The new rules mark the next stage of Uzbekistan’s reform of personal data localization requirements and identify jurisdictions to which personal data may be transferred, stored and processed subject to the applicable legal requirements.
Uzbekistan continues to reform its regulatory framework governing personal data localization and cross-border data transfers. By Resolution No. 415 dated 29 July 2026, which entered into force on 3 August 2026, the Cabinet of Ministers of the Republic of Uzbekistan approved a list of foreign countries and territories deemed to provide an adequate level of personal data protection. The adoption of the Resolution is particularly significant in light of the recent amendments to the Law of the Republic of Uzbekistan “On Personal Data”, which introduced important changes to the previously applicable data localization regime.
Changes to Uzbekistan’s Data Localization Requirements
Historically, Uzbekistan maintained relatively strict localization requirements for personal data of Uzbek citizens processed using information technologies, including requirements concerning the collection, systematization and storage of such data using technical facilities physically located in Uzbekistan. Recent amendments to the Law “On Personal Data” have partially liberalized this approach.
Under the revised framework, certain categories of personal data may now be stored and processed outside the territory of Uzbekistan, provided that one of the conditions established by law is satisfied. One of the key conditions is that the relevant foreign country must ensure an adequate level of protection of the rights of personal data subjects. The amended legislation further provided that the list of countries and territories meeting this standard would be determined by the Cabinet of Ministers. Resolution No. 415 now implements this provision by establishing the relevant list at the Government level.
Which Countries Are Considered to Provide Adequate Protection?
The approved list includes 49 countries and territories. Among them are EU Member States, including Germany, France, Italy, Spain, the Netherlands and others; the United Kingdom; Switzerland; Norway and Iceland; Canada; Japan; the Republic of Korea; Singapore; New Zealand; Israel; the Russian Federation; Brazil; Argentina; and Hong Kong and etc.
The United States is also included, although subject to an important qualification: the recognition applies to companies covered by the EU–US data privacy framework. The adoption of this list therefore provides the practical framework necessary to apply the recently introduced exceptions to Uzbekistan’s data localization requirements and facilitates cross-border transfers to jurisdictions officially recognized as providing an adequate level of personal data protection.
What About Transfers to Countries Outside the List?
The fact that a country is not included in the approved list does not necessarily mean that transfers of personal data to that jurisdiction are completely prohibited. However, such transfers are subject to a stricter regulatory regime and require additional legal, organizational and technical safeguards. Resolution No. 415 provides for the development of requirements concerning contractual mechanisms and binding corporate rules that may be used to ensure the security of transfers to countries that are not included in the adequacy list.
The Ministry of Internal Affairs, together with the Ministry of Digital Technologies, the State Security Service and the National Agency for Perspective Projects, has been tasked with developing the relevant requirements.
New Data Breach Notification Requirements
The Resolution also introduces specific requirements for responding to security incidents involving personal data transferred across borders. Where unauthorized access to or disclosure of personal data is identified, the relevant operator must notify the competent state authority within 24 hours of discovering the incident. A more detailed report must subsequently be submitted within 72 hours, providing information on the circumstances and causes of the incident, its scope and the measures taken to mitigate and remedy its consequences.
What Does This Mean for Businesses?
The new framework is particularly relevant for international companies, IT and SaaS providers, banks, payment service providers, marketplaces, digital platforms and other businesses that rely on foreign cloud infrastructure or transfer personal data outside Uzbekistan.
The approval of the 49 jurisdictions makes the mechanism introduced by the recent amendments to the Personal Data Law operational in practice. Businesses now have greater clarity when assessing whether foreign servers, data centers and cloud services may be used in compliance with Uzbekistan’s localization and cross-border data transfer requirements.
At the same time, the inclusion of a country in the adequacy list should not be interpreted as an automatic exemption from all requirements of Uzbekistan’s personal data legislation. Each data processing arrangement should still be assessed individually, taking into account the categories of personal data involved, the legal basis for processing and transfer, the status of the recipient, applicable information security requirements and other relevant conditions.
A Step Towards International Data Protection Standards
Resolution No. 415 also reflects Uzbekistan’s broader efforts to align its personal data framework with international standards. The Ministry of Foreign Affairs, together with the competent state authority, has been instructed to prepare proposals concerning Uzbekistan’s accession to the Council of Europe’s 1981 Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108). The authorities are also expected to pursue the recognition of Uzbekistan as a jurisdiction providing an adequate level of personal data protection under the corresponding frameworks of foreign countries.
Overall, Resolution No. 415 represents an important continuation of Uzbekistan’s recent data protection reforms. While the amendments to the Law “On Personal Data” created a legal basis for more flexible storage and processing of certain personal data outside Uzbekistan, the new Resolution identifies the foreign jurisdictions in respect of which this mechanism may now be applied. For businesses, this signals a gradual shift from a predominantly territorial localization model towards a more flexible approach based on the level of personal data protection in the receiving jurisdiction and the safeguards applicable to cross-border data transfers.