Approved list of foreign countries ensuring an adequate level of personal data protection

Important changes in personal data regulation in Uzbekistan

25 august 2026
On 3 August 2026, the Cabinet of Ministers of the Republic of Uzbekistan adopted Resolution No. 415 “On Approval of the List of Foreign States Providing an Adequate Level of Personal Data Protection” (the “Resolution”).
For details of the amendments introduced by Law No. ZRU-1125 to the personal data legislation of the Republic of Uzbekistan, please see our previous article.

The Resolution approves the list of foreign states providing an adequate level of personal data protection and also regulates certain aspects of cross-border transfers of personal data. The Resolution was adopted pursuant to Article 27 of the Law of the Republic of Uzbekistan “On Personal Data” and completes the implementation of the cross-border personal data transfer framework introduced by Law No. ZRU-1125 of the Republic of Uzbekistan.

Before the Resolution was adopted, the legislation permitted the transfer of personal data to foreign states providing an adequate level of personal data protection. However, the absence of an officially approved list of such states created legal uncertainty regarding practical application of this mechanism.
WHAT HAS CHANGED?

The Resolution approves the list of foreign states recognized as providing an adequate level of personal data protection (the “List”). No such list existed earlier.

This means that, when carrying out cross-border transfers of personal data, organizations must now take into account whether the recipient country is included in the approved List.
CROSS-BORDER TRANSFERS OF PERSONAL DATA TO COUNTRIES INCLUDED IN THE LIST

Where personal data is transferred across borders to countries included in the List:

  • No additional authorizations are required
  • No notification to the competent state authority is required
  • The transfer may be carried out automatically through information systems established under international agreements
  • The data operator must implement appropriate measures to prevent personal data breaches
CROSS-BORDER TRANSFERS OF PERSONAL DATA TO COUNTRIES NOT INCLUDED IN THE LIST

Where the recipient country is not included in the List, cross-border transfers of personal data are permitted only if additional legal, organizational and technical requirements established by the competent state authority are satisfied.

In addition, the Resolution provides for the development of requirements applicable to standard contractual clauses and binding corporate rules which will serve as safeguards for cross-border transfers of personal data.
PERSONAL DATA BREACH NOTIFICATION

The Resolution also introduces an obligation to notify the competent state authority in the event of a personal data breach occurring in connection with a cross-border transfer of personal data.

In such cases, the data operator must:

  • Notify the competent state authority within 24 hours of becoming aware of the incident
  • Submit detailed information on the causes of the breach and the remedial measures within 72 hours
LIST OF FOREIGN COUNTRIES ENSURING AN ADEQUATE LEVEL OF PERSONAL DATA PROTECTION
  • Principality of Andorra
  • Canada
  • Argentine Republic
  • Republic of Croatia
  • Republic of Austria
  • Republic of Cyprus
  • Kingdom of Belgium
  • Czech Republic
  • Federative Republic of Brazil
  • Kingdom of Denmark
  • Republic of Bulgaria
  • Republic of Estonia
  • Faroe Islands (autonomous territory of the Kingdom of Denmark)
  • Republic of Malta
  • Republic of Finland
  • Isle of Man (British Crown Dependency)
  • French Republic
  • Kingdom of the Netherlands
  • Federal Republic of Germany
  • New Zealand
  • Bailiwick of Guernsey
  • Kingdom of Norway
  • Hellenic Republic
  • Republic of Poland
  • Hong Kong Special Administrative Region of the People’s Republic of China
  • Portuguese Republic
  • Hungary
  • Romania
  • Iceland
  • Russian Federation
  • Ireland
  • Republic of Singapore
  • State of Israel
  • Slovak Republic
  • Republic of Italy
  • Republic of Slovenia
  • Japan
  • Kingdom of Spain
  • Bailiwick of Jersey
  • Kingdom of Sweden
  • Republic of Korea
  • Swiss Confederation
  • Republic of Latvia
  • United Kingdom of Great Britain and Northern Ireland
  • Principality of Liechtenstein
  • United States of America[1]
  • Republic of Lithuania
  • Oriental Republic of Uruguay
  • Grand Duchy of Luxembourg
PRACTICAL IMPLICATIONS FOR BUSINESS

The adoption of the Resolution means that the mechanism for cross-border transfer of personal data provided for by Law of the Republic of Uzbekistan No. ZRU-1125 has been put into practice.

Companies are recommended to:

  • Identify the foreign countries to which personal data is transferred
  • Check existing cross-border data flows against the approved List
  • Assess the need to implement additional protection mechanisms when transferring data to countries not included in the List
  • Establish internal procedures for responding to personal data breach incidents, taking into account the new notification deadlines
  • Review internal policies and contractual mechanisms governing cross-border transfers of personal data
HOW BEONE CAN HELP?

  • Conduct an audit of personal data processing and cross-border transfer processes
  • Assess compliance of business activities with the new legal requirements
  • Prepare internal documentation and contractual mechanisms
  • Provide advisory support on personal data protection and cross-border data transfer matters

We hope that this information will be useful to you. We would be pleased to provide you with a more detailed consultation regarding these changes and discuss any questions you may have.

CONTACTS


© BeOne Advisory LLC, 2026
Address: 23 T. Shevchenko Street, Mirabad District, Tashkent, 100060, Republic of Uzbekistan
www.beone-uz.com