Uzbekistan Central Bank Tightens Data Rules for Nonbank Lenders
Tashkent, Uzbekistan (UzDaily.uz) — The Central Bank of Uzbekistan has extended information security requirements to guarantee and factoring organizations and introduced a requirement for clients’ biometric personal data to be stored within the country, according to a Central Bank resolution dated 22 July and registered by the Ministry of Justice on 5 August.
The document amended the Regulation on Minimum Information Security Requirements for Microfinance Organizations, Pawnshops and Mortgage Refinancing Organizations. The resolution entered into force on 6 August.
Under the amendments, the Regulation now applies not only to microfinance organizations, pawnshops and mortgage refinancing organizations, but also to guarantee and factoring organizations. All these entities are referred to in the document as “nonbank credit organizations.”
The Regulation was supplemented with Clause 4-1, which establishes requirements for storing biometric personal data of individuals. Such data used by nonbank credit organizations to identify and authenticate clients must be stored within Uzbekistan.
Other client personal data that is not biometric may be stored and processed outside the country provided that the requirements of Part Three of Article 27-1 of the Law on Personal Data are met.
The resolution also brings the terminology used in the Regulation into line with current legislation. In particular, the term “secret” has been replaced throughout the text with “confidential.”
Under the Law on Personal Data, genetic data of individuals and data of individuals who use the services of telecommunications operators operating in Uzbekistan must also be stored within the country.