Skip to content

Evidence request lists

Uzbekistan Law on Personal Data (No. ZRU-547)

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Consent and Lawful Processing

UZB-DPL-02
Consent of the Data Subject

Personal data may only be processed with the consent of the data subject unless an exception applies. Consent must be free, specific, informed and unambiguous, and may be revoked at any time.

Artefacts an auditor will ask for
  • Consent capture records
  • Consent forms with required disclosures
  • Withdrawal mechanism logs
  • Lawful basis register per processing activity
Where this commonly fails
  • Pre ticked consent boxes used
  • No mechanism to withdraw consent
  • Consent bundled with terms of service
  • Withdrawal not propagated through systems
UZB-DPL-05
Purpose Limitation Principle

Personal data must be processed for specific, predetermined and legitimate purposes. Processing for purposes incompatible with the original purposes is prohibited unless a new lawful basis is established.

Artefacts an auditor will ask for
  • Purpose declarations per dataset
  • Compatibility assessments for secondary use
  • Privacy notices specifying purposes
  • Records of purpose changes with renewed consent
Where this commonly fails
  • Generic purposes such as commercial activities
  • Marketing reuses production data without new lawful basis
  • Purpose creep over time without documentation
UZB-DPL-06
Data Minimisation

The volume and content of personal data processed must be adequate to and not excessive in relation to the purposes of processing. Collection should be limited to what is necessary.

Artefacts an auditor will ask for
  • Field by field justification of collection
  • Periodic data minimisation reviews
  • Forms aligned to stated purposes
  • Evidence of deprecating unused fields
Where this commonly fails
  • Forms collect identifiers not needed for purpose
  • Legacy fields persist after purpose changes
  • No periodic review of necessity
UZB-DPL-07
Data Accuracy and Quality

Controllers must ensure the accuracy and currency of personal data. Inaccurate or incomplete data must be corrected, supplemented, blocked or destroyed upon the request of the data subject or upon detection.

Artefacts an auditor will ask for
  • Data quality procedures
  • Rectification logs
  • Periodic accuracy review records
  • Source validation
Where this commonly fails
  • No mechanism for subjects to update data
  • Rectifications not propagated
  • Stale data retained indefinitely

Data Subject Rights

UZB-DPL-10
Data Subject Rights

Data subjects have rights to access, to obtain information about processing, to rectify or block inaccurate data, to withdraw consent, and to demand destruction of personal data when processing is unlawful or no longer necessary.

Artefacts an auditor will ask for
  • Rights request procedures and intake channels
  • DSR register with timing
  • Identity verification records
  • Response templates
  • Destruction certificates
Where this commonly fails
  • No defined process for rights requests
  • Response timelines unclear
  • Destruction not propagated to backups
  • Identity verification overly burdensome

Governance

UZBEKPDP-4
DPO, Governance, Breach

Per Uzbekistan Law: DPO + governance + breach notification + enforcement.

Artefacts an auditor will ask for
  • Uzbekistan evidence for UZBEKPDP-4
Where this commonly fails
  • localization + DPO partial

Localisation, Registration and Transfers

UZB-DPL-03
Data Localisation Requirement

Personal data of citizens of the Republic of Uzbekistan, collected through information systems located in Uzbekistan or through the internet, must be stored on databases physically located within the territory of Uzbekistan.

Artefacts an auditor will ask for
  • Database location attestations
  • Hosting contracts confirming Uzbek territory
  • Data flow diagrams showing primary storage in Uzbekistan
  • Registration with State Personalisation Centre
Where this commonly fails
  • Cloud services with primary storage outside Uzbekistan
  • Backup copies stored abroad without local primary
  • Lack of documentation for storage location
  • Failure to register databases as required
UZB-DPL-04
State Personalisation Centre Registration

Owners or operators of databases containing personal data of Uzbek citizens must register the databases with the State Personalisation Centre (Personalisation Agency), the authorised body for personal data protection oversight.

Artefacts an auditor will ask for
  • Registration confirmations from State Personalisation Centre
  • Registration updates for material changes
  • Internal register of registrations and renewals
Where this commonly fails
  • New databases not registered before processing
  • Updates not filed when purposes or scope change
  • Multiple business units register separately without coordination
UZB-DPL-11
Cross Border Data Transfers

Transfers of personal data to foreign states may be carried out provided that the receiving state ensures adequate protection of rights of data subjects. Transfers to states without adequate protection require consent or other specified grounds.

Artefacts an auditor will ask for
  • Adequacy determination records
  • Consent for transfers to non adequate countries
  • Transfer impact assessments
  • Recipient lists with countries
  • State Personalisation Centre notifications where required
Where this commonly fails
  • Adequacy assumed without analysis
  • Onward transfers from processors not tracked
  • Consent not specific to international transfer

Processors, Retention and Incidents

UZB-DPL-14
Processor Engagement

Operators may engage third parties to process personal data on their behalf based on a contract, provided the data subject has consented unless otherwise provided by law. Third parties must comply with the same protection requirements.

Artefacts an auditor will ask for
  • Data processing agreements
  • Consent records for third party processing where required
  • Third party assessment records
  • Subprocessor inventory
Where this commonly fails
  • Verbal arrangements without contract
  • Third parties not assessed for capability
  • Consent obtained without identifying third parties
UZB-DPL-15
Retention and Destruction

Personal data must be retained no longer than necessary for the purposes of processing. Upon achievement of the purposes or upon withdrawal of consent, data must be destroyed or depersonalised unless retention is required by law.

Artefacts an auditor will ask for
  • Retention schedules
  • Destruction logs and certificates
  • Depersonalisation procedures
  • Legal hold processes
Where this commonly fails
  • Indefinite retention by default
  • Destruction not verifiable
  • Backup tapes not addressed in retention schedule
UZB-DPL-16
Incident Notification

Operators must notify the State Personalisation Centre and affected data subjects in cases of incidents involving unauthorised access, disclosure, alteration or destruction of personal data, within timeframes established by regulations.

Artefacts an auditor will ask for
  • Incident response plan covering personal data
  • Breach register
  • Notifications to State Personalisation Centre
  • Notifications to data subjects
  • Post incident reviews
Where this commonly fails
  • No defined trigger for notification
  • Notification not made within required timeframe
  • Processor incidents not surfaced to operator

Rights

UZBEKPDP-2
Consent, Notice, Rights

Per Uzbekistan Law: consent + notice + data subject rights.

Artefacts an auditor will ask for
  • Uzbekistan evidence for UZBEKPDP-2
Where this commonly fails
  • localization + DPO partial

Scope

UZBEKPDP-1
Scope, Lawful Basis (Uzbekistan)

Per Uzbekistan Law ZRU-547 + Decree 4173 + State Personalisation Centre regulations: scope + lawful basis + data localization requirements.

Artefacts an auditor will ask for
  • Uzbekistan evidence for UZBEKPDP-1
Where this commonly fails
  • localization + DPO partial

Scope and Definitions

UZB-DPL-01
Scope and Definitions

The Law applies to the processing of personal data by state bodies, individuals and legal entities operating in the Republic of Uzbekistan, including foreign entities processing personal data of Uzbek citizens through means located in Uzbekistan.

Artefacts an auditor will ask for
  • Records of processing activities involving Uzbek data subjects
  • Applicability assessment for foreign entities
  • Inventory of means used in Uzbekistan
Where this commonly fails
  • Foreign controllers fail to assess applicability when targeting Uzbek users
  • Scope assessment not refreshed when new services launched
  • Inconsistent treatment of citizens versus residents

Security

UZBEKPDP-3
Security, Cross-Border, Localization

Per Uzbekistan Law: security + cross-border restrictions + Data Localization requirement for personal data of Uzbek citizens.

Artefacts an auditor will ask for
  • Uzbekistan evidence for UZBEKPDP-3
Where this commonly fails
  • localization + DPO partial

Security and Confidentiality

UZB-DPL-12
Security of Personal Data

Owners and operators of personal data are required to take legal, organisational and technical measures to protect personal data against unauthorised access, destruction, modification, blocking, copying, distribution and other unlawful actions.

Artefacts an auditor will ask for
  • Information security policy aligned to personal data
  • Risk assessments
  • Access control records
  • Encryption configurations
  • Logging and monitoring evidence
  • Incident response procedures
Where this commonly fails
  • Generic IT security not mapped to personal data risks
  • Access logs incomplete for sensitive data
  • Encryption gaps in transit or at rest
UZB-DPL-13
Confidentiality Obligation

Owners, operators and third parties accessing personal data must ensure confidentiality of such data, except in cases of depersonalisation or where personal data has been made publicly available by the data subject.

Artefacts an auditor will ask for
  • Signed confidentiality agreements
  • Training records covering personal data
  • Onboarding and offboarding procedures
  • Acknowledgement registers
Where this commonly fails
  • Confidentiality not extended to contractors
  • Training generic rather than personal data specific
  • Post employment obligations omitted
UZB-DPL-20
Anonymisation and Depersonalisation

Depersonalisation means actions resulting in the impossibility of attributing personal data to a specific data subject without additional information. Depersonalised data may be processed without the constraints applicable to personal data.

Artefacts an auditor will ask for
  • Depersonalisation procedures
  • Reidentification risk assessments
  • Documentation of additional information segregation
  • Review of techniques against current state of the art
Where this commonly fails
  • Pseudonymisation treated as anonymisation
  • Linkage risk not assessed
  • Reidentification possible through external datasets

Sensitive, Biometric and Children Data

UZB-DPL-08
Sensitive Categories of Personal Data

Special categories of personal data, including data on race, nationality, political views, religious beliefs, health and intimate life, may be processed only with the written consent of the data subject or in specific cases provided by law.

Artefacts an auditor will ask for
  • Sensitive data classification
  • Written consent forms for special categories
  • Justification for statutory exceptions
  • Enhanced access controls
Where this commonly fails
  • Sensitive data inferred without consent
  • Health data processed by HR without written consent
  • Religious data captured incidentally without basis
UZB-DPL-09
Biometric Data Protection

Biometric personal data may be processed only with the written consent of the data subject, except in cases related to administration of justice, state security, counter terrorism and other purposes expressly provided by law.

Artefacts an auditor will ask for
  • Biometric processing inventory
  • Written consent records
  • Legal basis documentation for exceptions
  • Security controls specific to biometric data
  • Retention periods for biometric data
Where this commonly fails
  • Biometric authentication deployed without written consent
  • No alternative non biometric method offered
  • Retention indefinite without justification
UZB-DPL-17
Children's Data

Processing of personal data of minors requires the consent of parents or legal guardians. Special protections apply to data of children processed in the course of educational, medical and other services.

Artefacts an auditor will ask for
  • Age verification procedures
  • Parental consent records
  • Special handling procedures for child accounts
  • Educational and medical sector specific controls
Where this commonly fails
  • No age verification
  • Parental consent collected without verification
  • Targeted marketing to children without restraint

Supervision and Liability

UZB-DPL-18
State Personalisation Centre Inspections

The State Personalisation Centre, as authorised body, conducts inspections of compliance with the Law on Personal Data, may request information from controllers and processors, and may issue binding orders and recommendations.

Artefacts an auditor will ask for
  • Procedures for handling regulator requests
  • Inspection readiness pack
  • Records of past inspections and outcomes
  • Remediation tracking
  • Designated point of contact
Where this commonly fails
  • No defined point of contact
  • Records not retrievable on inspection timelines
  • Past findings not closed out
UZB-DPL-19
Liability and Sanctions

Violations of the Law on Personal Data may result in administrative, civil or criminal liability, including fines, blocking of information systems containing personal data, and other measures established by Uzbek legislation.

Artefacts an auditor will ask for
  • Risk assessments addressing enforcement scenarios
  • Sanctions tracking
  • Insurance documentation where applicable
  • Lessons learned from past enforcement
Where this commonly fails
  • Risk model does not account for system blocking sanction
  • No tracking of regulatory actions in industry
  • Cure of violations not documented
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.