Everything, then three categories
From April 2021, Article 27-1 of the Law “On Personal Data”, as worded by ZRU-666, set a strict rule. An owner or operator processing Uzbek citizens’ personal data with information technology was “obliged to ensure their collection, systematisation and storage in personal data databases on technical means physically located on the territory of the Republic of Uzbekistan” (translations from Russian and Uzbek in this piece are ours). The databases also had to be registered in the State Register.
For a chatbot the reading was simple. A conversation with a customer contains personal data, so it could only be stored on a server inside the country. A model from OpenAI or Anthropic, called over an API, did not fit. Blogs and hosting providers’ pages still repeat this wording.
Law ZRU-1125 is dated 26 March 2026 and applies from its official publication, which was on 27 March. Article 27-1 was rewritten, and the mandatory list became short: “The following personal data are subject to mandatory storage on the territory of the Republic of Uzbekistan: biometric data of individuals; genetic data of individuals…”. The third category is data on users of telecom operators’ services.
Article 20 changed at the same time: databases subject to mandatory storage in Uzbekistan are registered in the State Register.
Three conditions, one is enough
Everything outside the three categories may be stored and processed abroad. One of three conditions has to be met:
- The destination country is recognised as providing adequate protection of personal data.
- The operator uses standard contractual terms or binding corporate rules.
- The operator follows international standards for managing and storing personal data, as defined by the authorised body.
The conditions are alternatives. If the first is met, the second and third are not needed.
The amendment does not mention customer consent as a separate ground for transfer abroad. A checkbox on a website form does not satisfy any of the three conditions on its own.
For a bot, it comes down to this. A name, a phone number and the text of a question are neither biometric nor genetic data. Such a conversation may go to an external model if you have one of the three grounds. That rule covers only transfer abroad. It does not lift the law’s other requirements for processing personal data.
49 countries, the US with a footnote, no UAE
The first condition became checkable on 3 August 2026. On that day Cabinet of Ministers Resolution No. 415 of 29 July came into force, with a list of countries that provide adequate protection of personal data. The list has 49 countries and territories: the EU member states, the United Kingdom, Switzerland, Japan, South Korea, Singapore, Hong Kong, Russia, Canada, Israel, Brazil and others.
The US is on the list, with a footnote. It is included “for companies operating within the EU-US Data Privacy Framework”. Some news retellings dropped the footnote and simply reported that the US made the list. The difference is practical. A US provider that does not take part in the Data Privacy Framework does not qualify under the first condition, and then you need the second or the third.
The UAE, Kazakhstan and mainland China are not on the list. A server in Dubai is not, by itself, a ground for sending Uzbek citizens’ data there. That leaves contractual terms or international standards.
The same resolution sets out what happens if data leaks during cross-border transfer. The database operator notifies the authorised state body within 24 hours of discovering the leak, and within 72 hours provides details: the causes and what was done to fix it.
Voice and face: where the line runs
Biometric data stayed on the mandatory list, so the line follows its definition. Article 4 of the Law “On Personal Data” defines biometric data as “personal data characterising the anatomical and physiological features of the subject”.
The obvious cases are clear. A bot that recognises a regular customer from a photo of their face, or matches a voice against a sample, is working with biometric data. Such databases must be stored in Uzbekistan and registered, and they cannot be sent to an external model abroad.
An ordinary voice message is harder. A bot that turns a voice note into text and answers what was said does not recognise anyone by their voice. But the definition says nothing about identification. Whether a voice recording counts as biometric data when it is never matched against anything does not follow directly from the text of the law.
This question touches our own product. Valli, our auto-responder for Telegram Business and website widgets, is in pilot. It can transcribe customers’ voice messages into text. It does no voice matching. We do not present our reading of the law as an answer.
What a mistake costs
From 1 September 2026 the base calculation amount (BCA) is 440,000 soum, set by Decree UP-115 of 23 June. All amounts below are calculated from it.
- Article 46² of the Code of Administrative Liability, part one. Breach of personal data legislation, including the requirement to store data on technical means in Uzbekistan. A fine of 7 BCA for individuals (3.08m soum) and 50 BCA for officials (22m). These amounts date from the ZRU-726 amendments of 29 October 2021.
- Part two of the same article, added by ZRU-1115 of 21 January 2026. Unlawful processing of personal data using artificial intelligence technologies, and spreading it through the media, telecom networks or the internet. A fine of 50–100 BCA, or 22–44m soum, with confiscation of the instruments of the offence. There are no separate rates for individuals and officials.
- Article 141² of the Criminal Code, if the breach is repeated after an administrative penalty. A fine of 100–150 BCA (44–66m soum), deprivation of a specific right for up to 3 years, or corrective labour for up to 2 years. With aggravating circumstances, 150–200 BCA (66–88m) or other penalties, up to imprisonment for up to 3 years. We give these penalties as reported by Gazeta.uz.
Closest to the subject of this piece is part two of Article 46². It is about unlawful processing with AI and says nothing about where data is stored.
What to check before connecting a model
The order of checks:
- Which of the three conditions you rely on. Write down one, specifically, with the document it rests on.
- If the provider is American and your ground is the list, find the company among participants at dataprivacyframework.gov. If it is not there, the first condition does not work.
- If your ground is a contract, read the provider’s data processing terms and decide whether they can count as standard contractual terms.
- Where the data is physically processed. A data centre in a country outside the list, such as the UAE or Kazakhstan, moves you to the second or third condition.
- Whether face photos and voice samples used to recognise people go to the model.
- Whether the databases that must stay in Uzbekistan are registered in the State Register.
- Who in the company will notify the authorised body within 24 hours if data leaks during transfer.
A separate question is whose contract the data travels under. We install n8n workflows on the client’s server, with the client’s model keys, and hand over the code and access. Valli works differently: it is our service. An owner can connect their own OpenAI, Anthropic or Google key. Replies to customers are then written by that provider’s model under the owner’s key and contract. Until the owner connects a key, replies go through the platform’s key. If the owner’s provider fails, the bot answers through the platform’s backup model, so the customer is not left without a reply. Voice transcription and the customer card, which the bot compiles from recent messages, go through platform models even when the owner’s key is connected. All of this is data transfer too, and the check has to cover it.
What we don’t know
This is not legal advice. We are summarising the texts of the acts as worded on 13 September 2026. Applying them to your customer database is a job for a lawyer.
We have not checked whether OpenAI, Anthropic and Google take part in the Data Privacy Framework. As far as we have seen, the regulator has not published templates of standard contractual terms. Nor do we know which international standards the authorised body recognises.
Part one of Article 46² of the Code of Administrative Liability still refers to storing citizens’ personal data in Uzbekistan, with no carve-out for the three categories. How it will be applied after ZRU-1125 is unknown. Check the current wording on lex.uz. We know the Article 141² penalties from NORMA.UZ and Gazeta.uz reports; we did not open the text of the Criminal Code ourselves.
Resolution No. 415 describes automatic transfer to listed countries as transfer through information systems set up under international agreements, with measures against leaks. Whether that covers an ordinary commercial API is not clear from the text. Nor is it clear whether a customer’s phone number in a CRM falls into the category of telecom service users’ data; we read it as the operators’ own databases. The Russian text of ZRU-1125 on lex.uz is marked as an unofficial translation.
How we decide which fields go to the model and whose account it runs on is on AI implementation for business.
To see which data in your process leaves the company at all, and where it goes, one process taken apart step by step is enough. We do that breakdown for free in 48 hours, with no call needed.