Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
What it requires →
Art. 26 defines biometric data generally as data characterizing anatomical and physiological characteristics, and genetic data as data from analysis of biological material, with no illustrative list naming face, voice, or fingerprint.
Biometric and genetic data used for identification may be processed only with the subject's consent, except for treaty implementation, administration of justice, or enforcement proceedings, and electronic biometric or genetic data stored outside an information system must be kept on media that exclude unauthorized access. No retention or destruction duty specific to biometric data was found in this article or elsewhere in the Act.
Comprehensive regime
What it requires →
Law No. ZRU-547 reaches the owner, operator, and third party generally, with no public and private carve-out found in the articles read. Processing generally requires the subject's consent (Art. 21 sets the procedure for giving and revoking it), subject to statutory exceptions not read article by article in this pass.
Cross border transfer
What it requires →
Art. 15 permits cross-border transfer where the destination state ensures adequate protection, or, where it does not, on subject consent, statutory necessity, or an international treaty; transfer may also be restricted for constitutional-order, morality, health, rights, defense, or state-security reasons.
Art. 27-1, added by a 2021 amendment reported in force April 2021, is narrower and separate: when processing the personal data of citizens of Uzbekistan using information technologies, including the internet, the owner or operator must collect, systematize, and store that data on technical means physically located in Uzbekistan and register the database in the State Register of Personal Data Bases.
Enforcement of Art. 27-1 is documented: the State Inspectorate for Control in the Sphere of Informatization and Telecommunications blocked Twitter, TikTok, VKontakte, Skype, and WeChat in July 2021, and Facebook, Instagram, LinkedIn, Odnoklassniki, Telegram, and YouTube in November 2021, citing failure to store Uzbek users' data domestically; several were later unblocked, and TikTok was reported still restricted as of the most recent secondary reporting located.
Data subject rights
What it requires →
Art. 30 gives the subject the right to know that an owner, operator, or third party holds their data, obtain processing information on request, obtain information on access conditions, apply to the authorized state body or a court for protection of rights, give and withdraw consent, consent to inclusion in public sources, and require temporary suspension of processing where data is incomplete, outdated, or unreliable. Most, not all, of the article was extracted for this brief.
Enforcement supervision
What it requires →
Art. 33, the Act's only enforcement provision, is a bare reference clause: persons violating the legislation on personal data are liable in the manner prescribed by law, with no penalty schedule, no named authority, and no private right of action stated in the Act itself. The Act refers to an authorized state body fourteen times but never names it in the text read; substantive penalties and the body's identity live in legislation this research did not identify.
Sensitive categories
What it requires →
Art. 25 prohibits processing special personal data by default: racial or social origin, political, religious, or ideological beliefs, political-party or trade-union membership, physical or mental health, private life, and criminal record.
Processing is permitted only for state-security purposes by the authorized state body, on the subject's written or electronic consent, or where the subject has already published the special data in publicly available sources; this is a distinct track from Art. 26's biometric and genetic data, not a category that folds biometric data into it.