Price depends on the scope of work

Personal data and localization in Uzbekistan

We work out which of your databases must be stored in Uzbekistan after the 2026 reform, which ones may be kept abroad, and what evidence supports that.

  • Localization remains mandatory for biometric and genetic data — nothing was relaxed there
  • Registering a database in the State Register is free and takes 5 working days
  • Restriction of access to a service is a measure that has actually been applied
In brief

Can personal data be stored outside Uzbekistan in 2026?

Partly. Law No. ZRU-1125 of 26 March 2026 restated Article 27-1 of the Law of the Republic of Uzbekistan “On Personal Data”: a closed list of categories is subject to mandatory storage on the territory of Uzbekistan, among them the biometric and genetic data of individuals. Other personal data may be stored and processed outside the country if one of the three conditions set out in part three of Article 27-1 is met. At the same time, the list of foreign states ensuring adequate protection is established by the Cabinet of Ministers of the Republic of Uzbekistan, so this ground can be relied on only after that list has been approved.

Where money is lost

What usually goes wrong

These are not abstract risks but the scenarios that break deals and turn decisions of state authorities against you.

The company complies with a requirement that no longer exists

Monthly spending on local hosting and data mirroring that localization no longer requires, plus internal policies and agreements with counterparties describing a version of the law that is no longer in force.

Typical mistake: After the tightening of 2021, businesses moved their infrastructure to Uzbekistan en masse and registered every database in the State Register. Since 27 March 2026 mandatory storage covers only the list in part two of Article 27-1.

The law now allows storage abroad, but there is nothing to prove the right with

The company relies on a ground whose fulfilment it cannot demonstrate to an inspector, while a breach of the personal data storage requirements constitutes an administrative offence.

Typical mistake: They read the headline “localization has been relaxed” and leave the data in a foreign cloud. Yet all three conditions in part three of Article 27-1 are referential, and the list of states with adequate protection is approved by the Cabinet of Ministers.

Everyone is rolling out biometrics, and the relaxation did not touch it

Biometric data must be stored in Uzbekistan and the database is subject to registration. Liability is established by Article 46-2 of the Code on Administrative Liability and Article 141-2 of the Criminal Code.

Typical mistake: They fail to notice that ordinary things generate biometrics: face login, a fingerprint on an access control system, video analytics, HR turnstiles, remote customer identification. All of it often lives in a foreign cloud together with the rest of the HR system.

It is unclear which databases exactly have to be registered

Excessive registration means voluntarily handing the regulator a map of your data. Under-registration is a direct breach. The cost of an error runs both ways.

Typical mistake: The new wording of part one of Article 20 tied the registration duty to the list in part two of Article 27-1. Then the qualification work begins: does a profile photo count as biometrics, does a call centre recording fall within the list.

Risk is measured by the size of the fine

For a banking app, a marketplace or a SaaS the real sanction is not the fine but restriction of access to the service: revenue stops for the whole period of remedying the breach.

Typical mistake: The lawyer brings a fine figure and the matter is closed: “cheaper to pay”. The calculation leaves out both the access restriction and the fact that liability under Article 141-2 of the Criminal Code is personal.

HR files are a personal data database, and the consent in the employment contract is empty

Any labour dispute turns into a second front: a personal data complaint in which the employer has neither a policy, nor an order appointing a responsible person, nor valid consent.

Typical mistake: They collect passport scans, medical certificates and biometrics from turnstiles, run all of it in a foreign HR system, and record consent as a single line in the employment contract — with no processing purpose and no list of data.

Result

What you get

Data processing audit

An inventory: what data you collect, where it physically sits, who has access to it and which contractors it passes through.

Localization map

We split the data into what must be stored in Uzbekistan and what may be taken abroad, stating the ground under part three of Article 27-1.

Operator document set

Personal data processing and protection policy, order appointing the responsible person, internal processing procedure, consent forms tailored to specific purposes.

Registration of databases in the State Register

We determine which databases are subject to registration under the new wording of Article 20 and carry it out — the service is free and takes five working days.

Contracts with contractors

Data processing terms for cloud providers, call centres, HR and marketing services through which data leaves your perimeter.

Readiness for an inspection

A set of documents to produce on request and a clear answer to the question of on what ground the data sits where it sits.

How we work

How it works

  1. 011–2 weeks

    Inventory

    We look at systems and data flows, not just the website: HR, CRM, call centre, video surveillance, analytics.

  2. 021 week

    Legal qualification

    We assign every category either to the mandatory localization list or to what may be taken abroad, and record the ground.

  3. 032–3 weeks

    Documents and settings

    We prepare the operator set, correct consents and contractor agreements, and set tasks for moving what must be stored in Uzbekistan.

  4. 045 working days for registration

    Registration and support

    We register the databases subject to registration and support you during regulator enquiries.

Legal basis

What the law says

Every point comes with a link to the primary source so that you can check it yourself.

  • The base act is the Law of the Republic of Uzbekistan “On Personal Data” No. ZRU-547 of 2 July 2019.

    lex.uz — ZRU-547
  • Law No. ZRU-1125 of 26 March 2026 amended the Law “On Personal Data”, including restating Article 27-1 in a new wording.

    lex.uz — ZRU-1125
  • The categories listed in part two of Article 27-1, including the biometric and genetic data of individuals, are subject to mandatory storage on the territory of the Republic of Uzbekistan.

    lex.uz — Article 27-1
  • Personal data not listed in part two of Article 27-1 may be stored and processed outside Uzbekistan if one of the three conditions in part three of the same article is met.

    lex.uz — Article 27-1
  • The list of foreign states ensuring adequate protection of personal data is established by the Cabinet of Ministers of the Republic of Uzbekistan (part 4 of Article 27-1).

    lex.uz — Article 27-1
  • The duty to register personal data databases in the State Register is tied to the list of data subject to mandatory storage in Uzbekistan (new wording of part one of Article 20).

    lex.uz — Article 20
  • State regulation in the field of personal data is carried out by the Cabinet of Ministers and the authorized state body; maintaining the State Register of personal data databases falls within the powers of the authorized body (Articles 6 and 8 of ZRU-547).

    lex.uz — Articles 6, 8 of ZRU-547
  • The procedure for registering personal data databases is established by Cabinet of Ministers Resolution No. 71 of 8 February 2020: registration is free and the review period is five working days.

    lex.uz — CM Resolution No. 71
  • The Law does not apply to the processing of personal data by an individual solely for personal and household purposes (Article 3 of ZRU-547 as worded by ZRU-1125).

    lex.uz — Article 3
  • Liability for breaching personal data legislation is established by Article 46-2 of the Code on Administrative Liability and Article 141-2 of the Criminal Code.

    lex.uz — Criminal Code
Choosing an option

What has to sit in Uzbekistan and what may be taken abroad

Data categoryStorageWhat is required of the operator
Biometric and genetic dataOnly on the territory of UzbekistanLocal storage and registration of the database in the State Register
Other categories from part two of Article 27-1Only on the territory of UzbekistanThe same: localization and registration
All other personal dataStorage and processing abroad are permittedA documented ground under part three of Article 27-1
Data processed by an individual for personal purposesThe Law does not applyNo requirements

The practical conclusion: inventory and qualification of categories come first, and only then decisions about infrastructure. Moving data before qualification is either wasted spending or a breach.

Next step

Tell us about your case

We will go through your situation, tell you what can realistically be done and in what timeframe, and name the price — once we understand the scope. Without that, any figure would be invented.

Консультация по задаче — бесплатно. Стоимость работы называем после того, как поймём объём.

Questions

Frequently asked questions

Is it mandatory to store clients' personal data in Uzbekistan?
Not all of it. After the amendments made by Law No. ZRU-1125 of 26 March 2026, mandatory storage on the territory of Uzbekistan applies to a closed list of categories from part two of Article 27-1, including biometric and genetic data. Other data may be stored and processed abroad if one of the three conditions in part three of the same article is met.
What counts as biometric data in practice?
Biometrics are generated by face login, a fingerprint on an access control system, video analytics, HR turnstiles and remote customer identification. There was no relaxation for this category: it is stored in Uzbekistan and the database is subject to registration.
Does a personal data database have to be registered?
The registration duty is tied to the list of data subject to mandatory storage in Uzbekistan. So the question is decided by the composition of the data in a system, not by the system's name. Registration itself is free and the review period is five working days under Cabinet of Ministers Resolution No. 71.
Can a foreign cloud be used?
For data outside the mandatory localization list — yes, where there is a ground under part three of Article 27-1. One of the grounds relies on the list of states with adequate protection, which is established by the Cabinet of Ministers, so the ground has to be chosen and documented in advance, not after an enquiry from the regulator.
Is consent in the employment contract enough?
As a rule, no. Consent must be tied to a specific processing purpose and to a list of data, and the employer must additionally have a processing policy, an order appointing a responsible person and an internal procedure. HR files are a personal data database with all the duties that follow from that.
What is the liability for a breach?
Liability is established by Article 46-2 of the Code on Administrative Liability and Article 141-2 of the Criminal Code. For online services the practically more significant measure turns out to be restriction of access to the resource — it has been applied to large international platforms with reference to Article 27-1.
Where should compliance work start?
With an inventory: what data is collected, where it physically sits, which contractors it passes through. Without that map you can determine neither what is subject to localization nor which databases to register. Infrastructure decisions are taken after qualification, not before it.
What has changed for companies that have already moved data to Uzbekistan?
Part of the spending may turn out to be excessive: mandatory storage now covers a list of categories rather than all personal data indiscriminately. At the same time, internal policies and contracts with counterparties written for the previous wording need updating — they describe the requirement in a form that is no longer in force.
Why this can be entrusted to us

Verifiable facts about us

There are no testimonials or case studies here: they cannot be verified. Only what you can confirm yourself.

  • Every rule is cited with a link to lex.uz, including Law No. ZRU-1125 of 26 March 2026 itself, which rewrote Article 27-1.
  • We do not quote specific fine amounts under Article 46-2 of the Code on Administrative Liability and Article 141-2 of the Criminal Code: we could not confirm the wording currently in force against the primary source, and on this topic a figure taken from a retelling costs far too much.
  • Pactum is a legal services platform for Uzbekistan: 5042 services in the catalogue, and a request goes to a lawyer specialising in the relevant area.

This material is for reference only and is not legal advice on your specific situation. Rules and tariffs change — check the current wording via the links to the primary sources above. To have your case assessed, send a request.