Details
JULY 2026
The Cabinet of Ministers of the Republic of Uzbekistan adopted Resolution No. 415 dated July 29, 2026, approving a list of foreign states that ensure an equivalent level of personal data protection. The document was adopted pursuant to the Law of the Republic of Uzbekistan “On Personal Data” and establishes new rules for the cross-border transfer of personal data.
What Has Changed?
For the first time, a list of states to which personal data may be transferred under a simplified procedure has been established at the regulatory level. The list includes 49 states and territories, including the countries of the European Union, the United Kingdom, Canada, Switzerland, Japan, the Republic of Korea, Singapore, Israel, Brazil, Argentina and New Zealand.
Separate rules are provided for the United States of America. The simplified data transfer procedure applies only to organizations participating in the EU–US Data Privacy Framework.
The transfer of personal data to states included in the list is permitted without obtaining additional authorizations and without notifying the authorized state body, provided that data security requirements are complied with.
What Should Be Done if a Country Is Not Included in the List?
The transfer of personal data to countries not included in the approved list is also permitted; however, operators and owners of personal data databases must comply with additional legal, organizational and technical requirements to be determined by the authorized state body. In addition, the Government has been instructed to develop requirements for standard contractual clauses and binding corporate rules to be used for cross-border data transfers to such states.
Localization and Data Breach Notification
The Resolution does not abolish the requirements for the localization of certain categories of data. Biometric data, genetic data, as well as the data of users of services provided by telecommunications operators operating in Uzbekistan, remain subject to storage within the territory of the Republic of Uzbekistan.
At the same time, for the first time, the document establishes the obligation of operators to notify the authorized state body of personal data security breaches occurring during cross-border transfers. An incident must be reported within 24 hours of its discovery, and detailed information on the causes of the breach and the measures taken must be submitted within 72 hours.
Practical Significance
The adopted Resolution significantly simplifies the use of foreign digital infrastructure, including cloud services, CRM systems and corporate platforms, where personal data is transferred to states included in the approved list. At the same time, companies are advised to review the geographical locations in which personal data is stored, assess the applicability of the new rules to their cross-border data flows, and ensure compliance with legislative requirements concerning the localization and protection of certain categories of personal data.