The Central Bank of Uzbekistan has expanded information security requirements for organizations engaged in guaranteeing and factoring, and has also introduced an obligation to store clients' biometric personal data within the country. This was done according to the Central Bank's resolution of July 22, which was registered by the Ministry of Justice on August 5.
This document made amendments to the Regulation on minimum information security requirements for microfinance organizations, pawnshops, and mortgage refinancing organizations. The resolution came into force on August 6.
As a result of the amendments, the Regulation now applies not only to microfinance organizations, pawnshops, and mortgage refinancing organizations but also to guaranteeing and factoring organizations. All these structures are referred to as 'non-bank credit institutions' in the document.
The Regulation was supplemented with clause 4-1, which establishes rules for storing citizens' biometric personal data. Such data, used by non-bank credit institutions for client identification and authentication, must be stored exclusively within Uzbekistan.
Other personal data of clients that is not biometric may be processed and stored outside the country provided that the requirements of Part Three, Article 27-1 of the Personal Data Law are met.
Furthermore, the resolution unified the terminology used in the Regulation, bringing it into compliance with current legislation. In particular, the term 'secret' was replaced with 'confidential' throughout the text of the document.
According to the Personal Data Law, genetic data of people, as well as data of persons using services of telecommunications operators operating in Uzbekistan, must also be stored within the country.


