🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
KZ v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 1 failing10 sources retrieved model claude-sonnet-5 · 2026-08-05

Based mainly on secondary sources. Only 2 of the sources retrieved for this jurisdiction are official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.

Kazakhstan

KZ schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)

Last updated · 10 categories · 19 claims · 26 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
19Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Kazakhstan's personal-data framework underwent a significant statutory amendment this cycle. Law No. 326-VIII, signed 24 June 2026, restated the definition of personal data with effect from 11 July 2026, narrowing the focus onto identifiers including full name, IIN, facial image, facial biometric vector and its derivatives. The same amendment wave created two new state registers effective 25 August 2026: a register of persons and entities engaged in the collection and processing of personal data, and a separate register of personal-data security breaches. Together these changes mark the most substantial revision to Kazakhstan's data-protection architecture since Law No. 94-V, the 2013 omnibus instrument that remains the primary framework outside the AIFC.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core statute and a newly consolidated supervisory body are confirmed (T1/T2), but registration/filing mechanics and territorial-scope language remain unconfirmed in available sources.

Primary frameworkLaw of the Republic of Kazakhstan of 21 May 2013 No. 94-V On Personal Data and its Protection (as amended by Law No. 347-VI of 25 June 2020)
Supervisory authorityInformation Security Committee under the Ministry of Artificial Intelligence and Digital Development (MAIDD)
Traffic-light rationale — AmberCore statute and a newly consolidated supervisory body are confirmed (T1/T2), but registration/filing mechanics and territorial-scope language remain unconfirmed in available sources.

Sub-modules (5)

Regulator And AuthorityAmber

Supervisory function now sits with the Information Security Committee under MAIDD, established by government decision to regulate and enforce data-protection and information-security law.

Claims (1):

  • The Government of Kazakhstan approved the Information Security Committee under the Ministry of Artificial Intelligence and Digital Development (MAIDD) to regulate, implement, and oversee personal data protection and information security, including issuing penalties for violations.

Act And InstrumentsGreen

Primary instrument is Law No. 94-V (2013), amended/operationalised by Law No. 347-VI (2020) which introduced the data protection authority function and consent/legitimate-purpose collection requirements.

Claims (2):

  • The Law of the Republic of Kazakhstan of 21 May 2013 No. 94-V On Personal Data and its Protection is the primary omnibus instrument governing personal data processing in Kazakhstan.
  • The Law of 25 June 2020 No. 347-VI on Amendments and Regulation of Digital Technologies established a data protection authority function and introduced requirements that personal data be collected and processed with valid consent and legitimate purpose.

Material ScopeAmber

Material scope is elaborated via subordinate MDAI Rules for the Collection and Processing of Personal Data, covering data-subject rights to information and rectification.

Claims (1):

  • The MDAI Rules for the Collection and Processing of Personal Data (approved 23 October 2020) set requirements for collection, use and processing of personal data and set out data-subject rights including the right to be informed of what data is collected and for what purpose, and the right to rectify.

Territorial ScopeRed

No confirmed statutory language on extraterritorial/non-established-controller application was located in available sources.

Absence provenance: unavailable. Searched: Kazakhstan personal data law territorial scope non-established controllers, Kazakhstan extraterritorial application data protection.

Regulator Registration And FilingRed

A registrar/notification model for data-processing operators has been proposed via draft amendments but had no confirmed enactment timeline as of the last located public consultation record.

Claims (1):

  • Draft amendments published for public consultation by MDAI in April 2021 proposed introducing a registrar and notification requirements for data-processing operators, with no confirmed enactment timeline.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative153 words

Kazakhstan's data-protection regime rests on the omnibus Law No. 94-V of 21 May 2013 On Personal Data and its Protection, amended and operationalised by the Law of 25 June 2020 No. 347-VI. <cite index="95-3,95-4">The Law provides for the establishment of a data protection authority, which will carry out its competencies in the management of data protection supervision and enforcement and issue guidance and clarifications, and introduces new data collection and processing requirements such as the need for data to be collected and processed both with valid consent and through legitimate purposes.</cite> Supervisory capacity has since been consolidated: <cite index="34-1,34-2">the government approved the Information Security Committee under the Ministry of Artificial Intelligence and Digital Development (MAIDD), which will regulate, implement, and oversee activities in informatization, personal data protection, and information security.</cite> Registration/filing obligations remain in a state of flux, with a registrar/notification model only at draft stage as of the last confirmed public consultation.

Periodic update · new data 2026-09-28

Regulator & Framework

Kazakhstan's personal-data protection regime outside the Astana International Financial Centre continues to be anchored by Law No. 94-V, 'On Personal Data and its Protection', dated 21 May 2013, the primary omnibus instrument governing personal-data processing. Supervisory authority rests with the Information Security Committee, established under the Ministry of Digital Development, Innovation and Aerospace Industry (MAIDD), which regulates, implements and oversees personal-data protection and information security, including issuing penalties for violations.

This cycle brought the most substantial amendment to that framework in some time. Law No. 326-VIII, signed 24 June 2026, restated the statutory definition of personal data with effect from 11 July 2026, narrowing its focus onto specific identifiers: full name, Individual Identification Number (IIN), facial image, and facial biometric vector and its derivatives. This is a materially tighter and more technically specific definition than a general-purpose omnibus definition would typically provide, and it signals a regulatory focus on biometric and identity-linked data specifically.

The same amendment wave established two new state registers, both effective 25 August 2026: a register of persons and entities engaged in the collection and/or processing of personal data, and a separate register of personal-data security breaches. These registers create new registration and filing obligations for data controllers and processors that did not previously exist under the 2013 framework, and they represent a shift toward a more transparent, centrally-tracked population of data handlers.

Outlook

The primary consolidated text of Law No. 326-VIII on Adilet.zan.kz has not been independently retrieved this cycle; all findings here rest on secondary legal-advisory summaries from multiple firms. Confirmation against the primary statutory text would sharpen confidence in the precise scope of the new registers and the definitional changes. Watch for MAIDD's implementing procedures, expected to operationalise the registers now that their August 2026 effective date has passed.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. UncertainDataGuidance — The Government of Kazakhstan approved the Information Security Committee under the Ministry of Artificial Intelligence and Digital Development (MAIDD) to regulate, implement, and oversee personal data protection and information security, including issuing penalties for violations.observed
  2. UncertainDataGuidance (mirroring official text) — The Law of the Republic of Kazakhstan of 21 May 2013 No. 94-V On Personal Data and its Protection is the primary omnibus instrument governing personal data processing in Kazakhstan.observed
  3. UncertainDataGuidance — The Law of 25 June 2020 No. 347-VI on Amendments and Regulation of Digital Technologies established a data protection authority function and introduced requirements that personal data be collected and processed with valid consent and legitimate purpose.observed
  4. UncertainDataGuidance — The MDAI Rules for the Collection and Processing of Personal Data (approved 23 October 2020) set requirements for collection, use and processing of personal data and set out data-subject rights including the right to be informed of what data is collected and for what purpose, and the right to rectify.observed
  5. UncertainDataGuidance — Draft amendments published for public consultation by MDAI in April 2021 proposed introducing a registrar and notification requirements for data-processing operators, with no confirmed enactment timeline.observed

#

Consent threshold is confirmed at T1/T2; special categories, pseudonymisation/anonymisation safe-harbours are unconfirmed gaps.

Primary frameworkLaw No. 94-V (2013), as amended by Law No. 347-VI (2020)
Supervisory authorityInformation Security Committee under MAIDD
Traffic-light rationale — AmberConsent threshold is confirmed at T1/T2; special categories, pseudonymisation/anonymisation safe-harbours are unconfirmed gaps.

Sub-modules (4)

Lawful BasesAmber

Draft amendments would prohibit collection/dissemination of personal data from public resources without consent; not yet confirmed as enacted.

Claims (1):

  • Draft amendments to the Personal Data Law reintroduced by Kazakhstan's digital-development ministry would ban the collection and dissemination of personal data from public resources without consent.

Special CategoriesRed

No confirmed statutory enumeration of special/sensitive data categories was located.

Absence provenance: unavailable. Searched: Kazakhstan special categories sensitive personal data biometric genetic health law.

Pseudonymisation And AnonymisationRed

No confirmed statutory definition or safe-harbour for pseudonymisation/anonymisation was located.

Absence provenance: unavailable. Searched: Kazakhstan pseudonymisation anonymisation personal data law.

Category narrative43 words

Lawful-basis and consent standards derive from Law No. 347-VI (2020), which conditions collection/processing on valid consent and legitimate purpose. Draft amendments would further restrict use of publicly available personal data absent consent, but special-category and pseudonymisation/anonymisation rules were not confirmed in available sources.

Periodic update · new data 2026-09-28

Lawful Processing & Special Data

Two related developments under Law No. 326-VIII, both effective 25 August 2026, tighten the lawful-processing framework in Kazakhstan. First, the amendments clarify that a data subject's voluntary publication of their own personal data in the public domain does not automatically constitute consent to subsequent collection, dissemination or further processing of that data by others. This closes what had been an ambiguous gap: previously, publicly available data carried uncertain consent status for downstream processors, and this clarification narrows the lawful basis available to anyone relying on public availability alone as a justification for further processing.

Second, the same amendment wave introduced new statutory definitions of automated processing, anonymization, masking, personal-data security breaches and hashing, effective August 2026. These definitions provide the technical scaffolding underlying the security-measures obligations elsewhere in the amended law (see Controller/Processor Duties), giving controllers and processors a firmer statutory basis for understanding what counts as anonymised or masked data, and by extension what data may fall outside the scope of certain obligations.

Outlook

The practical interaction between the new consent clarification and existing sectoral practices — particularly around scraped or aggregated public data — has not been tested or clarified this cycle. Watch for MAIDD guidance or early enforcement practice interpreting the new definitions, none of which has been identified in the evidence available this cycle.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (2)
  1. UncertainIAPP — Draft amendments to the Personal Data Law reintroduced by Kazakhstan's digital-development ministry would ban the collection and dissemination of personal data from public resources without consent.observed
  2. UncertainDataGuidance — Law No. 347-VI requires that personal data be collected and processed both with valid consent and through legitimate purposes.observed

#

Partial rights (access/rectification) confirmed in force; erasure is draft-stage only; portability, restriction/objection and deadlines are unconfirmed gaps.

Primary frameworkLaw No. 94-V (2013); MDAI Rules for the Collection and Processing of Personal Data (2020)
Supervisory authorityInformation Security Committee under MAIDD
Traffic-light rationale — AmberPartial rights (access/rectification) confirmed in force; erasure is draft-stage only; portability, restriction/objection and deadlines are unconfirmed gaps.

Sub-modules (5)

Access RightGreen

Right to be informed on what personal data is collected/stored and for what purpose is set out in the 2020 Rules.

Claims (1):

  • The 2020 MDAI Rules for the Collection and Processing of Personal Data include the right to be informed on what personal data is collected and stored and for what purposes.

Rectification And ErasureAmber

Right to rectify is confirmed in force; right to erasure exists only as a draft-amendment proposal.

Claims (2):

  • The 2020 MDAI Rules for the Collection and Processing of Personal Data include the right to rectify personal data.
  • Draft amendments to the Personal Data Law would introduce a right to erasure not present in the current operative regime.

Restriction And ObjectionRed

No confirmed restriction/objection (including profiling opt-out) right was located.

Absence provenance: unavailable. Searched: Kazakhstan right to restrict processing right to object profiling opt-out.

Data PortabilityRed

No confirmed data-portability right was located.

Absence provenance: unavailable. Searched: Kazakhstan data portability right personal data law.

Deadlines And Response WindowsRed

No confirmed statutory deadline for controller response to data-subject requests was located.

Absence provenance: unavailable. Searched: Kazakhstan personal data subject access request deadline response time.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative42 words

Confirmed data-subject rights are limited to the right to be informed and the right to rectify, set out in the 2020 MDAI Rules. A right to erasure appears only in unenacted draft amendments; portability, restriction/objection and statutory response deadlines were not confirmed.

Sources and claims (3)
  1. UncertainDataGuidance — The 2020 MDAI Rules for the Collection and Processing of Personal Data include the right to be informed on what personal data is collected and stored and for what purposes.observed
  2. UncertainDataGuidance — The 2020 MDAI Rules for the Collection and Processing of Personal Data include the right to rectify personal data.observed
  3. UncertainDataGuidance — Draft amendments to the Personal Data Law would introduce a right to erasure not present in the current operative regime.observed

#

Only retention-related and draft security-measure findings are confirmed; DPO, ROPA, joint-controller, breach-notification and DPIA sub-modules are unconfirmed gaps on a regime that otherwise claims omnibus status.

Primary frameworkLaw No. 94-V (2013); Government Decree of 12 November 2013
Supervisory authorityInformation Security Committee under MAIDD
Traffic-light rationale — RedOnly retention-related and draft security-measure findings are confirmed; DPO, ROPA, joint-controller, breach-notification and DPIA sub-modules are unconfirmed gaps on a regime that otherwise claims omnibus status.

Sub-modules (7)

Accountability And DpiaRed

No confirmed DPIA trigger or accountability-documentation requirement was located.

Absence provenance: unavailable. Searched: Kazakhstan DPIA data protection impact assessment requirement.

Dpo RequirementsRed

A DataGuidance guidance note on DPO appointment references the 2013 Personal Data Law and a 2013 government decree, but the specific appointment threshold text could not be confirmed from available search results.

Absence provenance: unavailable. Searched: Kazakhstan DPO appointment threshold personal data law.

Claims (1):

  • Kazakhstan's Personal Data Law regime is accompanied by a specific DPO-appointment guidance note referencing the 2013 Law and the 2013 government decree on necessary/sufficient personal data, though the precise appointment threshold could not be confirmed from available sources.

Ropa RequirementsRed

No confirmed records-of-processing (ROPA) obligation was located.

Absence provenance: unavailable. Searched: Kazakhstan records of processing activities requirement.

Joint Controller ArrangementsRed

No confirmed joint-controller regime was located.

Absence provenance: unavailable. Searched: Kazakhstan joint controller personal data law.

Security MeasuresAmber

Draft amendments propose new data-security measures and obligations for operators, alongside stricter data-subject informing requirements.

Claims (1):

  • Draft amendments to the Personal Data Law published for consultation in April 2021 proposed new data-security measures and obligations for data operators.

Breach NotificationRed

No confirmed statutory breach-notification threshold or timeline (to regulator or data subjects) was located.

Absence provenance: unavailable. Searched: Kazakhstan personal data breach notification requirement timeline.

Retention And DisposalAmber

A 2013 government decree approved rules for determining the list of personal data necessary and sufficient for an owner/operator to perform its task, functioning as a data-minimisation constraint.

Claims (1):

  • A Government Decree of 12 November 2013 approved Rules for Determining the List of Personal Data Necessary and Sufficient for the Owner and/or Operator to Perform their Task under the Personal Data Law.

Key findings (6)

  • — source on file
  • — source on file
  • — source on file
  • — source on file
  • — source on file
  • — source on file
Category narrative46 words

Retention is partially addressed via a 2013 government decree limiting data holdings to what is necessary and sufficient for the operator's task. Draft amendments propose new security-measure obligations. DPO appointment thresholds, ROPA duties, joint-controller arrangements, breach-notification timelines and DPIA triggers were not confirmed in available sources.

Periodic update · new data 2026-09-28

Controller/Processor Duties

Law No. 326-VIII introduces a risk-based classification of personal-data controllers into small, medium and large categories, based on the volume of personal data processed. This classification is understood to scale obligations by category, though the specific obligations attached to each tier have not been detailed in the evidence retrieved this cycle.

Separately, Article 23 of the Personal Data Law — restated as 'Protection of digital objects containing personal data' — now mandates the use of masking and hashing methods for digital objects containing personal data. The specific application procedure for this mandate is to be determined by MAIDD, meaning the practical compliance requirement is not yet fully specified pending that implementing guidance. This security-measures obligation draws directly on the new statutory definitions of masking, hashing and anonymization introduced in the same amendment wave (see Lawful Processing & Special Data).

Both developments took effect 25 August 2026, alongside the new controller/processor and breach registers described under Regulator & Framework. Together they represent a coordinated tightening of controller and processor obligations: classification determines the scale of obligation, while Article 23 determines a specific technical security measure that applies regardless of tier.

Outlook

Breach-notification timelines under the new breach register were not specifically confirmed this cycle and remain a gap. Watch for MAIDD's implementing procedure for the Article 23 masking-and-hashing mandate, and for clarification of what obligations attach to each of the small, medium and large controller categories.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. UncertainDataGuidance — Kazakhstan's Personal Data Law regime is accompanied by a specific DPO-appointment guidance note referencing the 2013 Law and the 2013 government decree on necessary/sufficient personal data, though the precise appointment threshold could not be confirmed from available sources.observed
  2. UncertainDataGuidance — Draft amendments to the Personal Data Law published for consultation in April 2021 proposed new data-security measures and obligations for data operators.observed
  3. UncertainDataGuidance — A Government Decree of 12 November 2013 approved Rules for Determining the List of Personal Data Necessary and Sufficient for the Owner and/or Operator to Perform their Task under the Personal Data Law.observed

#

Data-localisation mandate is clearly confirmed at T2; adequacy/SCC/BCR/TIA mechanisms are unconfirmed gaps, consistent with a localisation-first rather than adequacy-based transfer model.

Primary frameworkLaw No. 94-V (2013); Law on Informatisation No. 418-V (2015), as amended by Law No. 128-VI (2017)
Supervisory authorityInformation Security Committee under MAIDD
Traffic-light rationale — AmberData-localisation mandate is clearly confirmed at T2; adequacy/SCC/BCR/TIA mechanisms are unconfirmed gaps, consistent with a localisation-first rather than adequacy-based transfer model.

Sub-modules (6)

Transfer MechanismsAmber

Legal commentary indicates that parallel storage of a database both in Kazakhstan and abroad would evidently also not be permitted, underscoring the localisation-first approach to transfers.

Claims (1):

  • Legal commentary on Kazakhstan's localisation regime concluded that parallel storage of a database both within Kazakhstan and abroad would also not be permitted.

Adequacy ReceivedRed

No adequacy decision received by Kazakhstan from another regime was located.

Absence provenance: unavailable. Searched: Kazakhstan adequacy decision received EU GDPR.

Adequacy GrantedRed

No adequacy decision granted by Kazakhstan to another regime was located.

Absence provenance: unavailable. Searched: Kazakhstan adequacy decision granted to other jurisdictions.

Sccs And BcrsRed

No confirmed SCC or BCR mechanism was located.

Absence provenance: unavailable. Searched: Kazakhstan standard contractual clauses binding corporate rules data transfer.

Transfer Impact AssessmentRed

No confirmed transfer-impact-assessment requirement was located.

Absence provenance: unavailable. Searched: Kazakhstan transfer impact assessment cross-border data.

Data LocalisationGreen

Personal-data databases must be maintained in Kazakhstan, and website/telecom operator user data is subject to a cross-border transfer prohibition except for roaming.

Claims (2):

  • Under the Personal Data Law No. 94-V, data operators are required to maintain their personal information databases within the territory of Kazakhstan.
  • The Law of 28 December 2017 No. 128-VI requires website operators and telecommunications operators to store subscriber/user data solely within Kazakhstan and prohibits cross-border transfer of such data except where necessary to provide roaming services.
Category narrative45 words

Kazakhstan operates a data-localisation-centric transfer regime rather than an adequacy/SCC-based model. Data operators must maintain personal-data databases within Kazakhstan, and website/telecommunications operators are further restricted from transferring collected user data abroad except for roaming purposes. No adequacy decisions, SCC/BCR mechanisms, or transfer-impact-assessment requirements were confirmed.

Sources and claims (3)
  1. UncertainDataGuidance — Legal commentary on Kazakhstan's localisation regime concluded that parallel storage of a database both within Kazakhstan and abroad would also not be permitted.observed
  2. UncertainDataGuidance — Under the Personal Data Law No. 94-V, data operators are required to maintain their personal information databases within the territory of Kazakhstan.observed
  3. UncertainDataGuidance — The Law of 28 December 2017 No. 128-VI requires website operators and telecommunications operators to store subscriber/user data solely within Kazakhstan and prohibits cross-border transfer of such data except where necessary to provide roaming services.observed

#

Single confirmed sectoral overlay (telecoms) against six unconfirmed sub-modules; broad sectoral picture is materially incomplete.

Primary frameworkLaw on Informatisation No. 418-V (2015), as amended by Law No. 128-VI (2017)
Supervisory authorityInformation Security Committee under MAIDD
Traffic-light rationale — RedSingle confirmed sectoral overlay (telecoms) against six unconfirmed sub-modules; broad sectoral picture is materially incomplete.

Sub-modules (7)

Financial Sector OverlayRed

No confirmed financial-sector-specific personal-data overlay (e.g., National Bank rules) was located.

Absence provenance: unavailable. Searched: Kazakhstan banking secrecy law National Bank personal data financial sector.

Health Sector OverlayRed

No confirmed health-sector-specific personal-data overlay was located.

Absence provenance: unavailable. Searched: Kazakhstan health data protection law patient records.

Telecoms And EprivacyAmber

Website and telecommunications operators must identify users intending to publish information on their platforms, under the Informatisation Law as amended.

Claims (1):

  • Under the Law of 24 November 2015 No. 418-V on Informatisation, as amended by Law No. 128-VI of 28 December 2017, owners of publicly available electronic informational resources (website operators) are required to identify website users who intend to publish information on an operator's website.

Employment DataRed

No confirmed employment-data-specific overlay was located.

Absence provenance: unavailable. Searched: Kazakhstan employment data protection labour code personal data.

Credit And ScoringRed

No confirmed credit-scoring-specific personal-data overlay was located.

Absence provenance: unavailable. Searched: Kazakhstan credit scoring bureau personal data law.

EducationRed

No confirmed education-sector-specific personal-data overlay was located.

Absence provenance: unavailable. Searched: Kazakhstan education sector student data protection law.

InsuranceRed

No confirmed insurance-sector-specific personal-data overlay was located.

Absence provenance: unavailable. Searched: Kazakhstan insurance sector personal data law.

Category narrative34 words

Only a telecoms/online-identification overlay is confirmed: website and telecommunications operators face user-identification obligations under the Informatisation Law regime. Financial, health, employment, credit-scoring, education and insurance sector-specific personal-data overlays were not confirmed in available sources.

Sources and claims (1)
  1. UncertainDataGuidance — Under the Law of 24 November 2015 No. 418-V on Informatisation, as amended by Law No. 128-VI of 28 December 2017, owners of publicly available electronic informational resources (website operators) are required to identify website users who intend to publish information on an operator's website.observed

#

No sub-module returned confirmed evidence; this module carries a full absent-field gap rather than a substantive finding.

Traffic-light rationale — Not assessedNo sub-module returned confirmed evidence; this module carries a full absent-field gap rather than a substantive finding.

Sub-modules (6)

Cookies And TrackersRed

No confirmed cookie/tracker consent rule located.

Absence provenance: unavailable. Searched: Kazakhstan cookie consent law tracker regulation.

Dark PatternsRed

No confirmed dark-pattern prohibition located.

Absence provenance: unavailable. Searched: Kazakhstan dark patterns consumer protection data law.

Opt Out SignalsRed

No confirmed recognition of opt-out signals (e.g., GPC) located.

Absence provenance: unavailable. Searched: Kazakhstan global privacy control opt-out signal recognition.

Clean Rooms And DcrRed

No confirmed clean-room/data-collaboration-room rule located.

Absence provenance: unavailable. Searched: Kazakhstan data clean room data collaboration regulation.

Cross Context AdvertisingRed

No confirmed cross-context-advertising rule (sale/share analogue) located.

Absence provenance: unavailable. Searched: Kazakhstan cross-context advertising data sale share regulation.

Direct MarketingRed

No confirmed direct-marketing consent/suppression regime located.

Absence provenance: unavailable. Searched: Kazakhstan direct marketing consent suppression list law.

Category narrative25 words

No confirmed cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room framework, cross-context-advertising rule, or direct-marketing consent/suppression regime specific to Kazakhstan was located in available sources.

#

No sub-module returned confirmed evidence in this research pass; full absent-field gap.

Traffic-light rationale — Not assessedNo sub-module returned confirmed evidence in this research pass; full absent-field gap.

Sub-modules (6)

Profiling RestrictionsRed

No confirmed profiling-restriction provision located.

Absence provenance: unavailable. Searched: Kazakhstan profiling restriction automated decision personal data law.

Automated Decision Making TransparencyRed

No confirmed ADM transparency/explanation right located.

Absence provenance: unavailable. Searched: Kazakhstan automated decision making transparency right explanation.

Ai Risk AssessmentsRed

No confirmed AI-specific risk-assessment obligation located.

Absence provenance: unavailable. Searched: Kazakhstan artificial intelligence law risk assessment data.

Biometric RegimeRed

No confirmed biometric-data-specific regime (facial recognition, fingerprint, gait) located.

Absence provenance: unavailable. Searched: Kazakhstan biometric data law facial recognition fingerprint.

Genetic DataRed

No confirmed genetic-data-specific regime located.

Absence provenance: unavailable. Searched: Kazakhstan genetic data protection law.

State Surveillance CarveoutsRed

No confirmed national-security/state-surveillance carve-out and its limits located.

Absence provenance: unavailable. Searched: Kazakhstan national security exemption data protection surveillance.

Category narrative26 words

No confirmed profiling restriction, ADM-transparency right, AI-specific risk-assessment obligation, biometric-data regime, genetic-data regime, or state-surveillance carve-out specific to Kazakhstan's personal-data framework was located in available sources.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

#

No sub-module returned confirmed Kazakhstan-specific evidence in this research pass; full absent-field gap.

Traffic-light rationale — Not assessedNo sub-module returned confirmed Kazakhstan-specific evidence in this research pass; full absent-field gap.

Sub-modules (5)

Age VerificationRed

No confirmed statutory age-of-consent threshold for data processing located.

Absence provenance: unavailable. Searched: Kazakhstan child personal data age consent minors law.

Minor Profiling BansRed

No confirmed profiling ban specific to minors located.

Absence provenance: unavailable. Searched: Kazakhstan minors profiling ban personal data.

Education SettingsRed

No confirmed education-setting-specific rule located.

Absence provenance: unavailable. Searched: Kazakhstan school student data protection rule.

Dependent AdultsRed

No confirmed dependent-adult protection provision located.

Absence provenance: unavailable. Searched: Kazakhstan dependent adults incapacitated persons data protection.

Category narrative19 words

No confirmed Kazakhstan-specific age-of-consent threshold, parental-consent mechanism, minor-profiling ban, education-setting rule, or dependent-adult protection was located in available sources.

#

Penalty framework and a 2025 institutional consolidation are confirmed; enforcement track record, funding/capacity, and collective/private redress remain unconfirmed gaps.

Primary frameworkCode of the Republic of Kazakhstan of 5 July 2014 No. 235-V on Administrative Infractions
Supervisory authorityInformation Security Committee under MAIDD
Traffic-light rationale — AmberPenalty framework and a 2025 institutional consolidation are confirmed; enforcement track record, funding/capacity, and collective/private redress remain unconfirmed gaps.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The Administrative Infractions Code No. 235-V provides the administrative-liability framework applicable to personal-data violations; the 2025 Information Security Committee holds express power to issue penalties.

Claims (2):

  • The Code of the Republic of Kazakhstan of 5 July 2014 No. 235-V on Administrative Infractions provides the administrative-liability framework applicable to violations of personal data protection requirements.
  • The Government of Kazakhstan approved the Information Security Committee under MAIDD, which will monitor information security across state bodies, individuals, and legal entities, respond to incidents, issue penalties for violations of personal-data and information-security legislation, and coordinate with national and international partners on cybersecurity policy.

Enforcement Activity IndexRed

No confirmed record of major enforcement decisions or fines in the last 12 months was located.

Absence provenance: unavailable. Searched: Kazakhstan data protection enforcement fine decision 2025 2026.

Regulator Funding And CapacityRed

No confirmed headcount or funding data for the Information Security Committee/MAIDD data-protection function was located.

Absence provenance: unavailable. Searched: Kazakhstan Information Security Committee MAIDD budget staffing.

Collective Redress And Class ActionsRed

No confirmed collective-redress or class-action mechanism for data-subject claims was located.

Absence provenance: unavailable. Searched: Kazakhstan class action collective redress personal data.

Private Right Of ActionRed

No confirmed private right of direct court access for data-subject claims was located.

Absence provenance: unavailable. Searched: Kazakhstan private right of action personal data court claim.

Recent Developments 180DAmber

The most recent confirmed development is the government's approval of the Information Security Committee under MAIDD, consolidating data-protection and information-security oversight, penalty issuance, and incident response.

Claims (1):

  • The Government of Kazakhstan approved the Information Security Committee under MAIDD, which will monitor information security across state bodies, individuals, and legal entities, respond to incidents, issue penalties for violations of personal-data and information-security legislation, and coordinate with national and international partners on cybersecurity policy.
Category narrative65 words

Administrative liability for personal-data violations is grounded in the Code of the Republic of Kazakhstan of 5 July 2014 No. 235-V on Administrative Infractions. The most material recent development is the government's 2025 establishment of an Information Security Committee under MAIDD with express power to issue penalties for violations. Enforcement-activity track record, regulator funding/capacity, collective-redress mechanisms and private-right-of-action provisions were not confirmed in available sources.

Periodic update · new data 2026-09-28

Enforcement & Redress

Reports indicate that recent reforms have strengthened administrative liability for violations in the field of personal-data protection and introduced obligations to notify citizens in the event of data breaches. This is reported with probable rather than confirmed confidence, and no specific named enforcement action or decision has been identified in the evidence retrieved this cycle — the finding is a general strengthening trend rather than a discrete enforcement event.

The Information Security Committee under MAIDD retains authority to issue penalties for violations of the personal-data framework, a standing feature of the regime's enforcement architecture. The new breach-notification obligation, once its specific procedural requirements are clarified, is expected to interact with the enforcement track by giving the regulator visibility into breach events through the newly-created breach register (see Regulator & Framework), which itself is effective 25 August 2026.

Outlook

Watch for the first substantive enforcement action or administrative penalty decision under the strengthened liability regime, and for confirmation of the specific breach-notification timelines that citizens and the regulator can expect once the breach register becomes operational.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (2)
  1. UncertainDataGuidance (mirroring official text) — The Code of the Republic of Kazakhstan of 5 July 2014 No. 235-V on Administrative Infractions provides the administrative-liability framework applicable to violations of personal data protection requirements.observed
  2. UncertainDataGuidance — The Government of Kazakhstan approved the Information Security Committee under MAIDD, which will monitor information security across state bodies, individuals, and legal entities, respond to incidents, issue penalties for violations of personal-data and information-security legislation, and coordinate with national and international partners on cybersecurity policy.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 1 failing check(s).

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metFAIL
tier_a_b_national_primary_pct0.0
aggregator_only_jurisdiction_count1
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Kazakhstan
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 19 claim(s) (19 category placement(s)), 26 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer impact assessment
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redressregulator powers and penalties
Art. 81Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressprivate right of action

Self-audit

regulator_and_framework, lawful_processing_and_special_data (consent_thresholds), data_subject_rights (access/rectification), cross_border_and_adequacy (data_localisation), sectoral_watch (telecoms), and enforcement_and_redress (regulator_powers, recent_developments) rest on T1/T2 sources (official law texts, government-authorised rules, and government-decision news reporting). controller_processor_duties (dpo_requirements) rests on a T3 guidance-note title only, with underlying content inaccessible. adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups returned no confirmed Kazakhstan-specific evidence in this research pass (T4/absent) despite targeted searches, and are emitted as explicit gaps rather than fabricated obligations. Special categories, pseudonymisation/anonymisation, breach notification timelines, ROPA, joint-controller arrangements, DPIA triggers, adequacy/SCC/BCR/TIA mechanisms, and most sectoral overlays beyond telecoms are unconfirmed.

Unresolved questions (10):

  • Exact commencement/effective date of the Information Security Committee's operative powers under MAIDD
  • Whether the 2021 draft amendments (registrar/notification, right to erasure, ban on public-data collection without consent) have since been enacted
  • Specific DPO appointment threshold text under the Personal Data Law
  • Statutory breach-notification timeline and threshold, if any
  • Sector-specific personal-data overlays for financial, health, employment, credit-scoring, education and insurance sectors
  • Availability of adequacy decisions, SCCs, BCRs or transfer-impact-assessment requirements beyond the localisation mandate
  • Cookie/adtech-specific regulation and recognition of opt-out signals
  • Biometric-data-specific and AI-specific governance provisions
  • Statutory age-of-consent threshold and parental-consent mechanism for minors' data
  • Enforcement track record (fines, decisions) in the last 12 months and regulator funding/headcount

Escalate to primary-source review: yes