Personal Data Protection in CRM: What Uzbekistan Law №547 Requires in 2026

The Republic of Uzbekistan''s Law №ZRU-547 "On Personal Data" has been in force since 2019 and was significantly tightened in 2021–2022. If you keep customers in a CRM, send campaigns or store passport copies in Google Drive — the law already applies to you. Without the legal jargon, here is what is required and how to configure your CRM to avoid penalties.
Who is covered
The law applies to anyone who collects, stores or processes the data of Uzbek citizens, including:
- Any company maintaining a customer database.
- E-commerce stores and online services.
- Education centers, clinics, banks.
- Foreign companies — if they work with users from Uzbekistan.
What counts as "personal data"
Any information that can identify a person: full name, phone, email, passport details, taxpayer ID, photo, biometrics, or an IP address combined with other data.
Core requirements
1. Consent to processing
You can''t collect data "by default". Consent must be:
- Active — a separate, non-prechecked checkbox.
- Informed — the user sees what data and why.
- Recorded — you have a log of what was confirmed and when.
2. Data localization
Since 2021, the data of Uzbek citizens must be stored on servers physically located in Uzbekistan. If your SaaS provider is hosted in Europe or the US — that is already a violation. UpGrid CRM, for instance, runs on Tashkent-based servers for exactly this reason.
3. Registration in the PD database registry
If you process data of more than 10,000 people or use biometrics — you must notify the State Personalization Center.
4. Designated officer
The company must have someone responsible for protecting personal data. It doesn''t have to be a dedicated role — it can be combined with another job — but the responsibilities must be fixed by an internal order.
5. Retention and right to deletion
Data is stored only as long as there is a legal basis (contract, consent). After that — deletion. A customer can request deletion of their data at any time, and you have 30 days to comply.
What the CRM itself must provide
- Consent log. Shows: when, to what, who agreed.
- Access rights. Not every employee should see a customer''s passport. Role-based access is mandatory.
- Encryption. Sensitive fields (passport, INN) encrypted in the database.
- Audit log. Who viewed/changed/exported data, and when. Critical during an incident.
- Export and deletion on request. One click — export all of a customer''s data, or remove it.
- Backups in Uzbekistan. If backups live in a foreign cloud, localization is broken.
Penalties
Sanctions were significantly raised in 2022. Localization breaches, missing consent or data leaks can lead to fines of 50–200 base accounting values for officials and substantially higher amounts for legal entities, plus suspension of operations.
Business checklist
- Consent on the website is a separate checkbox, not "checked by default".
- CRM is hosted in Uzbekistan or with a local provider.
- A data-protection officer is appointed by an internal order.
- A "Personal Data Processing Policy" is published on the website.
- Employees see only those customer fields they need for their work.
- A customer-request deletion procedure exists, with deadlines.
- An access audit log is in place.
How UpGrid helps
UpGrid CRM is designed around Law №547: local hosting, role-based access, audit log, encryption, one-click export and deletion. If you have compliance questions, drop us a line — we''ll help configure the process for your business.
This article is informational and does not replace legal advice.
Rate this article
Comments(0)
No comments yet. Be the first!


