The Senate of Uzbekistan is reviewing a bill in its second reading that will grant the Ministry of Internal Affairs (MIA) the authority of the primary regulator in the fight against cybercrime and change incident response rules for the financial sector.
What happened
Parliament is discussing a systemic document on countering cyber threats. The bill designates the MIA as the authorized state body in this area.
New operational obligations are being prepared for the financial and telecommunications sectors. The document requires banks, payment organizations, and internet service providers to rebuild their monitoring systems. The main focus is on reaction speed: institutions will have to detect suspicious transactions faster and mandatorily report cyber threats.
Special attention is given to data handling. Companies will be required to preserve digital evidence of incidents for subsequent transfer to law enforcement agencies. A specialized Telegram channel reports this, citing materials from the readings. In practice, this means the secure storage of logs, IP addresses, device identifiers, and transfer metadata.
Country and market
Amid the rapid growth of Uzbekistan’s digital economy, current anti-fraud mechanisms often fail to keep pace with the speed at which scammers withdraw funds.
Legislating these responsibilities should reduce the time between money theft and account blocking. The state expects to improve coordination between the private sector, which sees transactions in real time, and law enforcement, which conducts investigations.
Why it matters
The document shifts part of the responsibility for initial evidence collection to the private sector. The requirement to preserve digital evidence means fintech companies will have to revise internal data storage regulations. This will require additional investments in server capacity and secure databases.
For banks and payment services, the law acts as an infrastructure stress test: the speed of fraud detection and data transfer to the MIA becomes a strict compliance requirement that directly impacts operational risks.
What’s next
The bill has passed its second reading. After final approval by the Senate and signing by the president, it will take effect.
The financial market now awaits bylaws from relevant agencies. These documents will detail the technical regulations: the timeframes for transferring data to the MIA, the format for storing digital evidence, and the penalties companies face for violating the new rules.