Proposed amendments to the Law of the Republic of Azerbaijan “On Information, Informatization and Information Protection”.

Proposed amendments to the Law of the Republic of Azerbaijan “On Information, Informatization and Information Protection”.

A draft Law amending the Law of the Republic of Azerbaijan "On Information, Informatization and Information Protection" dated April 3, 1998, #460-IQ has been submitted to the Parliament of the Republic of Azerbaijan and is currently under consideration. The draft introduces a comprehensive legal framework governing digital development, information security and cybersecurity. Although the draft contains numerous technical amendments, a couple of the proposed changes are expected to have the greatest practical impact on businesses: the introduction of new cybersecurity obligations for organisations operating information infrastructure and the establishment of a new regulatory framework for entities performing public-interest functions.

I. New cybersecurity obligations for businesses

The draft law introduces a new chapter regulating the protection of information infrastructure and proposes new responsibilities for organisations operating information systems. Businesses falling within the scope of the proposed rules will be required to establish appropriate cybersecurity governance, implement technical and organisational security measures and cooperate with the National Computer Emergency Response Team (National CERT).

The proposed amendments also introduce obligations relating to the detection and reporting of cyber incidents. Organisations operating information infrastructure will be required to notify the National CERT of cyber incidents, cooperate during investigations and comply with cybersecurity instructions issued by the competent authority. These requirements are intended to improve the national response to cybersecurity threats and increase coordination between the public and private sectors.

II. New framework for public-interest information infrastructure

The draft introduces the concept of "public-interest information infrastructure" and establishes a separate legal regime for organisations whose information systems are considered important for the functioning of the state, the economy or society.

Such organisations will become subject to additional cybersecurity requirements, including the implementation of enhanced security measures and ongoing cooperation with the National CERT. The draft also establishes a legal basis for the operation of Computer Emergency Response Teams (CERTs) and Security Operations Centres (SOCs), which are expected to play a central role in monitoring cybersecurity risks and responding to cyber incidents.

III. Practical implications

Although the draft Law has not yet been adopted, it represents a significant step towards a more structured and centralised cybersecurity regime in Azerbaijan. Businesses operating digital platforms, online services or information systems should monitor the legislative process closely, as the proposed amendments are likely to require changes to cybersecurity governance, incident response procedures and compliance obligations. The establishment of the National CERT, the Government CERT (GOV CERT) and Security Operations Centers (SOCs) further underscores the Government's intention to create a coordinated national cybersecurity framework, with organisations providing essential or public-interest services expected to be among those most significantly affected by the new regime.

Azerbaijan