Law on Cybersecurity, general cybersecurity duties on cybersecurity subjects
Law No. O'RQ-764 (15 April 2022) "On Cybersecurity," Arts. 3, 16, 37
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 17 July 2022.
A security baseline statutes rule binding private bodies.
As of 18 September 2026.
What it requires
- Applies to any legal entity or individual entrepreneur that owns, uses, or disposes of national information resources, or that provides electronic information services using them.
- Prevent unlawful disclosure, theft, loss, corruption, blocking, or falsification of data in your information systems and resources, and act promptly when such a case is detected.
- Comply with the cybersecurity requirements the State Security Service sets for protecting information systems and resources.
- Maintain a functioning capability to respond to cybersecurity incidents, or use an outsourced provider with the State Security Service's authorization if you have none of your own.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Article 37 refers a violation of the cybersecurity legislation generically to liability "in the established manner," which the statute's own official commentary at that article identifies as the Code of Administrative Liability (Arts. 155, 202-2) and the Criminal Code (Ch. XX-1); the Law itself states no maximum penalty for either track.
Who enforces it
Enforcement body
State Security Service of the Republic of Uzbekistan
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Any legal entity or individual entrepreneur that owns, uses, or disposes of national information resources, or that provides electronic information services using them, is a "cybersecurity subject" under the Law and must prevent unlawful disclosure, theft, loss, corruption, blocking, or falsification of data in its information systems and resources, and act promptly when such a case is detected.
It must comply with the cybersecurity requirements the State Security Service sets for protecting information systems and resources, and must keep a functioning capability to respond to cybersecurity incidents, using an outsourced provider with the State Security Service's authorization if it has none of its own. The Law defines no general standard of "reasonable" security beyond compliance with the requirements the State Security Service itself sets.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
official statute text, lex.uz, Uzbekistan's national legislation database