Uzbekistan Law on Personal Data (No. ZRU-547)
Uzbekistan's Law on Personal Data (No. ZRU-547, 2019) establishes the personal data protection framework. The State Inspectorate for Supervision of Informatisation and Telecommunications oversees compliance. The law covers processing principles, consent requirements, data subject rights, cross-border transfer provisions, and data security obligations. Applies to processing of personal data by state bodies, legal entities, and individuals in Uzbekistan.
Uzbekistan Law on Personal Data (No. ZRU-547) is a compliance framework from Uzbekistan with 12 domains and 24 controls. The largest domains are Consent and Lawful Processing (4 controls), Localisation, Registration and Transfers (3 controls), Processors, Retention and Incidents (3 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (12)
Consent and Lawful Processing
Consent and Lawful Processing
| Code | Title |
|---|---|
| UZB-DPL-02 | Consent of the Data Subject |
| UZB-DPL-05 | Purpose Limitation Principle |
| UZB-DPL-06 | Data Minimisation |
| UZB-DPL-07 | Data Accuracy and Quality |
Data Subject Rights
Data Subject Rights
| Code | Title |
|---|---|
| UZB-DPL-10 | Data Subject Rights |
Governance
| Code | Title |
|---|---|
| UZBEKPDP-4 | DPO, Governance, Breach |
Localisation, Registration and Transfers
Localisation, Registration and Transfers
| Code | Title |
|---|---|
| UZB-DPL-03 | Data Localisation Requirement |
| UZB-DPL-04 | State Personalisation Centre Registration |
| UZB-DPL-11 | Cross Border Data Transfers |
Processors, Retention and Incidents
Processors, Retention and Incidents
| Code | Title |
|---|---|
| UZB-DPL-14 | Processor Engagement |
| UZB-DPL-15 | Retention and Destruction |
| UZB-DPL-16 | Incident Notification |
Rights
| Code | Title |
|---|---|
| UZBEKPDP-2 | Consent, Notice, Rights |
Scope
| Code | Title |
|---|---|
| UZBEKPDP-1 | Scope, Lawful Basis (Uzbekistan) |
Scope and Definitions
Scope and Definitions
| Code | Title |
|---|---|
| UZB-DPL-01 | Scope and Definitions |
Security
| Code | Title |
|---|---|
| UZBEKPDP-3 | Security, Cross-Border, Localization |
Security and Confidentiality
Security and Confidentiality
| Code | Title |
|---|---|
| UZB-DPL-12 | Security of Personal Data |
| UZB-DPL-13 | Confidentiality Obligation |
| UZB-DPL-20 | Anonymisation and Depersonalisation |
Sensitive, Biometric and Children Data
Sensitive, Biometric and Children Data
| Code | Title |
|---|---|
| UZB-DPL-08 | Sensitive Categories of Personal Data |
| UZB-DPL-09 | Biometric Data Protection |
| UZB-DPL-17 | Children's Data |
Supervision and Liability
Supervision and Liability
| Code | Title |
|---|---|
| UZB-DPL-18 | State Personalisation Centre Inspections |
| UZB-DPL-19 | Liability and Sanctions |
What is Uzbekistan Law on Personal Data (No. ZRU-547) and who does it apply to?
Uzbekistan Law on Personal Data (No. ZRU-547) is a compliance framework from Uzbekistan with 12 domains and 24 controls. Uzbekistan's Law on Personal Data (No. ZRU-547, 2019) establishes the personal data protection framework. The State Inspectorate for Supervision of Informatisation and Telecommunications oversees compliance. The law covers processing principles, consent requirements, data subject rights, cross-border transfer provisions, and data security obligations. Applies to processing of personal data by state bodies, legal entities, and individuals in Uzbekistan. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Uzbekistan Law on Personal Data (No. ZRU-547) actually require?
Uzbekistan Law on Personal Data (No. ZRU-547) has 24 controls organised across 12 domains. The largest domains are Consent and Lawful Processing (4 controls), Localisation, Registration and Transfers (3 controls), Processors, Retention and Incidents (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Uzbekistan Law on Personal Data (No. ZRU-547) do I already cover?
Uzbekistan Law on Personal Data (No. ZRU-547) does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement Uzbekistan Law on Personal Data (No. ZRU-547)?
Start your Uzbekistan Law on Personal Data (No. ZRU-547) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Uzbekistan Law on Personal Data (No. ZRU-547) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required