Azerbaijan Law on Personal Data (2010)
Evidence request list. 15 controls, 15 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Section I: General Provisions
Defines the purpose and scope of the Law on Personal Data: regulating the collection, processing and protection of personal data in Azerbaijan.
- Determination that the Law applies
- Scope mapping
- Scope not assessed
Sets out the definitions used in the Law (personal data, data subject, owner/operator, information system, etc.).
- Use of statutory definitions in policies
- Terms used inconsistently with the Law
The legal framework comprises the Constitution, this Law, international treaties and subordinate normative acts.
- Mapping to applicable legislation
- Subordinate acts not considered
Personal data must be collected and processed lawfully, fairly, for defined purposes, accurately and proportionately.
- Evidence of lawful, purpose-limited processing
- Accuracy and proportionality controls
- Processing without defined purpose
- Excessive collection
Section II: Categories and Legal Regime of Personal Data
Establishes categories of personal data (including special/sensitive categories) and their differentiated legal regime and protection.
- Categorisation of personal data
- Heightened protection for special categories
- Special categories not protected
- No categorisation
Provides for the state register of information systems and the role of the authorised state body (regulator) in the field.
- Registration in the state register where required
- Engagement with the authorised body
- Information system not registered
- No regulator engagement
Data subjects have rights to information, access, rectification, blocking and deletion of their personal data.
- Process to handle access/rectification/deletion requests
- Records of requests and responses
- Requests not actioned
- No rights process
Section III: Collection and Processing of Personal Data
The owner/operator is responsible for lawful processing, data quality, security and respecting data-subject rights.
- Operator accountability arrangements
- Evidence of obligations met
- Operator responsibilities undefined
Sets requirements for the creation and operation of personal data information systems.
- Information system documentation
- Compliance of the system with requirements
- System not compliant with requirements
Personal data is collected and processed on the basis of the data subject's consent, save for statutory exceptions.
- Consent records
- Withdrawal mechanism
- Processing without consent or lawful basis
Specifies the cases in which personal data may be processed without the data subject's consent (legal obligation, vital interests, etc.).
- Documented basis for consent-exempt processing
- Consent exemption claimed without basis
Section IV: Cross-Border Transfer and Protection
Cross-border transfer of personal data is permitted subject to adequate protection in the receiving state and statutory conditions.
- Assessment of receiving-state protection
- Transfer safeguards
- Transfer without adequacy/safeguards
The operator must take organisational and technical measures to protect personal data from unlawful access, loss or alteration.
- Technical and organisational security measures
- Access controls and protection of data
- Inadequate security measures
- Data not protected
Section V: Liability and Final Provisions
Provides for liability (administrative, civil and criminal) for violations of the Law.
- Compliance monitoring against the Law
- Remediation of violations
- Repeated violations
- No compliance monitoring
Disputes concerning personal data are resolved administratively (by the authorised body) or judicially.
- Process to handle disputes/complaints
- Records of dispute outcomes
- No dispute/complaint process
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Azerbaijan Law on Personal Data (2010) framework page.