What Is Law on Personal Data, No. 998-IIIQ?
Azerbaijan’s operative statute is the Law on Personal Data, No. 998-IIIQ, adopted on 11 May 2010. The official consolidated text shows amendments through 2014, 2018, two amendments in 2022, 2023, and the latest amendment, Law No. 1193-VIQD of 28 June 2024, which changed specified provisions. A significant currentness trap concerns the regulator. In the 2 June 2026 official record, responsibility lies with the National Cybersecurity Agency, a public legal entity under the Ministry of Digital Development and Transport, after the former Electronic Security Service was reorganized into MKA. The old CERT/ETX personal-data complaint form remains live and still labels ETX as handler, so its current routing needs verification before it is cited as the correct complaint channel. No EU-GDPR-style extraterritorial rule was located.
At a glance
- Full name
- Law on Personal Data, No. 998-IIIQ
- Short code
- Law 998-IIIQ
- Jurisdiction
- Azerbaijan
- Enacted
- 2010
- Last major update
- Law No. 1193-VIQD of 28 June 2024 amended specified provisions; the responsible authority transitioned from the Electronic Security Service to the National Cybersecurity Agency on 2 June 2026, while the legacy complaint form still labels ETX as handler
- Regulator
- National Cybersecurity Agency (Milli Kibertəhlükesizlik Agentliyi, MKA)
- Private right of action
- Limited
- Statutory citation
- Law on Personal Data, No. 998-IIIQ
Scope, who Law 998-IIIQ covers
Protected data
Data subject rights
Right to know whether data exists and identify the owner or operator
Right to demand the legal basis and consequences of processing
Right to inspect collected data
Right to know purposes, periods, methods, authorized persons, and exchange systems
Right to request correction, clarification, destruction subject to exceptions, or archiving
Right to request prohibition of collection or processing
Right to know data sources and demand proof of lawfulness
Right to demand data protection and security
Right to object to non-mandatory collection or processing without giving reasons
Right to object to adverse automated decisions
Right to complain to the competent authority or court and seek damages
No express portability right or separately titled restriction-of-processing right was located
Notable features
The law uses “subject,” “owner,” and “operator” rather than GDPR terminology. It provides a functional prohibition or stop-processing remedy but no express portability right or separately titled restriction right was located. Qualifying open-source data in a public-use system must disclose its source and be removable without delay on demand, while data must be destroyed without delay once its processing purpose is achieved. The 2 June 2026 MKA transition and legacy ETX complaint form create a live authority-routing trap.
Enforcement & penalties
Regulator: National Cybersecurity Agency (Milli Kibertəhlükesizlik Agentliyi, MKA)
Penalties: Administrative Offences Code Articles 375.0.1-375.0.2 provide fines of 300-500 AZN for unregistered processing where registration is required, owner or operator protection failures, required-destruction failures, or failure to stop processing when required. The Personal Data Law itself states no penalty figure and Article 19 defers liability to Azerbaijani legislation generally.
Private right of action: Article 7.4 provides a right to complain to the competent authority or court and seek damages. No fixed filing deadline for a direct Article 7.4 court action was located. The Personal Data Law itself states no fixed special deadline for the MKA’s investigation or decision.
Relevance to data brokers
Not located. No dedicated data-broker, people-search-service, or public-record-aggregator route was found. The general mechanisms are Article 7 rights, the Article 12 owner/operator request process, and Article 5.7’s narrow rule that qualifying open-source data in a public-use system must disclose its source and be removable without delay on demand. This is not a dedicated broker deletion route.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Who is Azerbaijan’s current personal-data authority?+
In the 2 June 2026 official record, the responsible authority is the National Cybersecurity Agency, or MKA, under the Ministry of Digital Development and Transport. The legacy CERT/ETX complaint form remains live and still labels ETX as handler, so its current routing needs verification.
Can I object to processing under Azerbaijan’s law?+
Yes. Article 7.2 allows an objection to non-mandatory collection or processing without reasons, with immediate stopping required after a valid objection. No separately titled restriction-of-processing right was located.
Does Azerbaijan have a dedicated data-broker deletion route?+
Not located. The reviewed materials identify only general Article 7 and Article 12 rights and the Article 5.7 removal rule for qualifying open-source data in a public-use system.
Official sources & citations
Other international privacy regimes
Law 998-IIIQ sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
