Uzbekistan approves adequacy list of 49 countries for cross-border personal data transfers
Cabinet of Ministers Resolution No. 415, signed on 29 July 2026, approves a list of 49 foreign states and territories whose level of personal data protection is deemed equivalent to Uzbekistan's own standards. The resolution implements Article 27¹ of the Law on Personal Data, a provision introduced by legislative amendments the President signed on 26 March 2026 and which entered into force on 27 March 2026. This adequacy list is the operational mechanism that determines whether personal data can move across Uzbekistan's borders automatically or only under additional safeguards, and it applies to every company that processes and transfers personal data connected to Uzbekistan.
The underlying legal basis: what Article 27¹ established
The March 2026 amendments created a clear data localisation and cross-border transfer regime. Three categories of personal data must be stored within Uzbekistan without exception: biometric data, genetic data, and data of individuals who are users of telecommunications operators active in Uzbekistan.
All other personal data may be stored and processed abroad, but only where one of three conditions is met: the destination country is recognised as providing an equivalent level of personal data protection, the operator adopts standard contractual clauses or binding corporate rules meeting requirements set by the competent authority, or the operator complies with a list of recognised international personal data management and storage standards approved by the competent authority. The amendments also narrowed the scope of data excluded from the Personal Data Law entirely, limiting the carve-out to state secrets and information related to defence and national security matters.
Resolution No. 415 operationalises the first of these three conditions by approving the actual list of countries recognised as equivalent.
Three tiers of cross-border data transfer
Building on this legal basis, the resolution establishes a practical three-tier structure for cross-border transfers.
For the 49 listed countries, personal data and anonymised data may be transferred automatically through information systems established under international agreements, without additional authorisation and without notifying the competent authority, provided the operator has taken measures to prevent data leakage.
For any country not on the list, transfer is permitted only where the operator and data controller comply with legal, organisational and technical conditions set by the competent authority, corresponding to the second and third conditions under Article 27¹: approved standard contractual clauses or binding corporate rules, or compliance with recognised international data management standards. The Ministry of Internal Affairs, together with the Ministry of Digital Technologies, the State Security Service and the National Agency for Prospective Projects, has three months from the resolution's signing to approve the specific requirements for these safeguards.
Breach notification obligations apply regardless of destination country. Where a data leakage is identified during cross-border transfer, the database operator must notify the competent authority within 24 hours of discovery, and provide a detailed report on the causes of the leakage and remedial measures taken within 72 hours.
Competent authority and list maintenance
The Migration and Personalisation Department under the Ministry of Internal Affairs is designated as the competent authority responsible for preparing proposals to add or remove countries from the list, and must publish the list on its official website within one week of the resolution's signing. The list is not static and may be revised over time.
Separately, the resolution instructs the Ministry of Foreign Affairs, together with the Ministry of Internal Affairs, to work within three months toward Uzbekistan's own accession to the 1981 Strasbourg Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, and to submit proposals for Uzbekistan's own inclusion on other countries' adequacy lists. This signals an intention to pursue reciprocal recognition rather than a purely unilateral framework.
The adequacy list
The 49 jurisdictions on the list are:
Andorra, Argentina, Austria, Belgium, Bulgaria, Brazil, Canada, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Faroe Islands, Finland, France, Germany, Greece, Guernsey, Hong Kong, Hungary, Iceland, Ireland, Isle of Man, Israel, Italy, Japan, Jersey, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Netherlands, New Zealand, Norway, Poland, Portugal, Romania, Russia, Singapore, Slovakia, Slovenia, South Korea, Spain, Sweden, Switzerland, United Kingdom, United States, and Uruguay.
The United States entry carries a specific qualification: it applies only to companies operating within the framework of the EU-US Data Privacy Framework, not to the United States as a whole. This mirrors the approach taken by the European Union itself, whose own US adequacy decision is similarly scoped to Data Privacy Framework participants.
Notable composition of the list
The list closely mirrors the European Union and European Economic Area's own adequacy decisions, covering all EU member states, the UK, Switzerland, and other European jurisdictions traditionally recognised as adequate under the EU General Data Protection Regulation framework. Beyond Europe, the list includes Japan, South Korea, Singapore, Hong Kong, Canada, New Zealand, Israel, Argentina, Brazil, Uruguay and Russia.
Some notably absent jurisdictions, at least as of this resolution, include China, the UAE and other Gulf states, India, Turkey, and most Central Asian neighbours. Companies with data flows to or from these jurisdictions will need to rely on the conditional transfer mechanism once the underlying contractual and corporate rule requirements are published, rather than benefiting from automatic transfer.
What this means for your business
This resolution gives international companies operating in Uzbekistan, or transferring Uzbekistan-linked personal data abroad, a concrete and immediately usable framework, closing a gap that has existed since the March 2026 amendments created the adequacy mechanism without yet naming any qualifying countries.
Companies headquartered or processing data in any of the 49 listed jurisdictions, including most of Western and Central Europe, the UK, the US under the Data Privacy Framework, Japan, South Korea, Singapore, Canada and Israel, can transfer personal data to and from Uzbekistan without additional authorisation, provided they maintain reasonable safeguards against data leakage. Biometric data, genetic data and telecom user data remain subject to mandatory local storage regardless of destination country.
Companies whose data flows involve jurisdictions outside the list, including China, the Gulf states, India and Turkey, will need to prepare for a conditional compliance regime once the Ministry of Internal Affairs publishes the specific requirements for standard contractual clauses, binding corporate rules and recognised international standards, expected within three months of the resolution. Multinational companies with complex data architectures spanning both listed and non-listed jurisdictions should map their current data flows against this list now to identify where additional contractual safeguards will be needed.
The 24-hour and 72-hour breach notification deadlines are demanding by regional standards and apply irrespective of which tier of transfer is involved. Companies should review their incident response procedures to confirm they can meet these timelines in practice, not just on paper.
Finally, the government's stated intention to pursue Strasbourg Convention accession and reciprocal adequacy recognition abroad suggests this framework will continue to evolve, and companies should expect further refinement of both the list and the conditional transfer requirements over the coming months.
Get in touch to discuss what these changes mean for your operations.