Legal UpdateRegulatory

Personal Data Localisation in Uzbekistan: What Businesses Need to Know

Uzbekistan requires personal data of its citizens that is processed using information technologies to be stored on servers located in the country. The rule continues to affect foreign businesses that rely on global cloud and SaaS platforms.

Key takeaways

  • Personal data of Uzbek citizens processed electronically must be collected, systematised and stored in databases physically located in Uzbekistan.
  • Such databases must be registered in the state register of personal data databases.
  • The rule applies to foreign companies, including online services, that process data of Uzbek citizens — not only to local entities.
  • Cross-border transfer is still possible, but only on top of compliant local storage.

What is the rule

The Law of the Republic of Uzbekistan «On Personal Data» sets the general framework for processing personal data: lawful grounds, consent, data subject rights, security measures and cross-border transfers. Its localisation requirement, contained in Article 27¹ and in force since 2021, obliges owners and operators that collect and process personal data of citizens of Uzbekistan using information technologies, including via the internet, to ensure that the collection, systematisation and storage of such data take place in databases physically located on the territory of Uzbekistan.

These databases must also be registered in the state register of personal data databases maintained by the authorised state body. The registration and localisation obligations are separate: a company may be in breach of either.

Localisation does not prohibit cross-border transfer as such. Data may be transferred abroad in accordance with the Law — for example, to countries ensuring adequate protection of data subjects' rights, or on the basis of the data subject's consent — but the primary database containing the data of Uzbek citizens must be located in Uzbekistan.

Who is affected

The requirement applies to any owner or operator processing personal data of Uzbek citizens using information technologies, regardless of where the company itself is incorporated. In practice, it is relevant for:

  • local subsidiaries and branches of international groups using group-wide HR, CRM or ERP systems hosted abroad;
  • banks, payment and fintech providers, insurers and telecom operators;
  • e-commerce platforms, marketplaces, delivery and ride-hailing services;
  • foreign online services and apps with users in Uzbekistan;
  • employers processing employee data in global cloud solutions.

Implications for business

Non-compliance may lead to administrative liability for the company and its officers. In practice, the authorities have also restricted access in Uzbekistan to online resources that did not comply with the localisation requirement. Beyond enforcement, localisation affects commercial negotiations: banks and large corporate customers increasingly ask suppliers to confirm compliance, and data protection terms are becoming a standard part of due diligence in M&A transactions.

The main practical challenge lies in architecture. Multinational groups typically operate centralised systems, and moving a full instance to Uzbekistan can be costly. Common solutions include hosting a local primary database in an Uzbek data centre with replication abroad, or using local cloud providers for the data of Uzbek citizens while keeping global systems for other jurisdictions. Each option has to be assessed against both the Law and the group's own security and data protection policies.

LEXGLOBAL recommendations

  1. Map the personal data you process: categories, data subjects, systems, hosting locations and data flows.
  2. Identify all databases that contain personal data of Uzbek citizens and confirm that they are physically located in Uzbekistan.
  3. Register the databases in the state register and keep the registration details up to date.
  4. Review the legal grounds for cross-border transfers and update consent forms and privacy notices accordingly.
  5. Update contracts with hosting, cloud and IT service providers to reflect localisation and security obligations.
  6. Adopt or update an internal personal data policy and appoint a person responsible for data protection.
  7. Reassess compliance whenever you launch a new product, change a hosting provider or migrate systems, and at least once a year.

LEXGLOBAL assists international and local companies with personal data compliance audits, database registration and the structuring of compliant data flows in Uzbekistan.

Official source: Law of the Republic of Uzbekistan «On Personal Data» — lex.uz

Speak to a lawyer

Get a clear view of your position and the next steps.

Request consultation