Unlike the GDPR's two-year implementation run-in or Russia's more familiar localisation regime, Uzbekistan's personal data framework arrived at pace with the country's broader investment liberalisation push, leaving many foreign construction and real estate companies exposed to obligations they had not budgeted into their market-entry planning. Under Uzbekistan's Law on Personal Data and accompanying technical regulations, any legal entity that collects, stores, or processes personal data of Uzbek residents — including employees on construction sites, clients signing purchase agreements, and tenants of completed developments — is treated as a data operator subject to specific registration, localisation, and security requirements. For foreign companies entering Uzbekistan's rapidly expanding real estate market, understanding where these obligations begin and how to satisfy them in the construction context is not an optional compliance exercise.
Before engaging with the registration and technical steps, a foreign construction or real estate business should have the following ready:
This preparation stage typically takes two to four weeks for a construction business with multiple workstreams and is time better spent before regulatory registration opens.
The first substantive step is a sector-specific data mapping exercise. Construction and real estate operations in Uzbekistan generate personal data at every project stage: recruitment of local labour generates employment and biometric records; land acquisition involves notarial processes that capture client identification data; sales of residential or commercial units require purchaser due diligence; and ongoing property management involves tenant records, payment histories, and maintenance logs.
Each of these data categories attracts a distinct treatment under Uzbekistan law. Biometric data — which in the construction context includes site-access fingerprint records and in some cases facial-recognition systems — is classified as a sensitive category requiring a higher standard of security and explicit consent. Payment data connected to property transactions triggers additional obligations if processed through Uzbek financial infrastructure.
The mapping output should identify: (a) what data is collected and by whom within your organisational structure; (b) the legal basis for each collection; (c) where the data is stored at the point of collection; and (d) any onward transfers to the parent group, third-party contractors, or professional advisers outside Uzbekistan. This inventory is the foundation for every subsequent compliance step.
[CTA: If your construction or real estate operations in Uzbekistan are expanding and you have not yet mapped your data flows, early-stage analysis reduces the cost of remediation significantly. Make an enquiry: info@vetrovpartners.com | WhatsApp/Telegram: +7 (983) 510-38-76]
Foreign legal entities operating in Uzbekistan through a subsidiary or branch are required to register that entity as a personal data operator with the responsible state authority — the Agency for Personal Data Protection (operating under the Ministry of Digital Technologies). Registration is not a one-time administrative formality: the register entry must accurately reflect the categories of data processed, the purposes, the storage location, and the identity of the responsible officer.
For construction companies, the registration form requires granular sector-specific entries. A company constructing a residential complex will typically need to declare at minimum: employee and contractor personal data (for payroll and site-access purposes), client identification data (for purchase agreement and notarial processes), and — where applicable — biometric data if the site uses automated access control. Omitting a data category at registration and later processing it is treated as an unregistered processing activity, which carries separate liability.
The registration process is conducted in Uzbek or Russian. Foreign companies without Uzbek-qualified compliance personnel should engage local counsel or a contributing regional analyst to prepare the submission accurately and to ensure that the responsible officer designation satisfies the formal requirements. Incomplete submissions are returned without substantive review, resetting the timeline.
The core compliance obligation that most often surprises foreign construction investors is the data localisation requirement: personal data of Uzbek citizens and residents must be stored on servers physically located within the territory of Uzbekistan. This obligation applies regardless of where the parent company's data infrastructure is based and regardless of whether the Uzbek entity is a subsidiary, branch, or representative office.
In the construction and real estate context, localisation is operationally non-trivial. Many foreign developers use group-wide HR platforms, ERP systems, and document management tools hosted in the EU, Russia, or the Gulf states. Employee records, payroll data, site-management logs, and client purchase documentation all potentially contain personal data of Uzbek residents and must be stored locally to satisfy the requirement. The standard approach is either to procure storage capacity from one of Uzbekistan's certified local data centre operators or to deploy a localised instance of the group's enterprise platform within Uzbekistan.
Two points require particular attention. First, localisation means primary storage within Uzbekistan — a copy held locally alongside a master copy abroad does not satisfy the requirement under the prevailing regulatory interpretation. Second, the obligation extends to data processed on behalf of the Uzbek entity by third parties: if a foreign payroll processor handles the Uzbek workforce's records from servers outside the country, the Uzbek data operator remains legally responsible and is required to ensure the processor establishes compliant local storage.
Cross-border transfers of personal data to jurisdictions outside Uzbekistan — including transfers to a Russian parent, a Cypriot holding structure, or a European headquarters — are permissible only in defined circumstances: where the recipient jurisdiction provides an adequate level of protection, where the data subject has given explicit consent, or where a specific permitted purpose applies. Transfers to countries with which Uzbekistan has concluded bilateral data protection arrangements proceed on that basis; all others require individual assessment. This is a live issue for construction companies structured through Russian or CIS intermediary entities: the [cross-border data transfer analysis](/jurisdictions/uzbekistan/regulatory-licensing/) on this site addresses the applicable framework in more detail.
[CTA: For foreign construction groups assessing how to restructure data storage to meet Uzbekistan's localisation requirements without disrupting group-wide IT architecture, our regional team can advise on proportionate solutions. Make an enquiry: info@vetrovpartners.com | WhatsApp/Telegram: +7 (983) 510-38-76]
Registration and localisation are the threshold requirements, but Uzbekistan's personal data framework also imposes a positive obligation to implement technical and organisational protection measures proportionate to the sensitivity of the data processed. For construction and real estate companies, this translates into a series of operational requirements that must be embedded into site operations, project management processes, and client-facing workflows.
The key measures include: access control systems ensuring that personal data is accessible only to personnel with a documented need; audit logs for data access and modification; written contracts with all data processors (including third-party contractors who handle employee or client records on behalf of the Uzbek entity); a documented data retention and deletion schedule aligned with the categories of data collected; and a documented procedure for handling data subject access requests and breach notifications.
Biometric data used for site-access control — common on larger construction projects in Uzbekistan, where automated turnstile systems manage workforce entry — requires an additional layer of protection. The consent mechanism for biometric collection must be explicit and documented; withdrawal of consent must trigger deletion of the biometric template rather than mere suspension of access rights. Construction companies using biometric access infrastructure imported from third-country suppliers should verify that the system's data handling architecture supports these deletion requirements before deployment.
The technical measures do not need to be elaborate for a mid-size construction operation, but they do need to be documented: Uzbek regulators assess compliance against the existence and content of internal documentation as well as against actual technical implementation. An undocumented process, however sound in practice, will not satisfy an inspection.
Data protection compliance in Uzbekistan is not a one-time registration event: the legal framework imposes ongoing obligations that run for the duration of operations. For construction and real estate companies, this means maintaining compliance through the full project lifecycle — from initial land acquisition through construction, sales, and post-completion property management.
The principal ongoing obligations are: periodic review of the data operator registration to reflect changes in data categories or processing purposes; annual or event-triggered review of technical measures; and a documented procedure for notifying the authorised body in the event of a personal data breach. The breach notification timeline under Uzbekistan's framework is short: notification must typically be made within a defined number of working days of the operator becoming aware of the breach, and the notification must identify the categories of data affected, the probable cause, and the remedial steps taken or planned.
For foreign developers managing multiple concurrent construction projects in Uzbekistan, the practical challenge is maintaining compliance visibility across project entities. Where different projects are operated through separate legal entities — a common structure in large residential developments — each entity bears its own registration and compliance obligations. A group-level data protection policy adapted for Uzbekistan-specific requirements, overseen by a regional compliance officer with access to local legal counsel, is the most effective long-term arrangement. The [Regulatory & Licensing](/jurisdictions/uzbekistan/regulatory-licensing/) practice page on this site covers the broader licensing and registration environment in which data compliance sits.
[CTA: If you are managing construction or real estate projects in Uzbekistan and require a compliance review of your current data protection arrangements, our contributing regional analyst for Uzbekistan is available for an initial discussion. Make an enquiry: info@vetrovpartners.com | WhatsApp/Telegram: +7 (983) 510-38-76]
Q: Does Uzbekistan's data localisation requirement apply to my foreign parent company directly, or only to the Uzbek subsidiary?
A: The localisation obligation applies to the legal entity designated as the data operator in Uzbekistan — in most cases the registered subsidiary or branch through which the foreign group conducts operations. The foreign parent company is not directly subject to Uzbek enforcement jurisdiction, but because the Uzbek entity is legally responsible for ensuring that all personal data of Uzbek residents is stored on domestic servers — including data processed on its behalf by group entities abroad — the practical effect extends to the parent's IT infrastructure. A foreign parent that hosts the Uzbek subsidiary's HR or client data on overseas servers is exposing its Uzbek entity to regulatory liability. The prudent approach is to treat the localisation obligation as a group-level infrastructure question from the outset of market entry, rather than as a problem to be solved by the local subsidiary alone.
Q: What documents does a construction company need to submit when registering as a data operator in Uzbekistan?
A: Registration requires submission of a completed application form identifying the data operator, a description of the categories of personal data to be processed and the purposes of processing, the storage location and technical infrastructure details, the identity of the designated responsible officer, and — where applicable — information on cross-border data transfers. For a construction company, the categories declaration will typically cover employee and contractor records, biometric access data, and client purchase or tenancy data. The application is submitted to the Agency for Personal Data Protection. Submissions in Uzbek or Russian are accepted; most foreign companies prepare submissions with the assistance of local counsel to avoid incomplete entries that cause the application to be returned without review and reset the timeline.
Q: What are the consequences of non-compliance with Uzbekistan's personal data requirements for a foreign construction firm?
A: Non-compliance can result in administrative fines imposed on the Uzbek entity, suspension of the right to process personal data pending remediation, and — in cases of egregious or repeated violations — referral to prosecutorial authorities. For a construction company, the most operationally disruptive consequence is a processing suspension: if the Uzbek entity loses its authorisation to process employee or client data, site operations and sales transactions may be interrupted until compliance is restored. Reputational risk is a secondary but real consideration, particularly for foreign developers seeking to position projects in Uzbekistan's premium residential or commercial segments. Early and documented compliance is materially less expensive than post-investigation remediation.
Vetrov & Partners is a Russian boutique law firm established in 2009, recognised by Pravo-300 for eight consecutive years and listed as a trusted adviser by the German Consulate General in Novosibirsk.
Through its network of contributing regional analysts, the firm advises foreign companies and investors on regulatory and licensing requirements across CIS jurisdictions, including Uzbekistan. The firm's regional advisory work covers market entry compliance, data protection and localisation obligations, employment and migration frameworks, and licensing requirements specific to the construction and real estate sector. With over 1,000 matters handled since inception, the team combines direct partner involvement with jurisdiction-specific regional expertise.
Enquiries: info@vetrovpartners.com | WhatsApp / Telegram: +7 (983) 510-38-76 | t.me/vitvetcom
— Nodira Yusupova Contributing Regional Analyst — Uzbekistan, Vetrov & Partners vetrovpartners.com/contributions/
This publication is provided for informational purposes only and does not constitute legal advice under Russian or any other applicable law. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. Vetrov & Partners is a Russian-qualified law firm. For matters governed by foreign law or requiring local admission in another jurisdiction, we collaborate with trusted counsel in the relevant jurisdiction. For advice regarding your particular situation, please contact info@vetrovpartners.com.