Law note · Azerbaijan
Law on Personal Data, cross-border transfer
What it requires
- An app transferring the personal data of a person in Azerbaijan to a recipient outside Azerbaijan must ensure the destination provides legal protection at the level Azerbaijani law sets, unless the data subject has consented or the transfer is necessary to protect the subject's life or health, since Azerbaijan has no contract, binding-corporate-rule, or authority-permit route for a non-adequate destination.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometricsprocesses_voice
What we found
Transfer is the default rule under Art. 14.1, prohibited only where it threatens national security (Art. 14.2.1) or the destination country's law does not ensure legal protection at the level determined by the legislation of the Republic of Azerbaijan (Art. 14.2.2).
Art. 14.3 then creates a broad override: with the data subject's consent, or where necessary to protect the subject's life or health, transfer may proceed regardless of the destination's actual level of legal protection, meaning consent fully overrides the adequacy-style standard rather than merely supplementing it.
No standard-contract, binding-corporate-rule, or authority-permit mechanism exists for a non-adequate destination, unlike several regional peers' authority-approval or contract-approval routes; this is a noticeably thinner, more binary regime, coded strict at the jurisdiction level rather than moderate for that reason. No data localization is compelled.