Skip to content

Evidence request lists

Azerbaijan Law on Personal Data (2010)

Evidence request list. 15 controls, 15 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Section I: General Provisions

AZ-DPA-1
Article 1 - Purpose of the Law

Defines the purpose and scope of the Law on Personal Data: regulating the collection, processing and protection of personal data in Azerbaijan.

Artefacts an auditor will ask for
  • Determination that the Law applies
  • Scope mapping
Where this commonly fails
  • Scope not assessed
AZ-DPA-2
Article 2 - Basic Concepts

Sets out the definitions used in the Law (personal data, data subject, owner/operator, information system, etc.).

Artefacts an auditor will ask for
  • Use of statutory definitions in policies
Where this commonly fails
  • Terms used inconsistently with the Law
AZ-DPA-3
Article 3 - Legislation in the field of personal data

The legal framework comprises the Constitution, this Law, international treaties and subordinate normative acts.

Artefacts an auditor will ask for
  • Mapping to applicable legislation
Where this commonly fails
  • Subordinate acts not considered
AZ-DPA-4
Article 4 - Principles of collection and processing

Personal data must be collected and processed lawfully, fairly, for defined purposes, accurately and proportionately.

Artefacts an auditor will ask for
  • Evidence of lawful, purpose-limited processing
  • Accuracy and proportionality controls
Where this commonly fails
  • Processing without defined purpose
  • Excessive collection

Section II: Categories and Legal Regime of Personal Data

AZ-DPA-5
Article 5 - Legal regime and categories of personal data

Establishes categories of personal data (including special/sensitive categories) and their differentiated legal regime and protection.

Artefacts an auditor will ask for
  • Categorisation of personal data
  • Heightened protection for special categories
Where this commonly fails
  • Special categories not protected
  • No categorisation
AZ-DPA-6
Article 6 - State regulation in personal data protection

Provides for the state register of information systems and the role of the authorised state body (regulator) in the field.

Artefacts an auditor will ask for
  • Registration in the state register where required
  • Engagement with the authorised body
Where this commonly fails
  • Information system not registered
  • No regulator engagement
AZ-DPA-7
Article 7 - Rights of the data subject

Data subjects have rights to information, access, rectification, blocking and deletion of their personal data.

Artefacts an auditor will ask for
  • Process to handle access/rectification/deletion requests
  • Records of requests and responses
Where this commonly fails
  • Requests not actioned
  • No rights process

Section III: Collection and Processing of Personal Data

AZ-DPA-10
Article 10 - Responsibilities of the operator

The owner/operator is responsible for lawful processing, data quality, security and respecting data-subject rights.

Artefacts an auditor will ask for
  • Operator accountability arrangements
  • Evidence of obligations met
Where this commonly fails
  • Operator responsibilities undefined
AZ-DPA-11
Article 11 - Characteristics of personal data information systems

Sets requirements for the creation and operation of personal data information systems.

Artefacts an auditor will ask for
  • Information system documentation
  • Compliance of the system with requirements
Where this commonly fails
  • System not compliant with requirements
AZ-DPA-8
Article 8 - Consent to collection and processing

Personal data is collected and processed on the basis of the data subject's consent, save for statutory exceptions.

Artefacts an auditor will ask for
  • Consent records
  • Withdrawal mechanism
Where this commonly fails
  • Processing without consent or lawful basis
AZ-DPA-9
Article 9 - Processing without consent

Specifies the cases in which personal data may be processed without the data subject's consent (legal obligation, vital interests, etc.).

Artefacts an auditor will ask for
  • Documented basis for consent-exempt processing
Where this commonly fails
  • Consent exemption claimed without basis

Section IV: Cross-Border Transfer and Protection

AZ-DPA-12
Article 13 - Cross-border transfer

Cross-border transfer of personal data is permitted subject to adequate protection in the receiving state and statutory conditions.

Artefacts an auditor will ask for
  • Assessment of receiving-state protection
  • Transfer safeguards
Where this commonly fails
  • Transfer without adequacy/safeguards
AZ-DPA-13
Article 14 - Security requirements

The operator must take organisational and technical measures to protect personal data from unlawful access, loss or alteration.

Artefacts an auditor will ask for
  • Technical and organisational security measures
  • Access controls and protection of data
Where this commonly fails
  • Inadequate security measures
  • Data not protected

Section V: Liability and Final Provisions

AZ-DPA-14
Article 16 - Liability for violations

Provides for liability (administrative, civil and criminal) for violations of the Law.

Artefacts an auditor will ask for
  • Compliance monitoring against the Law
  • Remediation of violations
Where this commonly fails
  • Repeated violations
  • No compliance monitoring
AZ-DPA-15
Article 17 - Dispute resolution

Disputes concerning personal data are resolved administratively (by the authorised body) or judicially.

Artefacts an auditor will ask for
  • Process to handle disputes/complaints
  • Records of dispute outcomes
Where this commonly fails
  • No dispute/complaint process
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Azerbaijan Law on Personal Data (2010) framework page.