What localization is and what the law requires
Data localization is the requirement to collect and store the personal data of citizens using technical means located within their state. Under amendments to the Republic of Uzbekistan's law "On Personal Data," an operator that processes the personal data of Uzbek citizens must store the databases of that data specifically on servers located in Uzbekistan.
In other words, it is about the physical location of the data: a citizen registry, customer base, employee records or ticket history must reside inside the country rather than in some foreign data center. The requirement was introduced to protect state sovereignty and the privacy of citizens.
- data is collected and stored on servers within Uzbekistan;
- the operator notifies the registering authority of where that database is located;
- cross-border transfer is allowed only under the conditions set by law;
- the requirement applies across the entire "life cycle" of the data — from collection to deletion.
Who the requirement applies to
The most common misconception is that localization is "only for government bodies." In reality the requirement applies to any operator that processes the personal data of Uzbek citizens, regardless of ownership form.
- Government bodies and institutions — citizens' applications, documents, registries.
- Banks and financial organizations — customer base, payment and credit history.
- Private companies — employee records, customer base, CRM systems.
- IT and online services — registered users, accounts.
- Foreign companies — if they process the data of Uzbek citizens.
Note: the requirement covers not only "new" data but all personal data already accumulated in the organization. For many, this is therefore a matter of relocating or migrating existing infrastructure.
What liability there is for breach
Failing to meet the localization requirement is not a "paper" risk. The legislation provides for several enforcement measures:
- Administrative fines — for violating the rules of personal data processing.
- Access restriction (blocking) — for repeated or serious breaches, access to the database may be suspended.
- Reputational damage — news that citizens' data was stored improperly sharply erodes trust.
- Business disruption — blocking or an emergency migration leads to operational outages.
That is why factoring in compliance not "later" but already at the system design stage is the cheapest and safest approach.
How to ensure compliance
Compliance may look like a complex legal process, but in practice it breaks down into a few clear steps:
- Data inventory. Identify what personal data is stored, where and in which systems.
- Assess the location. Are the primary databases in Uzbekistan or in a foreign cloud?
- Move to local infrastructure. A data center in Uzbekistan, a local cloud or the organization's own servers (on-premise).
- Control access. Who accessed the data, how and when must be recorded in a log.
- Apply encryption. Encryption in transit (TLS) and at rest strengthens privacy.
- Document it. Record the location of databases and the processing policy in official documents.
The role of on-premise and local hosting
The key question when meeting the localization requirement is where the data physically lives. This is exactly where the on-premise (on the organization's own servers) and local hosting (a data center in Uzbekistan) approaches give the clearest answer:
- Full control. In the on-premise model, data never leaves the organization's infrastructure.
- Clear jurisdiction. A local data center guarantees the data sits within Uzbekistan's legal framework.
- Verifiability. The location of the servers is easy to confirm with documentation.
- Sovereignty. The data is not exposed to foreign jurisdictions.
By contrast, when using global cloud providers it is not always clear which country the data is stored in — which can directly contradict the localization requirement.
How HAMA handles this
HAMA is a unified secure platform for organizations in Uzbekistan: a secure messenger, employee monitoring and a helpdesk in one place. The platform was designed from the start with the localization requirement in mind: all data is stored on a secure server within Uzbekistan or in the organization's own infrastructure (on-premise).
Communication and data are protected with end-to-end encryption (the Signal protocol) and TLS 1.3 in transit. This means the personal data of citizens and employees never ends up in an uncontrolled foreign data center — that is, data sovereignty is preserved, and the organization can document its compliance with the localization requirement.