Law on Personal Data art. 7.3 — an objection right against decisions taken by information technology, whose remedy is re-processing by another method or a full stop
Binds Owners («mülkiyyətçi») and operators («operator»), the Law's two controller-analogues — art. 2.1 defines the owner as the person who owns the information system and determines the purpose and scope of collection and processing, and the operator as the person who carries out collection and processing under a contract with or on the instruction of the owner. Art. 10.2 applies the operator's duties to an owner that performs them itself. The Law's preamble extends it to state and local self-government bodies and to legal and natural persons alike, so public-sector deployers are inside it on the same terms as private ones. There is no size threshold, no sectoral limit and no turnover test anywhere in art. 7. The reach is territorial and system-based rather than targeting-based: the Law regulates collection, processing and protection of personal data and the formation of the personal-data segment of the national information space, and art. 15 requires state registration of personal-data information systems, which is the hook that brings a system within the regime. Art. 3.2 carves out processing outside the Law's scope, and art. 10.5 requires operators to facilitate intelligence, counter-intelligence and operative-search measures and to keep the methods used confidential.. Art. 7.3 of the Law of the Republic of Azerbaijan on Personal Data (No. 998-IIIQ of 11 May 2010) is an automated-decision rule that never uses the word automated, which is why keyword sweeps miss it: the operative term is «informasiya texnologiyaları vasitəsilə» — by means of information technologies. The sentence reads «İnformasiya texnologiyaları vasitəsilə fərdi məlumatların toplanılması və işlənilməsi nəticəsində qəbul olunan qərar subyektin mənafeyini pozduğu halda, qanunvericiliklə müəyyən olunmuş qaydada məcburi xarakter daşıdığı hallar istisna olmaqla, subyektin bu məlumatların göstərilən üsulla toplanılmasına və işlənilməsinə etiraz etmək hüququ vardır» — where a decision taken as a result of the collection and processing of personal data by means of information technologies infringes the subject's interests, the subject has the right to object to the collection and processing of that data by that method, save where the processing is mandatory in the manner established by legislation. The whole of the Law was read end to end in its consolidated text on e-qanun.az, the official corpus of the Ministry of Justice; the words «avtomat» and «profil» appear nowhere in its nineteen articles. Four features set it apart from the GDPR art. 22 family. First, there is no «solely» qualifier and no profiling concept: the trigger is the method of processing, so a decision produced with information technology in the loop and a human signing it off is caught, where GDPR art. 22 and the Kazakh, Uzbek and Russian analogues would let it through. Second, the effects threshold is «subyektin mənafeyini pozduğu halda» — infringes the subject's interests. That is lower and wider than legal effects or similarly significant effects, and like the Turkish art. 11(g) it is adverse-only, so a favourable machine-made decision produces no right. Third, the remedy is not human intervention. Art. 7.3 second sentence obliges the owner or operator, on receiving the objection, either to obtain the subject's consent to process the data «digər üsulla» — by another method — or to stop the processing «təxirə salmadan», without delay. The subject cannot demand that a person re-take the decision, but can force the processing off the information-technology track altogether, which no GDPR-family rule offers. Fourth, the exception architecture is a single item: processing made mandatory by legislation. There is no consent limb and no contract limb, so a controller cannot buy its way out with a consent click. There is no explanation or logic-disclosure limb tied to automation. Art. 7.1.2 gives a general right to demand the legal justification for collection, processing and third-party disclosure and to be told what legal consequences these will have for the subject, and art. 11.2 lists what must be told at collection — identity, purpose and its legal basis, the protection level of the information system, whether that system holds a conformity certificate and has passed state expert examination, the circle of intended users, and the subject's rights under the Law — but neither list carries an automated-decision or logic item. Art. 7.5 adds real procedural friction: the art. 7.1 to 7.3 rights are exercised only by a written paper application presented with an identity document, or by an electronic request bearing an enhanced electronic signature. Art. 7.2 sits alongside it as a general objection right with the same stop-immediately consequence and no requirement to give reasons, so a subject who cannot show that a decision infringed their interests can often reach the same outcome by the more general route.
In force, and art. 7.3 is original 2010 text: the consolidated version on e-qanun.az marks amended provisions with bracketed source-document numbers — art. 8.2 carries [3] and art. 8.6 carries [4] — and art. 7 carries none across all five of its paragraphs, so none of the six amending laws listed in the source-document schedule (20 June 2014, 3 April 2018, 8 July 2022 and later) touched it. The commencement date is derived rather than stated, which is why confidence on the date alone is medium. The Law has no entry-into-force article: art. 19 is the last article and deals with liability, after which the text runs straight to the President's signature of 11 May 2010. It was published in «Azərbaycan» gazette on 6 June 2010, no. 121, and in the Collection of Legislative Acts of 30 June 2010, no. 06, art. 480, which under the ordinary rule puts it in force on publication. The e-qanun record separately carries a registration date of 1 July 2011 in its «registerDate» field and leaves «effectDate» null; that field tracks the state registry entry, not commencement, but the discrepancy is recorded here rather than resolved silently. Nothing turns on it for a reader today — the rule has been binding for well over a decade on either reading. Azerbaijan has no AI-specific statute and no GDPR-style replacement law in force.
Stated maximum penalty — 300 to 500 manat, roughly USD 175 to 295 — the lowest ceiling in the atlas. Art. 19 of the Law itself sets no figure, providing only that those guilty of violating it bear liability in the manner prescribed by the legislation of Azerbaijan. The quantum sits in art. 375 of the Code of Administrative Offences (Law No. 96-VQ of 29 December 2015), «violation of the legislation on personal data». Art. 375.0.2 is the limb that reaches art. 7.3: it penalises an owner or operator for failing to ensure the protection of personal data, for failing to destroy personal data in the cases and within the periods the Law requires, and — the operative words here — «fərdi məlumatların toplanılmasının, işlənilməsinin və ya verilməsinin dayandırılmamasına görə», for failing to stop the collection, processing or transfer of personal data. That is exactly the duty art. 7.3 imposes once an objection is received, so ignoring an objection is a discrete administrative offence rather than a matter for damages alone. Art. 375.0.1 covers collecting or processing in an information system that has not passed the state registration the Law requires. Unusually, art. 375.0 draws no distinction between natural persons, officials and legal persons and applies no turnover multiplier: the band is flat at 300 to 500 manat however large the offender. The separate civil route is art. 7.4 and art. 10.1 of the Law — complaint to the relevant executive authority or to a court, with material and moral damage assessed by the court and paid by the owner.