses how the choice of legal vehicle affects data protection obligations.

To discuss how cross-border data transfer rules apply to your operations in Uzbekistan, contact us at info@ferrazwhitmore.com.

Self-assessment checklist before commencing operations

A data protection compliance programme in Uzbekistan is appropriate if the following conditions are present:

  • The business collects, stores, or processes personal data of Uzbek citizens, including employee data, customer data, or vendor contact data.
  • The business operates a digital platform, application, or service accessible to users located in Uzbekistan.
  • The business has entered into agreements with Uzbek-based processors or sub-processors that handle personal data.
  • The business transfers personal data from Uzbekistan to servers or entities located outside the country.
  • The business operates in a regulated sector – financial services, telecommunications, healthcare, or e-commerce – where sector-specific data rules overlay the general legislative regime.

Before commencing or continuing data processing in Uzbekistan, verify the following:

  • Has the business submitted its DPA registration application and received confirmation of registration before processing commenced?
  • Are personal data of Uzbek citizens stored on servers physically located within Uzbekistan?
  • Has a responsible person been designated and communicated to the DPA?
  • Are all consent mechanisms compliant with Uzbek legislative requirements, not merely GDPR-standard consent forms?
  • Do all agreements with data processors include the provisions required by Uzbek data protection legislation?
  • Is there an internal incident response procedure that identifies the Uzbek notification obligation and its timeline?
  • Has the business mapped all cross-border data flows and assessed the legal basis for each transfer under Uzbek law?

Frequently asked questions

Q: How long does DPA registration take in Uzbekistan, and what happens if a business starts processing before registration is complete?

A: The registration process with the Agency for Personal Data Protection typically takes several weeks from the date of a complete application. Incomplete submissions are returned, which resets the timeline. Processing personal data before registration is finalised constitutes a violation of data protection legislation and can result in enforcement action, including a mandatory halt to processing. International businesses should build registration lead time into their market entry schedule rather than commencing operations and registering in parallel. Engaging a lawyer in Uzbekistan with experience in regulatory filings significantly reduces the risk of application deficiencies.

Q: Does Uzbekistan's data localisation requirement apply to employee data as well as customer data?

A: Yes. The localisation obligation under Uzbek data protection legislation applies to all personal data relating to Uzbek citizens, regardless of the context in which it was collected. This includes employee records, contractor data, and business contact information where individual names and identifiers are present. Businesses that process employee data through a centralised human resources system located outside Uzbekistan must either migrate that data to a local server or establish a mirrored local storage arrangement.

Q: Is a GDPR-compliant privacy policy sufficient for operating in Uzbekistan?

A: No. A GDPR-compliant privacy policy addresses EU requirements but does not satisfy the distinct obligations imposed by Uzbek data protection legislation. The consent mechanism requirements, the language and structure of the privacy notice, the registration references, and the data subject rights disclosure must all be adapted to the Uzbek legislative standard. A law firm in Uzbekistan with cross-border data protection experience can review existing GDPR documentation and identify the specific adaptations required rather than drafting entirely new instruments from scratch.

About Ferraz & Whitmore

Ferraz & Whitmore is an international law firm based in Lisbon, advising business clients across 46 jurisdictions. Our data protection practice supports international companies entering and operating in Uzbekistan and across CIS markets, covering DPA registration, localisation compliance, cross-border data transfer structuring, consent mechanism design, and regulatory response. As a law firm in Uzbekistan and across 15 practice areas, we combine Portuguese civil law expertise with English common law tradition to deliver practical, results-oriented advice for cross-border data operations. Our practitioners have advised on data protection matters across both civil law and common law systems, and our CIS practice gives us direct familiarity with the Uzbek regulatory environment. The firm's Lisbon base provides direct access to EU regulatory frameworks, enabling us to coordinate Uzbek and GDPR obligations in a single engagement. To receive an expert assessment of your data protection position in Uzbekistan, contact us at info@ferrazwhitmore.com.

Disclaimer: This publication is provided for informational purposes only and does not constitute legal advice. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. Ferraz & Whitmore assumes no liability for actions taken or not taken based on the contents of this material. For advice regarding your particular situation, please contact info@ferrazwhitmore.com.