#
Core statute and a newly consolidated supervisory body are confirmed (T1/T2), but registration/filing mechanics and territorial-scope language remain unconfirmed in available sources.
Sub-modules (5)
Regulator And AuthorityAmber
Supervisory function now sits with the Information Security Committee under MAIDD, established by government decision to regulate and enforce data-protection and information-security law.
Claims (1):
- The Government of Kazakhstan approved the Information Security Committee under the Ministry of Artificial Intelligence and Digital Development (MAIDD) to regulate, implement, and oversee personal data protection and information security, including issuing penalties for violations.
Act And InstrumentsGreen
Primary instrument is Law No. 94-V (2013), amended/operationalised by Law No. 347-VI (2020) which introduced the data protection authority function and consent/legitimate-purpose collection requirements.
Claims (2):
- The Law of the Republic of Kazakhstan of 21 May 2013 No. 94-V On Personal Data and its Protection is the primary omnibus instrument governing personal data processing in Kazakhstan.
- The Law of 25 June 2020 No. 347-VI on Amendments and Regulation of Digital Technologies established a data protection authority function and introduced requirements that personal data be collected and processed with valid consent and legitimate purpose.
Material ScopeAmber
Material scope is elaborated via subordinate MDAI Rules for the Collection and Processing of Personal Data, covering data-subject rights to information and rectification.
Claims (1):
- The MDAI Rules for the Collection and Processing of Personal Data (approved 23 October 2020) set requirements for collection, use and processing of personal data and set out data-subject rights including the right to be informed of what data is collected and for what purpose, and the right to rectify.
Territorial ScopeRed
No confirmed statutory language on extraterritorial/non-established-controller application was located in available sources.
Absence provenance: unavailable. Searched: Kazakhstan personal data law territorial scope non-established controllers, Kazakhstan extraterritorial application data protection.
Regulator Registration And FilingRed
A registrar/notification model for data-processing operators has been proposed via draft amendments but had no confirmed enactment timeline as of the last located public consultation record.
Claims (1):
- Draft amendments published for public consultation by MDAI in April 2021 proposed introducing a registrar and notification requirements for data-processing operators, with no confirmed enactment timeline.
Key findings (3)
- — source on file
- — source on file
- — source on file
Regulator & Framework
Kazakhstan's personal-data protection regime outside the Astana International Financial Centre continues to be anchored by Law No. 94-V, 'On Personal Data and its Protection', dated 21 May 2013, the primary omnibus instrument governing personal-data processing. Supervisory authority rests with the Information Security Committee, established under the Ministry of Digital Development, Innovation and Aerospace Industry (MAIDD), which regulates, implements and oversees personal-data protection and information security, including issuing penalties for violations.
This cycle brought the most substantial amendment to that framework in some time. Law No. 326-VIII, signed 24 June 2026, restated the statutory definition of personal data with effect from 11 July 2026, narrowing its focus onto specific identifiers: full name, Individual Identification Number (IIN), facial image, and facial biometric vector and its derivatives. This is a materially tighter and more technically specific definition than a general-purpose omnibus definition would typically provide, and it signals a regulatory focus on biometric and identity-linked data specifically.
The same amendment wave established two new state registers, both effective 25 August 2026: a register of persons and entities engaged in the collection and/or processing of personal data, and a separate register of personal-data security breaches. These registers create new registration and filing obligations for data controllers and processors that did not previously exist under the 2013 framework, and they represent a shift toward a more transparent, centrally-tracked population of data handlers.
Outlook
The primary consolidated text of Law No. 326-VIII on Adilet.zan.kz has not been independently retrieved this cycle; all findings here rest on secondary legal-advisory summaries from multiple firms. Confirmation against the primary statutory text would sharpen confidence in the precise scope of the new registers and the definitional changes. Watch for MAIDD's implementing procedures, expected to operationalise the registers now that their August 2026 effective date has passed.
1 further periodic run re-emitted the standing brief unchanged and is not shown.
Sources and claims (5)
- UncertainDataGuidance — The Government of Kazakhstan approved the Information Security Committee under the Ministry of Artificial Intelligence and Digital Development (MAIDD) to regulate, implement, and oversee personal data protection and information security, including issuing penalties for violations.observed
- UncertainDataGuidance (mirroring official text) — The Law of the Republic of Kazakhstan of 21 May 2013 No. 94-V On Personal Data and its Protection is the primary omnibus instrument governing personal data processing in Kazakhstan.observed
- UncertainDataGuidance — The Law of 25 June 2020 No. 347-VI on Amendments and Regulation of Digital Technologies established a data protection authority function and introduced requirements that personal data be collected and processed with valid consent and legitimate purpose.observed
- UncertainDataGuidance — The MDAI Rules for the Collection and Processing of Personal Data (approved 23 October 2020) set requirements for collection, use and processing of personal data and set out data-subject rights including the right to be informed of what data is collected and for what purpose, and the right to rectify.observed
- UncertainDataGuidance — Draft amendments published for public consultation by MDAI in April 2021 proposed introducing a registrar and notification requirements for data-processing operators, with no confirmed enactment timeline.observed