Uzbekistan Law on Personal Data (No. ZRU-547)
Uzbekistan's Law on Personal Data (No. ZRU-547, 2019) establishes the personal data protection framework. The State Inspectorate for Supervision of Informatisation and Telecommunications oversees compliance. The law covers processing principles, consent requirements, data subject rights, cross-border transfer provisions, and data security obligations. Applies to processing of personal data by state bodies, legal entities, and individuals in Uzbekistan.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (24)
Anonymisation
| Code | Title |
|---|---|
| UZB-DPL-20 | Anonymisation and Depersonalisation |
Biometric Data
| Code | Title |
|---|---|
| UZB-DPL-09 | Biometric Data Protection |
Breach Notification
| Code | Title |
|---|---|
| UZB-DPL-16 | Incident Notification |
Chapter 1 - General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
Chapter 2 - State Regulation
| Code | Title |
|---|---|
| Art. 6 | Writing |
| Art. 7 | Minimum Standards |
| Art. 8 | Compliance with the Requirements |
Chapter 3 - Processing of Personal Data
| Code | Title |
|---|---|
| Art. 10 | Data and Data Governance |
| Art. 11 | Technical Documentation |
| Art. 12 | Record-Keeping |
| Art. 13 | Transparency and Provision of Information to Deployers |
| Art. 15 | Accuracy, Robustness and Cybersecurity |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
| Art. 17 | Quality Management System |
| Art. 9 | Risk Management System |
Chapter 4 - Procedure for Processing
| Code | Title |
|---|---|
| Art. 18 | Documentation Keeping |
| Art. 19 | Automatically Generated Logs |
| Art. 20 | Corrective Actions and Duty of Information |
| Art. 21 | Cooperation with Competent Authorities |
Chapter 5 - Protection of Personal Data
| Code | Title |
|---|---|
| Art. 27 | Fundamental Rights Impact Assessment for High-Risk AI Systems |
| Art. 28 | Notifying Authorities |
| Art. 29 | Application of a Conformity Assessment Body for Notification |
| Art. 30 | Privacy Policy |
Chapter 7 - Final Provisions
| Code | Title |
|---|---|
| Art. 32 | Entry into Force |
| Art. 33 | Criminal Offences |
| Art. 36 | Right to Correction or Deletion |
Children
| Code | Title |
|---|---|
| UZB-DPL-17 | Children's Data |
Confidentiality
| Code | Title |
|---|---|
| UZB-DPL-13 | Confidentiality Obligation |
Data Localisation
| Code | Title |
|---|---|
| UZB-DPL-03 | Data Localisation Requirement |
Data Subject Rights
| Code | Title |
|---|---|
| UZB-DPL-10 | Data Subject Rights |
Enforcement
| Code | Title |
|---|---|
| UZB-DPL-19 | Liability and Sanctions |
International Transfers
| Code | Title |
|---|---|
| UZB-DPL-11 | Cross Border Data Transfers |
Lawful Basis
| Code | Title |
|---|---|
| UZB-DPL-02 | Consent of the Data Subject |
Principles
| Code | Title |
|---|---|
| UZB-DPL-05 | Purpose Limitation Principle |
| UZB-DPL-06 | Data Minimisation |
| UZB-DPL-07 | Data Accuracy and Quality |
Registration
| Code | Title |
|---|---|
| UZB-DPL-04 | State Personalisation Centre Registration |
Regulatory Oversight
| Code | Title |
|---|---|
| UZB-DPL-18 | State Personalisation Centre Inspections |
Retention
| Code | Title |
|---|---|
| UZB-DPL-15 | Retention and Destruction |
Scope
| Code | Title |
|---|---|
| UZB-DPL-01 | Scope and Definitions |
Security
| Code | Title |
|---|---|
| UZB-DPL-12 | Security of Personal Data |
Sensitive Data
| Code | Title |
|---|---|
| UZB-DPL-08 | Sensitive Categories of Personal Data |
Third Party Management
| Code | Title |
|---|---|
| UZB-DPL-14 | Processor Engagement |
Your Compliance Coverage
If you comply with Uzbekistan Law on Personal Data (No. ZRU-547), you already cover:
EU AI Act
36%
17 controls mapped
Compare →Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data
34%
16 controls mapped
Compare →BS 65000:2014 - Guidance on Organizational Resilience
34%
16 controls mapped
Compare →+ 613 more: Uruguay Personal Data Protection Act (Law No. 18.331) (32%), GDPR (32%)
See all 616 mapped frameworks ↓Maps to 616 other frameworks
Frequently Asked Questions
What is Uzbekistan Law on Personal Data (No. ZRU-547)?
Uzbekistan Law on Personal Data (No. ZRU-547) is a compliance framework from Uzbekistan with 24 domains and 47 controls. Uzbekistan's Law on Personal Data (No. ZRU-547, 2019) establishes the personal data protection framework. The State Inspectorate for Supervision of Informatisation and Telecommunications oversees compliance. The law covers processing principles, consent requirements, data subject rights, cross-border transfer provisions, and data security obligations. Applies to processing of personal data by state bodies, legal entities, and individuals in Uzbekistan. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Uzbekistan Law on Personal Data (No. ZRU-547) have?
Uzbekistan Law on Personal Data (No. ZRU-547) has 47 controls organised across 24 domains. The largest domains are Chapter 3 - Processing of Personal Data (8 controls), Chapter 1 - General Provisions (5 controls), Chapter 4 - Procedure for Processing (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Uzbekistan Law on Personal Data (No. ZRU-547) map to?
Uzbekistan Law on Personal Data (No. ZRU-547) maps to 616 other compliance frameworks. The top mapping partners are EU AI Act (36% coverage), Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (34% coverage), BS 65000:2014 - Guidance on Organizational Resilience (34% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Uzbekistan Law on Personal Data (No. ZRU-547) compliance?
Start your Uzbekistan Law on Personal Data (No. ZRU-547) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Uzbekistan Law on Personal Data (No. ZRU-547) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 47 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required