{
  "node_id": "az-pdp-law-2010",
  "title": "Azerbaijan Law on Personal Data 2010 - Supervisory Executive Authority",
  "domain": "Cybersecurity",
  "version": "1.1.0",
  "last_updated": "2026-06-29",
  "bluf": "Azerbaijan's Law on Personal Data (Fərdi məlumatlar haqqında Qanun) - Law No. 998-IIIQ, adopted by the Milli Majlis (National Assembly) of the Republic of Azerbaijan on 11 May 2010 and signed by President Ilham Aliyev, entering into force on 26 October 2010 - is Azerbaijan's primary personal data protection legislation, establishing a framework for the protection of personal data of natural persons in Azerbaijan. The law has been amended to reflect technological developments and to align Azerbaijan's data protection framework with international standards. The supervisory function for personal data protection in Azerbaijan is exercised by the relevant executive authority - in practice the Ministry of Digital Development and Transport and associated e-government bodies; the Law does not establish a single standalone commission as the supervisory body. Azerbaijan's data protection legislation was developed in the context of the country's broader e-government initiatives and digital economy strategy, reflecting Azerbaijan's position as a Caspian energy economy increasingly integrating into global digital infrastructure. Key features of Azerbaijan's Law on Personal Data 2010: (1) Scope - applies to the processing of personal data by state bodies, legal entities, and individuals in Azerbaijan; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; proportionality; accuracy; storage limitation; security; and confidentiality; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political views; religious or philosophical beliefs; trade union membership; health status; criminal convictions; biometric data; and financial data; (4) Data subject rights - right of access to personal data; right to rectification of inaccurate data; right to erasure; right to object to processing; and right to complain to the relevant executive authority; (5) Consent - required for personal data processing as the primary lawful basis; explicit consent for sensitive personal data; consent must be informed, voluntary, and expressed; (6) State registration - operators (data controllers) must register with the relevant executive authority before commencing personal data processing; (7) Cross-border transfers - personal data may be transferred to states providing equivalent protection; transfers to non-equivalent states require the relevant executive authority's consent or specific statutory basis; (8) Security obligations - operators must implement technical and organisational security measures to protect personal data; (9) Executive authority enforcement - the relevant executive authority investigates complaints; conducts inspections; issues binding orders; imposes administrative sanctions; (10) E-government context - Azerbaijan's digital government programmes (ASAN Service, ASAN Xidmət, electronic government portal) process significant personal data subject to the law. Azerbaijan's data protection framework intersects with the country's participation in the Council of Europe, Convention 108 obligations, and its Association Partnership with the European Union.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "coe-convention-108-plus",
    "iso-27001-2022"
  ],
  "primary_citations_count": 7
}