Law / Uzbekistan

Law on Cybersecurity, general cybersecurity duties on cybersecurity subjects

Law No. O'RQ-764 (15 April 2022) "On Cybersecurity," Arts. 3, 16, 37

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 17 July 2022.

A security baseline statutes rule binding private bodies.

As of 18 September 2026.

What it requires

  • Applies to any legal entity or individual entrepreneur that owns, uses, or disposes of national information resources, or that provides electronic information services using them.
  • Prevent unlawful disclosure, theft, loss, corruption, blocking, or falsification of data in your information systems and resources, and act promptly when such a case is detected.
  • Comply with the cybersecurity requirements the State Security Service sets for protecting information systems and resources.
  • Maintain a functioning capability to respond to cybersecurity incidents, or use an outsourced provider with the State Security Service's authorization if you have none of your own.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Article 37 refers a violation of the cybersecurity legislation generically to liability "in the established manner," which the statute's own official commentary at that article identifies as the Code of Administrative Liability (Arts. 155, 202-2) and the Criminal Code (Ch. XX-1); the Law itself states no maximum penalty for either track.

Who enforces it

Enforcement body

State Security Service of the Republic of Uzbekistan

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Any legal entity or individual entrepreneur that owns, uses, or disposes of national information resources, or that provides electronic information services using them, is a "cybersecurity subject" under the Law and must prevent unlawful disclosure, theft, loss, corruption, blocking, or falsification of data in its information systems and resources, and act promptly when such a case is detected.

It must comply with the cybersecurity requirements the State Security Service sets for protecting information systems and resources, and must keep a functioning capability to respond to cybersecurity incidents, using an outsourced provider with the State Security Service's authorization if it has none of its own. The Law defines no general standard of "reasonable" security beyond compliance with the requirements the State Security Service itself sets.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

official statute text, lex.uz, Uzbekistan's national legislation database

Back to the example  ·  Lint your app