The law applies irrespective of the processing technology used. The current official consolidated text is maintained on LexUZ.
Lifecycle and conditions: Articles 10 to 19 govern collection, systematisation, storage, alteration, use, provision, dissemination, transfers, anonymisation, destruction and processing conditions.
Registration and consent: Article 20 requires registration of databases containing the Article 27-1 categories that must be stored in Uzbekistan and lists exclusions. Article 21 governs consent and withdrawal evidence.
Transparency and automated processing: Articles 22 to 24 require processing information and notice of relevant actions and regulate decisions based solely on automated processing.
Protected data: Articles 25 and 26 regulate special, biometric and genetic data.
Security and localisation: Articles 27, 27-1 and 28 require protection and confidentiality. The current Article 27-1 requires biometric data, genetic data and data of individual customers of telecommunications operators operating in Uzbekistan to be stored in Uzbekistan. Other data may be stored or processed abroad through the listed adequacy, standard-contractual-clause, binding-corporate-rule or recognised-standard routes.
Rights and accountability: Articles 30 and 31 establish subject rights and duties of database owners and operators.
The local PDF is the original official 2019 promulgation. Amendments shown in the current LexUZ consolidation, including 2026 changes, control where the texts differ.