Law / Turkmenistan

Turkmenistan

10 of 14 named instruments researched to a stage, across four of the six areas of law we track: 10 in force. As of 19 September 2026.

When they take effect9 of 10 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 1 instrument (1 in force) 2015: 0 instruments ’15 2016: 0 instruments 2017: 5 instruments (5 in force) 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 2 instruments (2 in force) 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 5
  3. Scraping law 2
  4. Cybersecurity law 2
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law5 instruments, 5 in force

Research summary (327 words)

Turkmenistan's Law No. 519-V "On Information About Private Life and Its Protection" (20 March 2017, in force 1 July 2017) applies to the operator, defined broadly to include state bodies and private persons, and requires the subject's written consent for most collection and processing (Art. 7).

Its Articles 12 and 17 are structurally near-identical to Kazakhstan's Articles 12 and 16, and its biometric-deferral clause at Art. 7(7) is a word-for-word match to Kazakhstan's Art. 11(3) and Tajikistan's Art. 11, a pattern that reads as a shared CIS-region model-law lineage rather than coincidence, confirmed against all three texts.

Art. 17 makes the domestic database at Art. 12 an explicit precondition for any cross-border transfer, not merely an alternative to it, the clearest statement of that relationship anywhere in this batch; Arts. 12 and 17 are verified word for word against the official source, and the cross-border restriction is moderate on the transfer article's own terms, not by analogy to the rest of the batch: Art. 17(3) supplies four fallback grounds for a non-protecting destination (written consent, a ratified treaty, statutory necessity, or protection of life, health, or other legitimate interests where consent cannot be obtained), the same shape as Kazakhstan's Art. 16(3), not Azerbaijan's narrower two-ground override with no contract, BCR, or permit route that earns Azerbaijan's strict coding.

A strict reading does not fit Art. 17's actual conditions, even as a description of the storage duty alone, since Kazakhstan's textually identical unconditional Art. 12(2) storage duty is moderate for the same reason.

Turkmenistan is also the batch's clearest duty-with-no-regulator finding, confirmed at primary source: Art. 28(2) gives the Cabinet of Ministers only a discretionary power, not an obligation, to establish a dedicated protection authority, and no located source confirms that power has ever been exercised; secondary reporting describes practical enforcement of this Act as essentially nonexistent, the weakest framework reported among the Central Asian states in this batch. No breach-notification duty was found in the text searched.

Biometric privacy

Law on Information About Private Life, biometric information

Law No. 519-V (20 March 2017), Arts. 1(1), 7(7), 11(2)official text, Human Rights Ombudsman of Turkmenistan (converted from the site's RTF publication)

In force since 1 July 2017. Binds public and private bodies.

What this law does

Biometric data sits outside the Art. 21 special-category list and is instead governed by three scattered provisions. Art. 1(1) defines it generally, with no illustrative list: information characterizing the physiological and biological features of a person and permitting establishment of the identity of the person. Art. 11(2) makes biometric data, along with data held in electronic information resources generally, automatically confidential and limited to the purpose for which it was collected.

Art. 7(7) defers the specifics of biometric information collection and processing entirely to unnamed other Turkmen legislation, the same deferral pattern this batch also finds word for word in Kazakhstan's Art. 11(3) and Tajikistan's Art. 11.

What it requires

Comprehensive regime

Law on Information About Private Life, comprehensive regime

Law No. 519-V (20 March 2017), in force 1 July 2017, Arts. 1, 6-9official text, Human Rights Ombudsman of Turkmenistan (converted from the site's RTF publication)

In force since 1 July 2017. Binds public and private bodies.

What this law does

Law No. 519-V applies to the operator, defined broadly to include state bodies and other legal or physical persons collecting, processing, or protecting personal information, and to the third party.

Art. 7 requires the subject's written consent for collection and processing, bars purpose expansion without further consent, requires no license or permit of the operator, requires operator staff to notify their supervisors before beginning collection or processing, and bars an operator from subcontracting collection or processing duties by contract, a restriction not seen elsewhere in this batch.

Art. 8 sets consent form requirements (written, electronic document, or another compatible method) and a revocation right, subject to exceptions not fully extracted. Art. 6 splits personal information into publicly available and restricted-access categories by accessibility.

What it requires

Cross border transfer

Law on Information About Private Life, localization and cross-border transfer

Law No. 519-V (20 March 2017), Arts. 12, 17official text, Human Rights Ombudsman of Turkmenistan (converted from the site's RTF publication)

In force since 1 July 2017. Binds public and private bodies.

What this law does

Art. 12(2) is an unconditional domestic-storage duty, with no citizen-only qualifier and no sectoral limitation: storage of personal information is carried out in a database of personal information located in the territory of Turkmenistan. Art. 17, read in full, makes the domestic database an explicit precondition for any transfer, not merely an alternative to it: personal information is subject to cross-border transfer only where it is contained in a database located in Turkmenistan.

Transfer to a state ensuring protection is then permitted; where the destination does not, transfer may still occur on written subject consent, a ratified treaty, statutory necessity, or protection of vital interests or constitutional rights where consent cannot be obtained. No enforcement history for either duty was found; secondary reporting describes practical enforcement of this Act generally as essentially nonexistent.

What it requires

Enforcement supervision

Law on Information About Private Life, enforcement

Law No. 519-V (20 March 2017), Arts. 28(2), 29, 31, 32official text, Human Rights Ombudsman of Turkmenistan (converted from the site's RTF publication)

In force since 1 July 2017. Binds public and private bodies.

What this law does

Art. 28(2), read in extract, gives the Cabinet of Ministers of Turkmenistan only a discretionary power ("may," not "shall" or "must") to establish an authorized body for the protection of subjects' rights and determine its status and powers; no located source confirms that power has ever been exercised.

Absent that, Art. 29 assigns generic state bodies, within their existing competence, the powers to draft implementing regulations, hear complaints, and take measures to hold violators liable as established by other Turkmen law. Art. 31, read in full, is a single bare sentence naming no fine schedule, no authority, and no private cause of action. Art. 32 provides that disputes are resolved in the manner established by Turkmen legislation, again naming no forum.

Secondary reporting describes the Cabinet of Ministers and the Prosecutor General's Office as the de facto oversight bodies, with penalties described as very low and practical enforcement as essentially nonexistent, the weakest data-protection framework reported among the Central Asian states in this batch.

What it requires

Sensitive categories

Law on Information About Private Life, special categories of personal information

Law No. 519-V (20 March 2017), Art. 21official text, Human Rights Ombudsman of Turkmenistan (converted from the site's RTF publication)

In force since 1 July 2017. Binds public and private bodies.

What this law does

Art. 21, read in full, prohibits by default processing data concerning nationality, skin color, attitude toward religion, political convictions, state of health, or intimate life.

The prohibition lifts for written subject consent, publicly available data, health necessity to protect vital interests where consent is unobtainable, medical purposes by a professional bound to confidentiality, processing by an association or religious organization of its own members' data, necessity for the administration of justice, or operational-investigative activity and criminal-sentence enforcement.

Biometric data is not among the Art. 21 categories; it is governed separately, see the biometric_privacy instrument for this jurisdiction.

What it requires

Scraping law2 instruments, 2 in force

Research summary (185 words)

Turkmenistan has no scraping-specific statute; the Criminal Code's computer-information chapter is the only law reaching a scraper's own conduct, and it turns on the information being protected by law rather than on a contract, a terms-of-service term, or a robots.txt directive being breached.

Article 373 punishes illegal access to information stored on electronic media, an information system, or an information-telecommunication network where the information is protected by law, with a higher tier where the target is a national information source or a critical information-communication infrastructure object.

Article 379 separately punishes creating, using, or distributing a program that disrupts the normal operation of a computer, subscriber device, or information system, or unlawfully destroying, blocking, reformatting, or copying legally protected information.

No Turkmen court decision, terms-of-service enforceability rule, text-and-data-mining exception, database right, personal-data reach over scraped public data, unfair-competition doctrine, or robots.txt-specific rule was found: the 2014 Law on Legal Regulation of the Development of the Internet and Rendering of Internet Services, the one further lead for this topic, shows only its definitions article in the free portion of its only available copy, a subscription legal database.

Computer misuse

Criminal Code, malicious programs

Criminal Code of Turkmenistan, art. 379 (Law No. 456-VI of 17 April 2022, new redaction, in force 1 January 2023)official consolidated text of the Criminal Code of Turkmenistan, Human Rights Ombudsman of Turkmenistan

In force since 1 January 2023. Binds public and private bodies.

What this law does

Article 379(1) punishes the unlawful destruction of legally protected information in an information system or passing through an information-telecommunication network, the creation of a computer program intended to disrupt the normal operation of a computer, a subscriber device, another computer program, an information system, or an information-telecommunication network, and, separately, the production of, or unauthorized alteration, blocking, reformatting, or copying of, such information or software, along with the deliberate use or distribution of a program built for that purpose.

Article 379(2) raises the penalty where the act targets a national information source, the national information system, or a critically important information-communication infrastructure object, or is committed using one's official position. Article 379(3) raises it further where the acts caused grave consequences or were committed by a group by prior conspiracy or an organized group.

What it requires

Criminal Code, unlawful access to an information system

Criminal Code of Turkmenistan, art. 373 (Law No. 456-VI of 17 April 2022, new redaction, in force 1 January 2023)official consolidated text of the Criminal Code of Turkmenistan, Human Rights Ombudsman of Turkmenistan

In force since 1 January 2023. Binds public and private bodies.

What this law does

Article 373(1) punishes illegal access to information stored on electronic media and protected by law, to an information system, or to an information-telecommunication network, where the access substantially violates the rights or legitimate interests of a person or the protected interests of society or the state.

Article 373(2) raises the penalty where the same acts target sources of national electronic information, the national information system, or important information-communication infrastructure objects. Article 373(3) raises it further where either act negligently caused grave consequences or was committed by a group by prior conspiracy or an organized group.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (538 words)

Two bare-title leads for this jurisdiction, a "Law on Cybersecurity" and a "Law on Legal Regulation of the Internet Development and Internet Services in Turkmenistan," were checked against the Mejlis (Parliament) of Turkmenistan's own official legislation database at mejlis.gov.tm, which serves a machine-readable list of 370 laws spanning 1990 through its most recent entry of 22 November 2025 and was searched for every plausible Russian-language rendering of "cybersecurity" (кибербезопасность, кибер, информационная безопасность, критическая инфраструктура) with no result.

No standalone Law on Cybersecurity was located, and the second title is this jurisdiction's Law No. 159-V "On the Legal Regulation of the Development of the Internet Network and the Provision of Internet Services in Turkmenistan" (20 December 2014, last amended 22 November 2025), which was located, read in full, and imposes no product- or system-security duty.

Its Art. 12(1)(4¹) duty for an internet-service operator to "ensure users of the internet network with an externally protected internet network" is undated, unspecific, and, given Turkmenistan's documented internet-filtering practice, at least as plausibly a content-control duty as a cybersecurity one, so it is named here rather than coded as an instrument.

Two other statutes, located and read in full through the same official source, do impose an operator-facing security duty and are coded below: the Law "On Information and Its Protection" (No. 72-V, 3 May 2014) requires the possessor of information and the operator of an information system, in cases set by other Turkmen legislation, to maintain six specific technical and organizational safeguards against unauthorized access (Art. 15(4)); and the Law "On Communications" (No. 93-IV, 12 March 2010) requires a communications operator to implement technical and organizational protection of communication networks and facilities (Art. 18(4)) and to safeguard the confidentiality and integrity of subscriber data during automated processing (Art. 43).

Neither statute sets a security standard a software product or connected device must meet before being placed on the market, and neither creates a reporting duty running to an authority or to users on any clock.

The Ministry of Communications' own enumerated competence includes licensing "activity in the field of communications and cybersecurity" (Communications Law Art. 8(1)(11)), which is affirmative evidence that Turkmenistan regulates cybersecurity as a licensed activity somewhere in its legislation, most plausibly by Cabinet of Ministers resolution rather than by a Mejlis-enacted Law; that implementing act was not located and is recorded as an open question rather than assumed.

The Criminal Code's unauthorized-access and malicious-program offenses, and the Internet Law's parallel liability provisions for a user's unauthorized intrusion into an information system (Art. 30(9)) or creation of malicious programs (Art. 30(11)), bind the intruder rather than the operator and belong to this jurisdiction's scraping-topic material, not repeated here.

Turkmenistan's comprehensive personal-information statute, the Law "On Information About Private Life and Its Protection" (No. 519-V, 20 March 2017), is this jurisdiction's privacy-topic instrument; no breach-notification duty was found in it, and any security-of-processing content it carries is documented there rather than here.

The Russian-language texts used for both instruments below are the Mejlis's own official Turkmen-to-Russian translations, published on its statutory-text pages rather than as an RTF file, which is why verbatim quotes are pinned below where the privacy-topic instruments for this jurisdiction, sourced to an unparsed RTF file, carry none.

Sector security regimes

Law on Communications, network and subscriber-information protection duties

Law of Turkmenistan No. 93-IV "On Communications" (Vedomosti Mejlisa Turkmenistana 2010, No. 1, art. 17; as last amended by Law No. 184-VII of 22 November 2025), arts. 18, 43Official text, Mejlis (Parliament) of Turkmenistan

In force since 12 March 2010. Binds public and private bodies.

What this law does

A communications operator (a category that under this Act may be a state entity or a legal or natural person) must implement technical and organizational methods to protect communication networks, telecommunications facilities, restricted-access information about the organization of communication networks, and information transmitted by those networks.

The operator must, together with law-enforcement bodies, protect communication facilities and structures from unauthorized access, and a developer building or reconstructing communication facilities must likewise provide for protection against unauthorized access. Separately, a communications operator must ensure and bear responsibility for the safekeeping of subscriber information obtained on contracting and about services rendered, including duration, content, and routing.

The operator must also protect that information during automated processing. The Ministry of Communications of Turkmenistan exercises general regulatory and licensing authority over the sector, including, by its own Art. 8(1)(11), licensing of activity in the field of communications and cybersecurity, though no separate implementing act setting cybersecurity licensing requirements was located.

Neither Art. 18 nor Art. 43 states a fixed penalty; a violation carries liability under other Turkmenistan legislation the Act does not itself quantify.

What it requires

Security baseline statutes

Law on Information and Its Protection, information-security duty

Law of Turkmenistan No. 72-V "On Information and Its Protection" (Vedomosti Mejlisa Turkmenistana 2014, No. 2, art. 72; as amended by Laws No. 234-VI of 14 March 2020, No. 390-VI of 5 June 2021, and No. 445-VI of 18 December 2021), art. 15Official text, Mejlis (Parliament) of Turkmenistan

In force since 3 May 2014. Binds public and private bodies.

What this law does

A possessor of information (defined to include the state and any natural or legal person of Turkmenistan) and an operator of an information system must, in cases established by Turkmenistan legislation, maintain safeguards that prevent unauthorized access to information and its transfer to a person without a right of access.

The same duty requires the possessor or operator to detect unauthorized access in a timely manner, prevent adverse consequences of a breach of access procedure, prevent disruption of the technical means that process the information, permit immediate restoration of information altered or destroyed through unauthorized access, and continuously monitor the level of the information's protection.

The Act does not itself identify which other legislation triggers this duty for a given information holder outside the state-information-system context it separately regulates. A person whose rights were violated by disclosure or other unlawful use of restricted-access information may sue for damages, moral-harm compensation, and vindication of honor and dignity, though that claim is barred against a plaintiff who did not itself meet its own confidentiality or protection obligations.

Violation of the Act's requirements carries liability under other Turkmenistan legislation, which this Act does not itself quantify.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (220 words)

Turkmenistan has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of Law No. 257-IV of 10 January 2012, on Copyright and Related Rights, is the only law reaching an aggregator's reproduction of news content. Article 7 excludes “reports of events and facts of an informational character” from copyright protection outright, so a bare news item is never a protected work regardless of who first published it.

Article 19 separately permits, without the rightholder's consent or payment, quoting lawfully published works for informational purposes including press-review excerpts of newspaper and magazine articles (para. 1), and reproducing or broadcasting lawfully published newspaper and magazine articles on current economic, political, social, and religious topics unless the author or rightholder has specifically prohibited that reproduction (para. 3).

Neighbouring rights under the Act protect performers, phonogram producers, and broadcasting organisations rather than news publishers, so there is no publisher-side right of the kind the European Union's Digital Single Market Directive Article 15 creates, no hot-news or misappropriation doctrine distinct from ordinary copyright, and no machine-readable text-and-data-mining opt-out mechanism; database compilations are protected only as copyrightable compilations under Articles 6 and 21, with no separate sui generis database right; no reported Turkmen decision applies either free-use provision to a systematic online news aggregator as opposed to a traditional press review.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.