Law / Azerbaijan

Law on Personal Data, enforcement and liability

Law of the Republic of Azerbaijan on Personal Data, Law No. 998-IIIQ, Arts. 7.4, 17, 19

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 11 May 2010.

An enforcement supervision rule binding public and private bodies.

As of 2 September 2026.

What it requires

  • An app processing the personal data of a person in Azerbaijan must be prepared to answer to the relevant executive authority's compliance checks; Art. 19's own liability provision is a bare reference to other Azerbaijani law with no fine amounts stated in this Act, and an aggrieved person may separately sue in court for moral and material damage under Art. 7.4, but only on proof of the damage suffered.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Azerbaijan's Criminal Code has no personal-data-specific offense. Where processing personal data in an information system this Act requires to be registered (Art. 16) is unregistered, and that unregistered processing also amounts to entrepreneurial activity conducted without the state registration or license Criminal Code Art. 192 requires, and the activity causes especially large damage or especially large income, Art. 192.3 punishes it with a fine of four times the damage or income, or five to seven years' imprisonment, with or without up to three years' bar from holding certain positions or engaging in certain activity. Ordinary violations that do not reach this unlicensed-business, especially-large-scale threshold are not separately criminalized.

Penalty structure

Fine sits in the Administrative Violations Code (Inzibati Xetalar Mecellesi) Art. 375.0, not in this Act's own text; Art. 19 (Liability) only refers out to the legislation of the Republic of Azerbaijan without stating an amount. Applies to collecting or processing personal data in an information system that requires state registration under this Act but was not registered (Art. 375.0.1), and to a data owner or operator's failure to protect personal data, failure to destroy it within this Act's required timeframes, or failure to halt collection, processing, or transfer of it as required (Art. 375.0.2).

Rule
Fixed only
As of
2 September 2026
Minimum
300
Currency
AZN
Fixed cap
500

Who enforces it

Enforcement body

Ministry of Digital Development and Transport of the Republic of Azerbaijan, through its Electronic Security Service (Elektron Tehlukesizlik Xidmeti, operating as CERT.az), which operates the State Registry of Personal Data Information Systems (registry.pdp.az) that Art. 16 requires and that Art. 17's compliance-check power reaches; Art. 375 administrative fines and any Criminal Code Art. 192 prosecution are pursued through the ordinary courts and prosecutors rather than by this Ministry itself.

What it reaches

Obligation class

Licensing, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Art. 17 gives a relevant executive authority, not named within this Act itself, power to check compliance of registered information systems, demand information, verify registration filings, demand remedies for violations, and take measures to prosecute violators; which body currently holds that role is not confirmed.

Art. 19 (Liability) is a single sentence: persons guilty of violating this Law shall be held responsible in accordance with the legislation of the Republic of Azerbaijan, a bare reference-out to other, unread law with no fine amounts, penalty tiers, or named enforcement mechanism inside this Act itself, markedly thinner than every other jurisdiction in this batch.

Art. 7.4 gives the data subject a right to complain to the executive authority or the court, and to demand payment of moral and material damage in a court of law, an ordinary proof-of-damage civil remedy rather than a no-proof-of-damage statutory-damages mechanism. Fine amounts a secondary source claims exist in the Administrative Violations Code (300 to 500 AZN, imprisonment up to 7 years) are unconfirmed against primary text and are not stated here as sourced to this Act.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

official English translation, International Labour Organization NATLEX

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app