Law on Information and Its Protection, information-security duty
Law of Turkmenistan No. 72-V "On Information and Its Protection" (Vedomosti Mejlisa Turkmenistana 2014, No. 2, art. 72; as amended by Laws No. 234-VI of 14 March 2020, No. 390-VI of 5 June 2021, and No. 445-VI of 18 December 2021), art. 15
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 3 May 2014.
A security baseline statutes rule binding public and private bodies.
As of 19 September 2026.
What it requires
- This duty binds the possessor of information and the operator of an information system only in cases established by Turkmenistan legislation elsewhere; the Act does not itself name those cases.
- Where the duty is triggered, maintain administrative, technical and organizational measures that: prevent unauthorized access to information and its transfer to a person without a right of access; detect an unauthorized access event in a timely manner; prevent adverse consequences from a breach of the access procedure; prevent disruption of the technical means used to process the information; permit immediate restoration of information altered or destroyed by unauthorized access; and continuously monitor the level of the information's protection.
- A person injured by disclosure or unlawful use of restricted-access information may sue for damages, moral-harm compensation, and protection of honor and dignity, but not if the plaintiff itself failed to meet its own confidentiality or information-protection obligations.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Who enforces it
Settledness
- As of
- 19 September 2026
- Open questions
- Which other Turkmen law or regulation designates the cases established by legislation that trigger the Article 15(4) duty for a given possessor of information or information-system operator?
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A possessor of information (defined to include the state and any natural or legal person of Turkmenistan) and an operator of an information system must, in cases established by Turkmenistan legislation, maintain safeguards that prevent unauthorized access to information and its transfer to a person without a right of access.
The same duty requires the possessor or operator to detect unauthorized access in a timely manner, prevent adverse consequences of a breach of access procedure, prevent disruption of the technical means that process the information, permit immediate restoration of information altered or destroyed through unauthorized access, and continuously monitor the level of the information's protection.
The Act does not itself identify which other legislation triggers this duty for a given information holder outside the state-information-system context it separately regulates. A person whose rights were violated by disclosure or other unlawful use of restricted-access information may sue for damages, moral-harm compensation, and vindication of honor and dignity, though that claim is barred against a plaintiff who did not itself meet its own confidentiality or protection obligations.
Violation of the Act's requirements carries liability under other Turkmenistan legislation, which this Act does not itself quantify.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Official text, Mejlis (Parliament) of Turkmenistan
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.