The Central Bank expanded information security requirements to the entire non-bank lending sector and introduced mandatory biometrics localization.
What happened
The Central Bank of Uzbekistan updated its regulation on minimum information security requirements. The document took effect on August 6 and introduced a unified data handling standard. Previously, the rules mainly applied to microfinance organizations (MFOs), pawnshops, and mortgage refinancing companies. Now, the document officially covers guarantee and factoring companies.
The main change concerns handling sensitive information. As reported by the specialized channel Uzbek Fintech, the regulator introduced a direct requirement: any biometric personal data of individuals used for identification and authentication must physically reside on servers inside Uzbekistan.
An exception is made for other customer personal data. It can be stored and processed outside the country, provided it complies with the core law “On Personal Data.”
Additionally, the regulator aligned the terminology with current legislation, completely replacing the concept of “secret” with “confidential.”
Country and market
For Uzbekistan, this is a consistent step toward digital sovereignty. Remote identification is actively developing in the country. Microfinance organizations and payment services are massively implementing biometrics for customer onboarding and issuing online loans.
Earlier, similar database localization requirements affected telecommunications operators and the storage of citizens’ genetic information. Now, the state is closing the security loop for the non-bank financial sector.
Why it matters
The regulator clearly separated data sensitivity levels. Allowing standard information to be processed abroad gives fintech companies room to maneuver and use international SaaS solutions for scoring or analytics. At the same time, the most critical part is taken under strict control.
Mandatory biometrics localization forces fintech companies to revise their app architecture and invest in local data centers. This reduces the risks of mass leaks through foreign servers and makes the financial infrastructure less dependent on external cloud providers.
What’s next
Non-bank credit organizations that previously relied on foreign clouds to process biometrics will have to move these processes inside the country. This will require time for database migration and additional infrastructure costs. At the same time, local data center providers and information security system developers gain a new guaranteed market.
