Back to Legal Updates

Jurisdictions with adequate protection of personal data: what is adequate for one may not be adequate for another

legal updates
31 / 08 / 2026
In July 2026, Uzbekistan approved a list of 49 jurisdictions recognized as providing an adequate level of personal data protection. This caused our international privacy team to take a broader look at how adequate jurisdictions are regulated across different countries, focusing on Uzbekistan, the UAE, Georgia and Turkey.

UAE

The UAE's federal regulations on personal data do not provide for a separate list of jurisdictions with adequate protection. However, federal regulation provides for a caveat: under Article 28 of the UAE Personal Data Protection Law, the Council of Ministers was to adopt implementing regulations for the law; however, no such document has yet been issued. Therefore, even though the law took effect back in 2022, it is not actually being enforced, and companies are trying to use the regulations of other regions, including the GDPR, as a reference. At the same time, certain sector-specific regulations impose their own restrictions on cross-border data transfers and data localisation. For example, in banking and insurance, personal data may not be transferred as part of an outsourcing arrangement to a jurisdiction that does not provide a level of protection comparable to that of the UAE. For medical data, there is a specific list of cases in which the transfer or storage of data abroad is permitted.

Separate regulations governing personal data are being actively developed and implemented in two free economic zones: the Dubai International Financial Centre (DIFC) and the Abu Dhabi Global Market (ADGM). The DIFC maintains a list of 50 jurisdictions with adequate protection, which includes European countries, the state of California, Canada, South Korea, Japan, the Qatar Financial Centre, and some others. At the ADGM, the list differs in some respects, as the regulator of this free economic zone recognises adequate protection of personal data in Israel, as well as in companies that have joined the EU-US Data Privacy Framework, but does not recognise Colombia, Singapore and California as jurisdictions with adequate protection. Russia is not included on the list of jurisdictions with adequate protection in either the DIFC or the ADGM. It is interesting to note that both freezones recognise each other as jurisdictions with adequate protection, but deny this status to the rest of the UAE. Accordingly, when auditing cross-border transfers of personal data, it is not enough to simply verify that the counterparty’s servers are located in the UAE; rather, it is important to confirm whether they are located in the DIFC or the ADGM.

Georgia

Article 38 of Georgia’s Law on the Protection of Personal Data provides for an official list of countries with adequate protection, which must be reviewed every three years or more frequently. The current list was approved on 14 April 2026 by Order No. 007 and includes 49 countries, including the EEA member states, North Macedonia, Bosnia and Herzegovina, Albania and Uruguay (Russia is not included on the list).

A transfer to a country that is not on the list is permitted on other grounds, including the data subject’s written consent, the protection of the data subject’s vital interests, and the public interest. It is also possible to use a contract, which is a regional equivalent of Standard Contractual Clauses (SCC), but in that case, the cross-border transfer will need to be approved by the regulator. This ground implies an authorisation-based procedure, and the controller (operator) is prohibited from transferring data until an authorisation is obtained. Documents must be drawn up in Georgian, or a notarised translation must be attached to them. An application for authorisation to transfer data may be filed through a representative. During the procedure, the regulator may invite the controller to oral hearings, which may be held either in person or remotely. If the controller fails to appear at these hearings, the body will discontinue considering the application. The maximum approval period (including any extensions and excluding suspensions) must not exceed three months.

Uzbekistan

Uzbekistan's Personal Data Law provides for the creation of a list of states with adequate protection of personal data. It is approved by the Cabinet of Ministers pursuant to Article 271 of the Law. The up-to-date list (covering 49 jurisdictions) was approved by the Cabinet of Ministers in Resolution No. 415 of 29 July 2026. The list of jurisdictions with adequate protection that became effective on 3 August 2026, includes, for example, European countries, Russia, Singapore, Hong Kong and Brazil, while the UAE and Georgia are not included on the list. For the United States, Uzbekistan recognises transfers to companies participating in the EU-US Data Privacy Framework.

If, however, the counterparty’s state is not included on the list of states ensuring adequate protection, local equivalents of the SCCs and BCRs (Binding Corporate Rules), the requirements for which must be approved by November 2026, or international standards may be used for processing personal data outside Uzbekistan. At the same time, Article 15 of the Law formally continues to authorise cross-border transfers to jurisdictions with inadequate protection, in particular, with the consent of the data subject.

Turkey

Although Turkish law provides for a mechanism to recognise jurisdictions as those with adequate protection in terms of personal data protection, the regulator has not yet issued any such decision. Those companies that wish to transfer personal data to other states must rely on other mechanisms: Turkish SCCs, BCRs and written commitments approved by the regulator. Each of these measures requires notification to or authorisation from a government body. The regulator takes a fairly strict stance on the latter measure (written commitment): of the 89 applications considered in 2025, only 13 were approved, while 76 were rejected. So far, only one BCR has been approved, in May 2026. That leaves the SCC as a mechanism that is simpler to implement and familiar to international companies, but even it requires a special approach. Standard contract terms must be signed on paper or using an electronic digital signature recognised in Turkey (Docusign and similar services are not acceptable). The document must be submitted to the regulator within five days of signing.
Subscribe