Law / Uzbekistan

Uzbekistan

14 of 18 named instruments researched to a stage, across all six areas of law we track: 14 in force. As of 18 September 2026.

When they take effect14 of 14 carry a date. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 2 instruments (2 in force) 2019: 7 instruments (7 in force) 2020: 0 instruments ’20 2021: 0 instruments 2022: 2 instruments (2 in force) 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 1 instrument (1 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law 3
  5. Age gating law 2
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (194 words)

Law No. ZRU-1115 (21 January 2026) amended the Law on Informatization (Law No. 560-II, 11 December 2003) to define artificial intelligence in Art. 3 and to add Art. 7-1, which bars an information resource created using artificial intelligence, or an information system that functions on artificial-intelligence technology, from harming a person's life, health, freedom, honor, or dignity, and bars a legally significant decision affecting a person's rights or freedoms from resting exclusively on such a resource's or system's conclusions.

The Presidential Resolution approving the Strategy for the Development of Artificial Intelligence Technologies until 2030 (Resolution No. RP-358, 14 October 2024, in force 17 October 2024) sets government targets, an action plan, and a list of state-sector big-data sources, and states no duty running to a private developer or operator.

Ministerial ethics rules for the development and use of AI-based solutions, reported to enter into force on 17 June 2026, are not confirmed in a primary source and are not described further here. The same 21 January 2026 amending law also added an administrative fine for illegal processing of personal data using artificial-intelligence technologies, which is addressed under this jurisdiction's privacy findings rather than here.

AI risk obligations

Law on Informatization, use of artificial intelligence in information resources and systems

Law No. 560-II (11 December 2003) "On Informatization," Arts. 3, 7-1, as added by Law No. ZRU-1115 (21 January 2026)consolidated text of the Law on Informatization

In force 8 months, effective 21 January 2026. Binds public and private bodies.

What this law does

Article 7-1, inserted into the Law on Informatization by Law No. ZRU-1115 (21 January 2026), reaches any information resource created using artificial intelligence and any information system that functions on artificial-intelligence technology. Such a resource or system must not harm a person's life, health, freedom, honor, or dignity, or violate the person's other inalienable rights.

A legally significant decision affecting a person's rights or freedoms may not rest exclusively on the conclusions of an information resource or system built on artificial-intelligence technology.

What it requires

Privacy law6 instruments, 6 in force

Research summary (195 words)

Uzbekistan's Law No. ZRU-547 "On Personal Data" (2 July 2019, in force 1 October 2019) governs the owner, operator, and third party generally, requiring subject consent for most processing and treating special personal data (Art. 25) and biometric or genetic data (Art. 26) as two separate, dedicated tracks rather than folding one into the other.

A January 2021 amendment, in force April 2021, added Art. 27-1, a citizen-specific localization duty: personal data of Uzbek citizens processed over the internet must be collected, systematized, and stored on technical means physically located in Uzbekistan and registered in the State Register of Personal Data Bases, distinct from and narrower than Kazakhstan's unqualified equivalent.

This is the batch's one jurisdiction with documented enforcement of its localization rule: several major platforms, including Facebook, Telegram, and TikTok, were blocked in 2021 for failing to store Uzbek users' data domestically, though some were later unblocked.

The Act carries no breach-notification duty of any kind (the dedicated security article, Art. 27, was read in full and contains none, corroborated independently), and Art. 33's enforcement provision is a single bare liability sentence naming no authority, no penalty schedule, and no private right of action.

Biometric privacy

Law on Personal Data, biometric and genetic data

Law No. ZRU-547 (2 July 2019), Art. 26official text, lex.uz, Uzbekistan's official legislation portal

In force since 1 October 2019. Binds public and private bodies.

What this law does

Art. 26 defines biometric data generally as data characterizing anatomical and physiological characteristics, and genetic data as data from analysis of biological material, with no illustrative list naming face, voice, or fingerprint.

Biometric and genetic data used for identification may be processed only with the subject's consent, except for treaty implementation, administration of justice, or enforcement proceedings, and electronic biometric or genetic data stored outside an information system must be kept on media that exclude unauthorized access. No retention or destruction duty specific to biometric data was found in this article or elsewhere in the Act.

What it requires

Comprehensive regime

Law on Personal Data, comprehensive regime and lawful bases

Law No. ZRU-547 (2 July 2019), Arts. 1-14, 18-23, 28, 30-31official text, lex.uz, Uzbekistan's official legislation portal

In force since 1 October 2019. Binds public and private bodies.

What this law does

Law No. ZRU-547 reaches the owner, operator, and third party generally, with no public and private carve-out found in the articles read. Processing generally requires the subject's consent (Art. 21 sets the procedure for giving and revoking it), subject to statutory exceptions not read article by article.

What it requires

Cross border transfer

Law on Personal Data, cross-border transfer and citizen data localization

Law No. ZRU-547 (2 July 2019), Art. 15; Art. 27-1 (added 2021, in force April 2021)official text, lex.uz, Uzbekistan's official legislation portal

In force since 1 October 2019. Binds public and private bodies.

What this law does

Art. 15 permits cross-border transfer where the destination state ensures adequate protection, or, where it does not, on subject consent, statutory necessity, or an international treaty; transfer may also be restricted for constitutional-order, morality, health, rights, defense, or state-security reasons.

Art. 27-1, added by a 2021 amendment reported in force April 2021, is narrower and separate: when processing the personal data of citizens of Uzbekistan using information technologies, including the internet, the owner or operator must collect, systematize, and store that data on technical means physically located in Uzbekistan and register the database in the State Register of Personal Data Bases.

Enforcement of Art. 27-1 is documented: the State Inspectorate for Control in the Sphere of Informatization and Telecommunications blocked Twitter, TikTok, VKontakte, Skype, and WeChat in July 2021, and Facebook, Instagram, LinkedIn, Odnoklassniki, Telegram, and YouTube in November 2021, citing failure to store Uzbek users' data domestically; several were later unblocked, and TikTok was reported still restricted as of the most recent secondary reporting located.

What it requires

Data subject rights

Law on Personal Data, data subject rights

Law No. ZRU-547 (2 July 2019), Art. 30official text, lex.uz, Uzbekistan's official legislation portal

In force since 1 October 2019. Binds public and private bodies.

What this law does

Art. 30 gives the subject the right to know that an owner, operator, or third party holds their data, obtain processing information on request, obtain information on access conditions, apply to the authorized state body or a court for protection of rights, give and withdraw consent, consent to inclusion in public sources, and require temporary suspension of processing where data is incomplete, outdated, or unreliable. Most, not all, of the article was extracted for this brief.

What it requires

Enforcement supervision

Law on Personal Data, enforcement

Law No. ZRU-547 (2 July 2019), Art. 33official text, lex.uz, Uzbekistan's official legislation portal

In force since 1 October 2019. Binds public and private bodies.

What this law does

Art. 33, the Act's only enforcement provision, is a bare reference clause: persons violating the legislation on personal data are liable in the manner prescribed by law, with no penalty schedule, no named authority, and no private right of action stated in the Act itself. The Act refers to an authorized state body fourteen times but never names it in the text read; substantive penalties and the body's identity live in legislation the Act does not name and that is not identified here.

What it requires

Sensitive categories

Law on Personal Data, special personal data

Law No. ZRU-547 (2 July 2019), Art. 25official text, lex.uz, Uzbekistan's official legislation portal

In force since 1 October 2019. Binds public and private bodies.

What this law does

Art. 25 prohibits processing special personal data by default: racial or social origin, political, religious, or ideological beliefs, political-party or trade-union membership, physical or mental health, private life, and criminal record.

Processing is permitted only for state-security purposes by the authorized state body, on the subject's written or electronic consent, or where the subject has already published the special data in publicly available sources; this is a distinct track from Art. 26's biometric and genetic data, not a category that folds biometric data into it.

What it requires

Scraping law1 instrument, 1 in force

Research summary (158 words)

Uzbekistan has no scraping-specific statute, so general law governs each dimension separately, and only the personal-data dimension is described here.

Article 29 of the Law on Personal Data (Law No. ZRU-547, 2 July 2019) defines publicly available personal data as data that is freely accessible with the subject's consent or that is not subject to a confidentiality requirement, and the Act's general lawful-basis and consent duties apply without a stated carve-out for the collection method, so an operator scraping personal data from a public Uzbek source is reached the same way as one collecting it by any other means.

The Law on Informatization's Art. 23 liability clause cross-references a chapter of the Criminal Code addressing unauthorized access to computer information, but the chapter's substantive articles were not established here, so no computer-misuse instrument is recorded. Terms-of-service enforceability, a copyright or text-and-data-mining exception, a database right, an unfair-competition or misappropriation doctrine, and robots.txt's legal weight are not described here.

Personal data

Law on Personal Data, publicly available personal data

Law No. ZRU-547 (2 July 2019), Art. 29official text, lex.uz, Uzbekistan's official legislation portal

In force since 1 October 2019. Binds public and private bodies.

What this law does

Article 29 of the Law on Personal Data defines publicly available personal data as data access to which is free with the subject's consent or which is not subject to a confidentiality requirement.

The Act's general consent and lawful-basis duties, read elsewhere in the Act, are not stated to turn on how the operator collected the data, so a public Uzbek source's data reached by crawling or scraping falls within the same regime as data collected by any other means, unless it independently qualifies as publicly available personal data under Art. 29.

What it requires

Cybersecurity law3 instruments, 3 in force

Research summary (329 words)

Uzbekistan's Law No. O'RQ-764 "On Cybersecurity" (15 April 2022, in force 17 July 2022) is a standalone, eight-chapter statute binding any legal entity or individual entrepreneur that owns, uses, or provides electronic information services over national information resources: it requires notifying the State Security Service of cybersecurity incidents and cybercrimes as they occur, preserving the incident's digital evidence, and complying with the cybersecurity requirements the Service sets, all without a numeric reporting clock or severity threshold in the statute's own text.

Certification of security-related hardware and software and the compliance expertise the same Law provides for (Arts. 17-21) are mandatory only for government information resources and systems and for objects classified as critical information infrastructure, running only at an operator's own request otherwise, so the Law sets no general product-security requirement reaching a software product or connected device before or after market placement.

The Law's critical-infrastructure chapter (Arts. 25-31) layers a categorization scheme and a registry onto energy, defense, banking, healthcare, and similar strategic operators, but the categorization criteria and the registry procedure are left entirely to the State Security Service's own subordinate acts, so no instrument is filed here for that regime under the deferred-sector-regime rule.

The older Law on Informatization (No. 560-II, 11 December 2003, as amended) adds a thinner general duty at Arts. 19-20: protection is mandatory only for information resources and systems containing state secrets or confidential information, with the Cabinet of Ministers setting that procedure, while an owner of any other information resource or system sets its own protection procedure with no external floor.

The Cybersecurity Law's Art. 37 refers violations generically to the Code of Administrative Liability (Arts. 155, 202-2) and the Criminal Code (Ch. XX-1) rather than stating its own penalty amounts, no private right of action or published enforcement record was found, and Uzbekistan's comprehensive privacy statute, Law No. ZRU-547 "On Personal Data," researched on the privacy topic, carries no breach-notification duty at all in its own security article, Art. 27.

Security baseline statutes

Law on Cybersecurity, general cybersecurity duties on cybersecurity subjects

Law No. O'RQ-764 (15 April 2022) "On Cybersecurity," Arts. 3, 16, 37official statute text, lex.uz, Uzbekistan's national legislation database

In force since 17 July 2022. Binds private bodies.

What this law does

Any legal entity or individual entrepreneur that owns, uses, or disposes of national information resources, or that provides electronic information services using them, is a "cybersecurity subject" under the Law and must prevent unlawful disclosure, theft, loss, corruption, blocking, or falsification of data in its information systems and resources, and act promptly when such a case is detected.

It must comply with the cybersecurity requirements the State Security Service sets for protecting information systems and resources, and must keep a functioning capability to respond to cybersecurity incidents, using an outsourced provider with the State Security Service's authorization if it has none of its own. The Law defines no general standard of "reasonable" security beyond compliance with the requirements the State Security Service itself sets.

What it requires

Law on Informatization, information security duty for information resource and system owners

Law No. 560-II (11 December 2003) "On Informatization," Arts. 19-20official statute text, lex.uz, Uzbekistan's national legislation database

In force since 11 February 2004. Binds public and private bodies.

What this law does

State bodies, legal entities, and individuals must protect information resources and information systems that contain state secrets or confidential information; the Cabinet of Ministers sets the procedure for that protection. For any other information resource or system whose improper handling could harm its owner or another party, the owner or holder sets its own protection procedure, and the Law states no external minimum standard for it.

The Law's own general-responsibility clause (Art. 23) refers a violation to liability "in accordance with the established procedure" without naming an authority or a penalty.

What it requires

Vulnerability and incident reporting

Law on Cybersecurity, cybersecurity incident notification duty

Law No. O'RQ-764 (15 April 2022) "On Cybersecurity," Arts. 3, 16, 22-24official statute text, lex.uz, Uzbekistan's national legislation database

In force since 17 July 2022. Binds private bodies.

What this law does

A "cybersecurity subject," defined as any legal entity or individual entrepreneur that owns, uses, or disposes of national information resources, or that provides electronic information services using them, must notify the State Security Service of cybersecurity incidents and cybercrimes as they occur, take measures to prevent the loss of digital evidence needed to fully expose the incident, and keep the records needed to analyze it.

The Law sets no numeric reporting deadline and no severity or materiality threshold for this duty. Where the affected resource's owner has the resources and technical means to investigate the incident itself, it may do so, but must then report the results to the State Security Service.

What it requires

Age gating law2 instruments, 2 in force

Research summary (198 words)

Uzbekistan's Law No. ZRU-444 "On the protection of children from information harmful to their health" (8 September 2017, in force 10 March 2018) requires the producer or distributor of an information product, defined to include material distributed using software or placed on the worldwide information network Internet, to self-classify it, if necessary with expert help, before its circulation begins in Uzbekistan, assigning one of five age categories from "0+" to "18+" (Art. 17).

Article 16 separately identifies a category of content barred from distribution to children outright, including material of a pornographic character, regardless of any age-category marking, and a narrower category restricted by age rather than barred outright.

Articles 18 and 19 direct the Cabinet of Ministers to set the administrative, organizational, hardware and software measures for protecting children from harmful information, bar circulating such information in public places without those measures, require printed material carrying it to be sold only in sealed packaging, and bar its distribution in institutions intended for children.

Article 24, the Act's only enforcement provision, states liability in general terms without a penalty schedule or a named enforcing authority. No dedicated app-store age-verification statute or standalone social-media minor-access statute has been located.

Adult content age verification (AV)

Law on Protection of Children from Harmful Information, prohibition on distributing content harmful to children

Law No. ZRU-444 (8 September 2017), Art. 16consolidated text of Law No. ZRU-444, lex.uz, Uzbekistan's official legislation portal

In force since 10 March 2018. Binds public and private bodies.

What this law does

Article 16 defines information harmful to children's health as an information product barred from distribution to children altogether, or one whose distribution to children of certain age categories is restricted.

The categories barred outright include material inciting self-harm or suicide, material capable of inducing children to use alcohol, tobacco, narcotic or psychotropic substances, gamble, engage in prostitution, vagrancy or begging, material justifying violence and cruelty, material denying family values or fostering disrespect toward parents, obscene language, and material of a pornographic character, alongside identifying information about a child victim of an unlawful act.

A second, narrower category restricted by age rather than barred outright covers depictions of cruelty or antisocial acts, material inducing fear or panic, and depictions of sexual relations between a man and a woman, which fall under Article 17's age-tiered classification instead.

Note and primary source

Age-appropriate design code

Law on Protection of Children from Harmful Information, age classification and circulation requirements

Law No. ZRU-444 (8 September 2017), Arts. 4, 17-19consolidated text of Law No. ZRU-444, lex.uz, Uzbekistan's official legislation portal

In force since 10 March 2018. Binds public and private bodies.

What this law does

Article 4 defines an information product to include material distributed using software or placed in telecommunications networks, including the worldwide information network Internet, so an online service reached by children is covered on the same footing as printed, audiovisual or broadcast media.

Article 17 requires the producer or distributor to determine an information product's age classification, if necessary with expert help, before its circulation begins in Uzbekistan, assigning it one of five categories marked "0+", "7+", "12+", "16+" or "18+" based on its theme, genre, content and artistic design, how a child of the relevant age is likely to perceive it, and the likelihood of harm to a child's health.

Articles 18 and 19 direct the Cabinet of Ministers to set the administrative, organizational, hardware and software measures for protecting children from harmful information, bar its circulation in public places without those measures, require printed material carrying it to be sold only in sealed packaging, and bar its distribution in institutions intended for children.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (159 words)

Uzbekistan has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the Law on Copyright and Related Rights (Law No. ZRU-42, 20 July 2006, in force 21 July 2006) is the primary instrument reaching an aggregator's reproduction of news content.

Article 26's free-use exception, conditioned on naming the author and the source and on not harming the normal use of the work or infringing the author's legitimate interests, covers quoting a published work to the extent justified by the purpose of quotation, including reproducing excerpts from newspaper and magazine articles as press reviews, and separately permits reproducing whole newspaper or magazine articles on current political, economic, social or religious topics unless the author has specifically prohibited it, an author-side opt-out rather than a blanket licence.

Uzbekistan has no hot-news or misappropriation doctrine distinct from ordinary copyright law, no statute or case on whether a hyperlink is a communication to the public, and no text-and-data-mining opt-out reaching news content.

Snippet reproduction

Law on Copyright and Related Rights, quotation and news-article reproduction exceptions

Law No. ZRU-42 (20 July 2006), Art. 26unofficial English translation of Law No. ZRU-42, WIPO Lex

In force since 21 July 2006. Binds public and private bodies.

What this law does

Article 26 permits, with the author's name and the source of borrowing indicated and provided it does not harm the normal use of the work or infringe the author's legitimate interests, quoting a published work in the original or in translation for scientific, research, polemical, critical or non-promotional information purposes to the extent justified by the purpose of quotation, including reproducing excerpts from newspaper and magazine articles in the form of press reviews.

The same article separately permits reproducing in newspapers, or communicating by broadcast or cable, articles already published in newspapers or magazines on current political, economic, social or religious issues, or broadcast works of the same nature, unless the author has specifically prohibited such use, so the exception is an author opt-out rather than an unconditional licence. Article 26 carries no headline-length or short-extract cap distinct from the purpose-justified test in its own text.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.