Wednesday, 05, August, 2026

Uzbekistan has approved a list of countries where personal data is protected at a level equivalent to that guaranteed domestically, under a Cabinet of Ministers resolution dated July 29.

The list includes 49 countries and territories, among them the United States, the United Kingdom, Germany, France, Italy, Japan, South Korea, Canada, Singapore, Russia, Switzerland, New Zealand, and a number of European Union member states.

Under the resolution, personal data and depersonalized data may be transferred to listed countries through information systems established on the basis of international agreements without the need for additional authorization or notification of the relevant government agency — provided that appropriate measures are taken to prevent data leaks.

Transfers to countries not on the list will be permitted only if the legal, organizational and technical requirements set by the authorized state body are met.

The resolution also deploys breach-notification requirements for cross-border data transfers: if a leak is detected, the database operator must notify the relevant government agency within 24 hours and submit a detailed report on the causes of the incident and the remedial measures taken within 72 hours.

The Migration and Personalization Department under the Interior Ministry has been designated responsible for preparing proposals to add or remove countries from the list.

The Foreign Ministry, meanwhile, has been directed to draw up proposals within three months for Uzbekistan's accession to the 1981 Strasbourg Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, and to pursue Uzbekistan's inclusion on other countries' lists of states with adequate data protection standards.

The move builds on an October 2022 government resolution that overhauled Uzbekistan's personal data protection framework, establishing security classifications for data processing, introducing a threat taxonomy, and creating a four-tier data protection system. Operators were also required to implement specific organizational and technical measures to guard against unauthorized access and unlawful use of data.

 

 

Stay up to date with all the latest news:

Telegram

Facebook

Latest in National