Uzbekistan

The Central Bank has amended information security requirements

The Central Bank has updated the minimum requirements for information security. According to the new regulations, biometric data used for customer identification and authentication in non-bank credit organizations must be stored only in Uzbekistan.

The Central Bank has updated the requirements for information security.

The Central Bank has made amendments and additions to the Regulation on minimum requirements for information security in information systems of microfinance organizations, pawnshops, mortgage refinancing organizations, guaranteeing organizations and factoring organizations. This resolution was registered with the Ministry of Justice and entered into force on the date of its official publication.

According to the new edition, non-bank credit organizations are required to store biometric data of individuals used in the process of identifying and authenticating clients only in the territory of Uzbekistan. At the same time, other non-biometric data about a person may be stored and processed outside the country in accordance with the procedure established by law.

In addition, the document updated the terms related to information security and expanded the scope of the regulation to guaranteeing and factoring organizations. The obligations of employees to keep confidential and personal information secret, as well as other information security requirements, were clarified.