Uzbekistan Law on Personal Data (No. ZRU-547)
Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Consent and Lawful Processing
Personal data may only be processed with the consent of the data subject unless an exception applies. Consent must be free, specific, informed and unambiguous, and may be revoked at any time.
- Consent capture records
- Consent forms with required disclosures
- Withdrawal mechanism logs
- Lawful basis register per processing activity
- Pre ticked consent boxes used
- No mechanism to withdraw consent
- Consent bundled with terms of service
- Withdrawal not propagated through systems
Personal data must be processed for specific, predetermined and legitimate purposes. Processing for purposes incompatible with the original purposes is prohibited unless a new lawful basis is established.
- Purpose declarations per dataset
- Compatibility assessments for secondary use
- Privacy notices specifying purposes
- Records of purpose changes with renewed consent
- Generic purposes such as commercial activities
- Marketing reuses production data without new lawful basis
- Purpose creep over time without documentation
The volume and content of personal data processed must be adequate to and not excessive in relation to the purposes of processing. Collection should be limited to what is necessary.
- Field by field justification of collection
- Periodic data minimisation reviews
- Forms aligned to stated purposes
- Evidence of deprecating unused fields
- Forms collect identifiers not needed for purpose
- Legacy fields persist after purpose changes
- No periodic review of necessity
Controllers must ensure the accuracy and currency of personal data. Inaccurate or incomplete data must be corrected, supplemented, blocked or destroyed upon the request of the data subject or upon detection.
- Data quality procedures
- Rectification logs
- Periodic accuracy review records
- Source validation
- No mechanism for subjects to update data
- Rectifications not propagated
- Stale data retained indefinitely
Data Subject Rights
Data subjects have rights to access, to obtain information about processing, to rectify or block inaccurate data, to withdraw consent, and to demand destruction of personal data when processing is unlawful or no longer necessary.
- Rights request procedures and intake channels
- DSR register with timing
- Identity verification records
- Response templates
- Destruction certificates
- No defined process for rights requests
- Response timelines unclear
- Destruction not propagated to backups
- Identity verification overly burdensome
Governance
Per Uzbekistan Law: DPO + governance + breach notification + enforcement.
- Uzbekistan evidence for UZBEKPDP-4
- localization + DPO partial
Localisation, Registration and Transfers
Personal data of citizens of the Republic of Uzbekistan, collected through information systems located in Uzbekistan or through the internet, must be stored on databases physically located within the territory of Uzbekistan.
- Database location attestations
- Hosting contracts confirming Uzbek territory
- Data flow diagrams showing primary storage in Uzbekistan
- Registration with State Personalisation Centre
- Cloud services with primary storage outside Uzbekistan
- Backup copies stored abroad without local primary
- Lack of documentation for storage location
- Failure to register databases as required
Owners or operators of databases containing personal data of Uzbek citizens must register the databases with the State Personalisation Centre (Personalisation Agency), the authorised body for personal data protection oversight.
- Registration confirmations from State Personalisation Centre
- Registration updates for material changes
- Internal register of registrations and renewals
- New databases not registered before processing
- Updates not filed when purposes or scope change
- Multiple business units register separately without coordination
Transfers of personal data to foreign states may be carried out provided that the receiving state ensures adequate protection of rights of data subjects. Transfers to states without adequate protection require consent or other specified grounds.
- Adequacy determination records
- Consent for transfers to non adequate countries
- Transfer impact assessments
- Recipient lists with countries
- State Personalisation Centre notifications where required
- Adequacy assumed without analysis
- Onward transfers from processors not tracked
- Consent not specific to international transfer
Processors, Retention and Incidents
Operators may engage third parties to process personal data on their behalf based on a contract, provided the data subject has consented unless otherwise provided by law. Third parties must comply with the same protection requirements.
- Data processing agreements
- Consent records for third party processing where required
- Third party assessment records
- Subprocessor inventory
- Verbal arrangements without contract
- Third parties not assessed for capability
- Consent obtained without identifying third parties
Personal data must be retained no longer than necessary for the purposes of processing. Upon achievement of the purposes or upon withdrawal of consent, data must be destroyed or depersonalised unless retention is required by law.
- Retention schedules
- Destruction logs and certificates
- Depersonalisation procedures
- Legal hold processes
- Indefinite retention by default
- Destruction not verifiable
- Backup tapes not addressed in retention schedule
Operators must notify the State Personalisation Centre and affected data subjects in cases of incidents involving unauthorised access, disclosure, alteration or destruction of personal data, within timeframes established by regulations.
- Incident response plan covering personal data
- Breach register
- Notifications to State Personalisation Centre
- Notifications to data subjects
- Post incident reviews
- No defined trigger for notification
- Notification not made within required timeframe
- Processor incidents not surfaced to operator
Rights
Per Uzbekistan Law: consent + notice + data subject rights.
- Uzbekistan evidence for UZBEKPDP-2
- localization + DPO partial
Scope
Per Uzbekistan Law ZRU-547 + Decree 4173 + State Personalisation Centre regulations: scope + lawful basis + data localization requirements.
- Uzbekistan evidence for UZBEKPDP-1
- localization + DPO partial
Scope and Definitions
The Law applies to the processing of personal data by state bodies, individuals and legal entities operating in the Republic of Uzbekistan, including foreign entities processing personal data of Uzbek citizens through means located in Uzbekistan.
- Records of processing activities involving Uzbek data subjects
- Applicability assessment for foreign entities
- Inventory of means used in Uzbekistan
- Foreign controllers fail to assess applicability when targeting Uzbek users
- Scope assessment not refreshed when new services launched
- Inconsistent treatment of citizens versus residents
Security
Per Uzbekistan Law: security + cross-border restrictions + Data Localization requirement for personal data of Uzbek citizens.
- Uzbekistan evidence for UZBEKPDP-3
- localization + DPO partial
Security and Confidentiality
Owners and operators of personal data are required to take legal, organisational and technical measures to protect personal data against unauthorised access, destruction, modification, blocking, copying, distribution and other unlawful actions.
- Information security policy aligned to personal data
- Risk assessments
- Access control records
- Encryption configurations
- Logging and monitoring evidence
- Incident response procedures
- Generic IT security not mapped to personal data risks
- Access logs incomplete for sensitive data
- Encryption gaps in transit or at rest
Owners, operators and third parties accessing personal data must ensure confidentiality of such data, except in cases of depersonalisation or where personal data has been made publicly available by the data subject.
- Signed confidentiality agreements
- Training records covering personal data
- Onboarding and offboarding procedures
- Acknowledgement registers
- Confidentiality not extended to contractors
- Training generic rather than personal data specific
- Post employment obligations omitted
Depersonalisation means actions resulting in the impossibility of attributing personal data to a specific data subject without additional information. Depersonalised data may be processed without the constraints applicable to personal data.
- Depersonalisation procedures
- Reidentification risk assessments
- Documentation of additional information segregation
- Review of techniques against current state of the art
- Pseudonymisation treated as anonymisation
- Linkage risk not assessed
- Reidentification possible through external datasets
Sensitive, Biometric and Children Data
Special categories of personal data, including data on race, nationality, political views, religious beliefs, health and intimate life, may be processed only with the written consent of the data subject or in specific cases provided by law.
- Sensitive data classification
- Written consent forms for special categories
- Justification for statutory exceptions
- Enhanced access controls
- Sensitive data inferred without consent
- Health data processed by HR without written consent
- Religious data captured incidentally without basis
Biometric personal data may be processed only with the written consent of the data subject, except in cases related to administration of justice, state security, counter terrorism and other purposes expressly provided by law.
- Biometric processing inventory
- Written consent records
- Legal basis documentation for exceptions
- Security controls specific to biometric data
- Retention periods for biometric data
- Biometric authentication deployed without written consent
- No alternative non biometric method offered
- Retention indefinite without justification
Processing of personal data of minors requires the consent of parents or legal guardians. Special protections apply to data of children processed in the course of educational, medical and other services.
- Age verification procedures
- Parental consent records
- Special handling procedures for child accounts
- Educational and medical sector specific controls
- No age verification
- Parental consent collected without verification
- Targeted marketing to children without restraint
Supervision and Liability
The State Personalisation Centre, as authorised body, conducts inspections of compliance with the Law on Personal Data, may request information from controllers and processors, and may issue binding orders and recommendations.
- Procedures for handling regulator requests
- Inspection readiness pack
- Records of past inspections and outcomes
- Remediation tracking
- Designated point of contact
- No defined point of contact
- Records not retrievable on inspection timelines
- Past findings not closed out
Violations of the Law on Personal Data may result in administrative, civil or criminal liability, including fines, blocking of information systems containing personal data, and other measures established by Uzbek legislation.
- Risk assessments addressing enforcement scenarios
- Sanctions tracking
- Insurance documentation where applicable
- Lessons learned from past enforcement
- Risk model does not account for system blocking sanction
- No tracking of regulatory actions in industry
- Cure of violations not documented
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.