The Central Bank of Uzbekistan has tightened requirements for microfinance institution data.
The Central Bank has extended information security requirements to factoring and guarantee organizations and introduced new data storage rules.

The Central Bank of Uzbekistan has tightened requirements for non-bank credit institutions, extending information security rules to guarantee and factoring companies and mandating the storage of clients' biometric data within the country. The corresponding Central Bank resolution, issued on July 22, was registered by the Ministry of Justice on August 5 and entered into force on August 6.
The document amends and supplements the Regulation on Minimum Information Security Requirements for Microfinance Organizations, Pawnshops, and Mortgage Refinancing Organizations. These requirements now also apply to organizations providing guarantees and factoring organizations. All these entities are grouped under the general heading "non-bank credit institutions" in the document.
The Regulation has been supplemented by clause 4-1, which requires non-bank credit institutions to store biometric personal data of individuals used for client identification and authentication exclusively within Uzbekistan.
However, other personal data of clients that is not biometric may be stored and processed outside the country, subject to the requirements of Part 3 of Article 27-1 of the Law "On Personal Data."
The Resolution also updates the terminology of the Regulation in line with current legislation. Specifically, the word "secret" has been replaced with "confidential" throughout the document.
As a reminder, according to the Law "On Personal Data," genetic data of individuals and data of individuals using the services of telecommunications operators operating in the country are also subject to mandatory storage in Uzbekistan.

