ZRU-547 “On Personal Data” is Uzbekistan’s basic personal-data protection law. The ZRU-1125 amendment (26 March 2026) introduced mandatory in-country localisation for biometric data, genetic data and telecom subscriber data; other personal data may be stored abroad where adequate protection is in place. Voice biometrics inside call recordings can fall under mandatory localisation.
What ZRU-547 and ZRU-1125 are
ZRU-547 is the Law of the Republic of Uzbekistan “On Personal Data”. It sets out how a business must collect, process and store people’s data — customers, employees, subscribers. The ZRU-1125 amendment of 26 March 2026 clarified the key question: which data must physically stay inside the country and which may be stored abroad (gazeta.uz; the text is on lex.uz).
The localisation requirement used to be read broadly. After the amendment the picture is more precise — and for many companies, less demanding.
Which data must be stored in Uzbekistan
After ZRU-1125, mandatory in-country localisation applies to three categories:
- Biometric data — fingerprints, face recognition, voiceprints.
- Genetic data.
- Telecom operator subscriber data.
Other personal data (name, phone number, order history) may be processed abroad — provided there is an adequate level of protection, standard contractual clauses (SCCs) or ISO 27001 / 27701 certification on the processor’s side.
| Data category | Where it may be stored |
|---|---|
| Biometrics (voice included) | Uzbekistan only |
| Genetic data | Uzbekistan only |
| Telecom subscriber data | Uzbekistan only |
| Name, phone number, orders | Abroad, with adequate protection / SCCs / ISO 27001–27701 |
How this touches your CRM and call recordings
Your CRM stores personal data by definition — contacts, conversations, deal history. If the business records calls, those recordings may contain voice biometrics, and that is already a mandatory-localisation category. This is why “the server is in Uzbekistan” remains a strong and often necessary argument when choosing a system.
Global CRMs keep data in EU, US or Russian data centres. Zukko.AI stores data belonging to customers in Uzbekistan inside the country, and for CIS banks and regulated companies an on-prem / private cloud deployment is available — see the Security section and the article on on-prem CRM for CIS banks. How this is built into the system itself is covered on the AI-CRM page.
What the business gets
- Less regulatory risk — the data sits where the law requires it to sit.
- Readiness for an inspection — residency, access control and the audit trail answer compliance questions.
- An argument for banks and large customers — their first question is where the data physically lives.
- Peace of mind on call recordings — voice data stays in the country.
One caveat: Zukko.AI helps you comply with ZRU-547 (residency, RBAC, audit trail), but that is compliance support, not a legal guarantee. A legal assessment for your specific business is your lawyer’s job. The full data-protection picture is in the CRM security guide.
Frequently asked questions
What is ZRU-547 in plain words?
It is Uzbekistan’s “On Personal Data” law — it sets the rules for collecting, processing and storing people’s data, and the business’s responsibility for it.
Does all data have to be stored in Uzbekistan?
No. After the ZRU-1125 amendment, mandatory localisation covers biometrics, genetic data and telecom subscriber data. Other personal data may be stored abroad with adequate protection, SCCs or ISO 27001 / 27701.
Do call recordings fall under localisation?
They can: voice biometrics belong to the mandatory-localisation category, so keeping recordings in the country is the safe choice.
Does Zukko.AI help with ZRU-547 compliance?
Yes — through data residency, on-prem for CIS banks, access control and an audit trail. That is compliance support, not a legal guarantee.
What about certifications?
We claim no certification of our own — we state the controls that are actually in place: encryption, role-based access, an audit trail and data inside the customer’s perimeter. We apply GDPR practices.