The company complies with a requirement that no longer exists
Monthly spending on local hosting and data mirroring that localization no longer requires, plus internal policies and agreements with counterparties describing a version of the law that is no longer in force.
Typical mistake: After the tightening of 2021, businesses moved their infrastructure to Uzbekistan en masse and registered every database in the State Register. Since 27 March 2026 mandatory storage covers only the list in part two of Article 27-1.
The law now allows storage abroad, but there is nothing to prove the right with
The company relies on a ground whose fulfilment it cannot demonstrate to an inspector, while a breach of the personal data storage requirements constitutes an administrative offence.
Typical mistake: They read the headline “localization has been relaxed” and leave the data in a foreign cloud. Yet all three conditions in part three of Article 27-1 are referential, and the list of states with adequate protection is approved by the Cabinet of Ministers.
Everyone is rolling out biometrics, and the relaxation did not touch it
Biometric data must be stored in Uzbekistan and the database is subject to registration. Liability is established by Article 46-2 of the Code on Administrative Liability and Article 141-2 of the Criminal Code.
Typical mistake: They fail to notice that ordinary things generate biometrics: face login, a fingerprint on an access control system, video analytics, HR turnstiles, remote customer identification. All of it often lives in a foreign cloud together with the rest of the HR system.
It is unclear which databases exactly have to be registered
Excessive registration means voluntarily handing the regulator a map of your data. Under-registration is a direct breach. The cost of an error runs both ways.
Typical mistake: The new wording of part one of Article 20 tied the registration duty to the list in part two of Article 27-1. Then the qualification work begins: does a profile photo count as biometrics, does a call centre recording fall within the list.
Risk is measured by the size of the fine
For a banking app, a marketplace or a SaaS the real sanction is not the fine but restriction of access to the service: revenue stops for the whole period of remedying the breach.
Typical mistake: The lawyer brings a fine figure and the matter is closed: “cheaper to pay”. The calculation leaves out both the access restriction and the fact that liability under Article 141-2 of the Criminal Code is personal.
HR files are a personal data database, and the consent in the employment contract is empty
Any labour dispute turns into a second front: a personal data complaint in which the employer has neither a policy, nor an order appointing a responsible person, nor valid consent.
Typical mistake: They collect passport scans, medical certificates and biometrics from turnstiles, run all of it in a foreign HR system, and record consent as a single line in the employment contract — with no processing purpose and no list of data.