Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

Azerbaijan Law on Personal Data 2010 - Supervisory Executive Authority

Azerbaijan's Law on Personal Data (Fərdi məlumatlar haqqında Qanun) - Law No. 998-IIIQ, adopted by the Milli Majlis (National Assembly) of the Republic of…

What Azerbaijan Law on Personal Data 2010 - Supervisory Executive Authority requires

Azerbaijan's Law on Personal Data (Fərdi məlumatlar haqqında Qanun) - Law No. 998-IIIQ, adopted by the Milli Majlis (National Assembly) of the Republic of Azerbaijan on 11 May 2010 and signed by President Ilham Aliyev, entering into force on 26 October 2010 - is Azerbaijan's primary personal data protection legislation, establishing a framework for the protection of personal data of natural persons in Azerbaijan. The law has been amended to reflect technological developments and to align Azerbaijan's data protection framework with international standards. The supervisory function for personal data protection in Azerbaijan is exercised by the relevant executive authority - in practice the Ministry of Digital Development and Transport and associated e-government bodies; the Law does not establish a single standalone commission as the supervisory body. Azerbaijan's data protection legislation was developed in the context of the country's broader e-government initiatives and digital economy strategy, reflecting Azerbaijan's position as a Caspian energy economy increasingly integrating into global digital infrastructure. Key features of Azerbaijan's Law on Personal Data 2010: (1) Scope - applies to the processing of personal data by state bodies, legal entities, and individuals in Azerbaijan; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; proportionality; accuracy; storage limitation; security; and confidentiality; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political views; religious or philosophical beliefs; trade union membership; health status; criminal convictions; biometric data; and financial data; (4) Data subject rights - right of access to personal data; right to rectification of inaccurate data; right to erasure; right to object to processing; and right to complain to the relevant executive authority; (5) Consent - required for personal data processing as the primary lawful basis; explicit consent for sensitive personal data; consent must be informed, voluntary, and expressed; (6) State registration - operators (data controllers) must register with the relevant executive authority before commencing personal data processing; (7) Cross-border transfers - personal data may be transferred to states providing equivalent protection; transfers to non-equivalent states require the relevant executive authority's consent or specific statutory basis; (8) Security obligations - operators must implement technical and organisational security measures to protect personal data; (9) Executive authority enforcement - the relevant executive authority investigates complaints; conducts inspections; issues binding orders; imposes administrative sanctions; (10) E-government context - Azerbaijan's digital government programmes (ASAN Service, ASAN Xidmət, electronic government portal) process significant personal data subject to the law. Azerbaijan's data protection framework intersects with the country's participation in the Council of Europe, Convention 108 obligations, and its Association Partnership with the European Union.

Pillar: Cybersecurity · Authority: Ministry of Digital Development and Transport (the relevant executive authority), Republic of Azerbaijan · Version: 1.1.0 · Last updated:

Primary source: https://www.e-gov.az/

SHA-256 integrity: dff0a4f2ce3eb1ce6739da4fda60258a7c9917bb54fb5378b91d20649c6a703c

Primary Citations — 7 traced to source

  • Law on Personal Data No. 998-IIIQ (Azerbaijan) - adopted by Milli Majlis 11 May 2010; in force 26 October 2010; processing principles: lawfulness, purpose limitation, proportionality, accuracy, storage limitation, security, confidentiality; sensitive personal data: racial/ethnic origin, political views, religious beliefs, trade union membership, health, criminal convictions, biometric, financial data; data subject rights: access, rectification, erasure, objection; consent as primary lawful basis; explicit consent for sensitive data; state registration mandatory; cross-border transfer restrictions; enforcement by the relevant executive authority
  • Relevant executive authority (Ministry of Digital Development and Transport), Azerbaijan - the supervisory authority under the Law on Personal Data; the Law assigns supervisory functions to the relevant executive authority rather than a dedicated standalone commission; maintains the state register of personal data operators; investigates complaints from data subjects; conducts inspections; issues binding orders; imposes administrative sanctions; approves cross-border transfers to non-equivalent jurisdictions; issues guidance on Law compliance; operates within Azerbaijan's digital governance structure

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.