Legislative updates in the field of Personal data protection – August 2026

Uzbekistan approved the List of Foreign States Ensuring Adequate Protection of Personal Data

On August 3, 2026, the Resolution of the Cabinet of Ministers of the Republic of Uzbekistan No.415 “On Approval of the List of Foreign States Ensuring Adequate Protection of Personal Data” dated July 29, 2026 (the “Resolution No.415”), entered into force.

The adopted Resolution No.415 is aimed at establishing a unified legal framework for the cross-border transfer of personal data (the “PD”). The key development is approval of the List of Foreign States Ensuring Adequate Protection of Personal Data (the “List”), which comprises 49 jurisdictions. The List mostly encompasses European countries, as well as select advanced Asian economies, including Singapore, Japan and the Republic of Korea.

The regulation of cross-border transfers of personal data to the United States merits particular attention. Thus, under the Resolution No. 415, transfer of personal data to U.S.-based companies is permitted, provided that the recipient companies maintain an active certification under the EU-U.S. Data Privacy Framework. For compliance purposes, any company utilizing U.S. cloud platforms, software or technological infrastructure must strictly verify this certification.

Elimination of the Legal Gap in National Legislation

Prior to the approval of the List, the national regulatory framework governing cross-border transfers of PD was characterized by a significant degree of legal uncertainty. Specifically, Article 15 of the Law of the Republic of Uzbekistan No.LRU-547 “On Personal Data” dated July 2, 2019 (the “Law on Personal Data”) stipulates that the cross-border transfer of PD is permitted to foreign states ensuring an adequate level of protection of the rights of PD subjects. Furthermore, part 3 of Article 27-1 of the Law on Personal Data provides that PD may be stored and processed outside the Republic of Uzbekistan ("Uzbekistan"), provided that the relevant foreign state is recognized as ensuring an adequate level of PD protection.

However, prior to the adoption of the Resolution No.415, the legislation contained neither a comprehensive list of states ensuring an adequate level of PD protection nor established criteria for classifying states under this category.

Consequently, transferring PD to the states that did not ensure adequate protection of PD subjects’ rights was permitted only in instances explicitly prescribed by the Law on Personal Data. These exemptions included obtaining the explicit consent of the PD subject, safeguarding the constitutional order, or executing international treaties of Uzbekistan. In practice, this created significant compliance risks and administrative burdens.

With the entry into force of the Resolution No.415, this statutory gap has been rectified. The cross-border transfer of PD, as well as its storage and processing in the states included in the List, may now be conducted automatically without the need to obtain additional permits or notify the authorized body, provided that other requirements of PD legislation are met.

Matters Regarding Automatic Data Transfers by Private Entities

Although the Resolution No.415 is intended to streamline cross-border data transfer, its certain provisions create new legal uncertainties. Specifically, paragraph 2 of Clause 4 of the Resolution No.415 stipulates that automatically generated data is transferred “via information systems established on the basis of international agreements”.

However, the wording of this provision fails to unambiguously identify the relevant information systems or define the criteria for their classification as systems established on the basis of international agreements. As a result, it remains unclear whether this requirement applies universally to all instances of automated cross-border data transfers.

The terminology used in the Resolution No.415 regarding data transfer via information systems established under international agreements raises additional legal concerns. This wording prompts questions regarding the applicability of the List to the private sector. In particular, it remains ambiguous whether commercial organizations may fully rely on the cross-border data transfer regime defined by the Resolution No.415.

Until official enforcement practice is established and the competent authorities issue relevant clarifications, applying the provisions of the Resolution No.415 to specific corporate operations necessitates an individual legal analysis.

Mechanisms for Cross-Border Data Transfers to Non-Listed Jurisdictions

The Resolution No.415 also introduces regulatory mechanisms for cross-border data transfers to foreign states not included in the List, including jurisdictions such as China, India and the United Arab Emirates.

Pursuant to Clause 7 of the Resolution No.415, the Ministry of Internal Affairs, the Ministry of Digital Technologies, the State Security Service, and the National Agency for Perspective Projects are to develop and approve, within three months from the date of the Resolution’s adoption, the requirements for standard contractual clauses (SCCs) and binding corporate rules (BCRs) to be utilized in cross-border PD transfers.

Mandatory Procedural Timelines for Data Breach Notification

In addition, a key requirement introduced by the Resolution No. 415 is the establishment of strict timeframes for reporting PD breaches occurring in the course of cross-border processing.

Paragraph 4 of Clause 4 imposes a mandatory obligation on data operators to notify the competent authority, the Department of Migration and Personalization under the Ministry of Internal Affairs, within 24 hours from the moment a data leak is detected. Furthermore, a comprehensive report identifying the causes of the breach and detailing the remedial measures taken must be submitted within 72 hours.

Contacts:      

Zafar Vakhidov Partner,

Vakhidov & Partners

Uzbekistan / Kazakhstan

ZV@vakhidovlaw.com 

Kamila Sharipova Senior

Associate,

Vakhidov & Partners Uzbekistan

KamilaSh@vakhidovlaw.com 

Download