UPPERSETUP logo

Personal Data and Localisation in Kazakhstan in 2026: Law No. 94-V After the Amendments, the Ban on Automated Decisions, Two State Registers and the Fines

Personal Data and Localisation in Kazakhstan in 2026: Law No. 94-V After the Amendments, the Ban on Automated Decisions, Two State Registers and the Fines

The Law of the Republic of Kazakhstan “On Personal Data and Their Protection” of 21 May 2013 No. 94-V remains in force after the Digital Code took effect on 12 July 2026. The Digital Code neither repealed nor replaced it: the only act it repealed is the 2003 law on electronic documents and electronic digital signatures, and on personal data it refers expressly back to Law No. 94-V. The operative text of Law No. 94-V is the version in force as at 25 August 2026 — the day the largest amendment package in the statute’s history took effect.

Three developments that make any compliance assessment prepared before August 2026 out of date.

One: from 25 August 2026 Law No. 94-V carries two state registers and a size-based classification of processors. Article 10-1 introduced notification of the start and end of processing, with the details entered in the register of persons collecting and/or processing personal data; article 23-2 created the register of personal data security breaches; and article 25-1 divided owners and operators into three classes by the number of unique data subjects. All three articles were inserted by the Law of 24 June 2026 No. 326-VIII.

Two: automated processing producing legal consequences has been prohibited since 18 January 2026.Article 19-1 of Law No. 94-V, inserted by the Law of 17 November 2025 No. 231-VIII, is framed as a prohibition with consent as the exception, not as a right to object: “Запрещается автоматизированная обработка персональных данных, в результате которой у субъекта возникают, изменяются или прекращаются права, законные интересы, за исключением случая, когда получено согласие субъекта, или в случаях, предусмотренных законами Республики Казахстан.” Structurally that is stricter than article 22 of the GDPR.

Three: the maximum administrative fine reaches 2,000 times the monthly calculation index (MCI) — KZT 8,650,000 at the 2026 MCI of KZT 4,325. Part 4 of article 79 of the Code of Administrative Offences applies to a large enterprise where a failure to take protective measures has resulted in loss, or in unlawful collection and processing, of personal data.

The Legal Framework: Two Layers, and Why They Must Not Be Conflated

Personal data regulation in Kazakhstan in 2026 operates on two layers: the sectoral Law No. 94-V, which remains the principal statute, and the Digital Code, which builds a layer of digital-environment rights on top of it. The Digital Code did not codify personal data law and did not absorb Law No. 94-V — it regulates the digital environment generally and refers personal data back to the sectoral statute.

Instrument

Number and date

In force from

Role in personal data regulation

Law “On Personal Data and Their Protection”

No. 94-V of 21 May 2013

26 November 2013; operative version as at 25 August 2026

The principal sectoral act. Consent, localisation, cross-border transfer, automated processing, the registers, data subject rights, the regulator’s competence

Digital Code of the Republic of Kazakhstan

No. 255-VIII of 9 January 2026

12 July 2026 — article 106 of the Code itself states only the formula “по истечении шести месяцев после дня его первого официального опу­блико­вания”

The overlay. Digita­l-envi­ronment rights: erasure and ano­nymisa­tion, algorithmic systems, the citizen’s digital space, biometric authe­nti­cation

Code of Admi­nistra­tive Offences

No. 235-V of 5 July 2014

1 January 2015

Article 79 — admi­nistra­tive liability

Criminal Code

No. 226-V of 3 July 2014

1 January 2015

Article 147 — criminal liability

Law “On the Republican Budget for 2026–2028”

No. 239-VIII of 8 December 2025

1 January 2026

Article 7(4): the monthly calculation index is KZT 4,325

What the Digital Code actually repealed. Article 106 of the Code runs to two paragraphs, and the second is the only repealing provision in the entire enactment: “Признать утратившим силу Закон Республики Казахстан от 7 января 2003 года «Об электронном документе и электронной цифровой подписи».” Law No. 94-V does not appear in that list, in whole or in part. Nor does the Code contain a chapter of consequential amendments to other acts: those were carried by separate laws.

Author’s assessment: the “code on top of a statute” structure is the main source of error in this area. The arrival of a Digital Code is routinely read as replacing the sectoral law, and from that reading follows the conclusion that Law No. 94-V no longer needs checking. The practical consequence: localisation, the consent mechanics, cross-border transfer and every administrative fine stayed exactly where they were — in Law No. 94-V and in article 79 of the Code of Administrative Offences. The Digital Code added rights for individuals; it did not rewrite obligations for business.

The amendment chain of Law No. 94-V from 2015 to 2026 runs to twenty-two instruments. Six of them decide the subject matter of this analysis.

Amending law

Signed

In force from

What it did

No. 419-V

24 November 2015

1 January 2016

Introduced the requirement to store personal data in a database located in the territory of Kazakhstan — article 12

No. 96-VII

30 December 2021

2 March 2022

Rewrote article 8 on consent and inserted articles 8-1 and 8-2 — the state and non-state services

No. 231-VIII

17 November 2025

18 January 2026

Inserted article 19-1 — requirements for automated processing of personal data

No. 256-VIII

9 January 2026

12 July 2026

The Digital Code’s companion law: terminology alignment — “объекты инфо­рмати­зации” replaced by “цифровые объекты”; the definition of biometric data deleted

No. 326-VIII

24 June 2026

25 August 2026

Inserted articles 10-1, 23-2 and 25-1 — the two registers and the classi­fica­tion; rewrote the definitions and articles 6, 7, 8 and 12

No. 350-VIII

14 July 2026

14 September 2026 (not yet in force)

Supplements article 9

> One further instrument is routinely missed: Law No. 311-VIII of 12 June 2026 takes effect only on 1 January 2027 and supplements article 9. It cannot be cited as operative law during 2026.

The Key Definitions: Why a Paper Database and a Digital Object Are Different Things

Personal data, under article 1(2) of Law No. 94-V, means “сведения или совокупность сведений о субъекте персональных данных, дополненные одним или несколькими идентификаторами персональных данных”.The definition was put in these terms by the Law of 9 January 2026 No. 256-VIII, in force from 12 July 2026, and is built around the new concept of an identifier rather than around the medium the data sits on. Law No. 326-VIII did not amend article 1(2).

Term

Definition in article 1 of Law No. 94-V

Personal data

“сведения или совокупность сведений о субъекте персональных данных, дополненные одним или несколькими иденти­фика­торами персональных данных”

Personal data identifier

“информация, позволяющая иденти­фици­ровать субъект персональных данных или связать отдельные наборы данных о нем в совокупность сведений, позволяющих иденти­фици­ровать данного субъекта”

Data subject

“физическое лицо, к которому относятся персональные данные”

База (database) containing personal data

“совокупность упорядоченных персональных данных на бумажном носителе

Digital object containing personal data

“цифровой объект, содержащий совокупность упорядоченных персональных данных”

Owner

“госу­дарстве­нный орган, физическое и (или) юридическое лицо, реализующие в соответствии с законами Республики Казахстан право владения, пользования и распоряжения базой на бумажном носителе и (или) цифровым объектом, содержащим персональные данные”

Operator

“госу­дарстве­нный орган, физическое и (или) юридическое лицо, осу­ще­ствляющие сбор, обработку и защиту персональных данных”

Third party

“лицо, не являющееся субъектом, собственником и (или) оператором, но связанное с ними (ним) обстоя­те­льствами или правоо­тно­шениями по сбору, обработке и защите персональных данных”

Automated processing of personal data

“обработка персональных данных объектом инфо­рмати­зации, исключающая участие собственника и (или) оператора, а также третьего лица в процессе обработки”

A distinction to settle before reading any other provision of the statute. After the amendments, “база” means a paper record set only: “совокупность упорядоченных персональных данных на бумажном носителе”. The electronic counterpart is the “цифровой объект, содержащий персональные данные”. The practical consequence: a provision that speaks only of a “база” does not reach a server, while a provision that speaks of “база и (или) цифровой объект” reaches both. That is precisely why Law No. 326-VIII rewrote the localisation requirement — so that it covers the digital object expressly rather than by analogy.

“Owner” and “operator” are not the Kazakh equivalents of “controller” and “processor”, and substituting one set for the other does not work. The owner is defined by the rights of possession, use and disposal over a database or digital object; the operator by actually carrying out collection, processing and protection. One entity can be owner and operator at once, and the statute addresses obligations to the composite formula “собственник и (или) оператор, а также третье лицо” — to all three at the same time.

The term “biometric personal data” no longer carries a definition in Law No. 94-V. Article 1(1), which contained it, was deleted by the Law of 9 January 2026 No. 256-VIII with effect from 12 July 2026. The term nevertheless still appears in the statute — for example in relation to the collection of biometric data in public places.

Author’s assessment: this is a real definitional gap, opened on 12 July 2026. Biometrics remain regulated, but their legal definition has disappeared from the sectoral statute, and article 48 of the Digital Code defines only “биометрическая аутентификация”, not “биометрические данные”. The practical consequence: a borderline attribute — voice characteristics or gait, say — can no longer be classified against an express statutory definition, and the position has to be built on article 48 of the Digital Code, which treats biometric data used for digital authentication as personal data, and on the subordinate Rules.

Law No. 326-VIII inserted nine new sub-paragraphs into article 1, in force from 25 August 2026: deletion of personal data, anonymisation, masking, dissemination of personal data in publicly available sources, the register of persons collecting and/or processing personal data, the digital object containing personal data, the personal data identifier, a personal data security breach, and hashing of digital data. One clarification: “нарушение безопасности персональных данных” is not new — it existed as sub-paragraph 15-1) and was moved to 15-2) with the words “и удаление” added, while the vacated 15-1) was taken by the breach register. Without these definitions the new articles 10-1, 23-2 and 25-1 could not operate.

Consent: Three Routes, and Mandatory Integration with the State Service

Consent to the collection and processing of personal data is given under article 8 of Law No. 94-V and may be expressed in three ways: on paper, through the state personal data access control service under article 8-1, or through a non-state service under article 8-2. The current consent architecture was introduced by the Law of 30 December 2021 No. 96-VII, in force from 2 March 2022, and extended by Law No. 326-VIII from 25 August 2026.

Integration with the state service is not a recommendation, and the duty is drafted conditionally. Article 8-1(1) reads:

“Собственники и (или) операторы, третьи лица в случае взаимодействия с цифровыми объектами государственных органов и (или) государственных юридических лиц, содержащими персональные данные, обеспечивают интеграцию собственных цифровых объектов, задействованных в процессах сбора и обработки персональных данных, с государственным сервисом, за исключением случаев, предусмотренных подпунктами 1), 2), 2-1), 9) и 9-2) статьи 9 настоящего Закона. […] В иных случаях интеграция с государственным сервисом осуществляется на добровольной основе.” The omitted paragraphs deal with compliance with the legislation on state secrets and protected confidences, and with the authorised body setting the integration procedure.

The trigger is the fact of interacting with state digital objects, not the sector and not the volume of processing. A company that receives or transmits personal data through state information systems — which covers virtually any business dealing with eGov, the pension fund, or state tax or banking services — must integrate. A company that has no dealings with state digital objects integrates voluntarily.

The functions of the state service under article 8-1(2) are: the giving of consent or refusal by the data subject; withdrawal of consent by the data subject; notification of the data subject about actions taken with their personal data; and provision to the data subject of details of the owners and operators holding consent to collect.

The Rules on the functioning of the state service were approved by order of the Minister of Digital Development, Innovation and Aerospace Industry of 29 April 2022 No. 144/НҚ and took effect on 24 May 2022. They were amended by order of 5 March 2026 No. 120/НҚ, in force from 23 March 2026: automated processing was added and the access processes were expanded — clause 3 of the Rules now lists five processes, including proactive services using biometrics and an electronic digital signature, a mode generating a fifteen-minute security token, and a one-time-code channel through “Мобильное правительство”. Clause 3 was subsequently restated by order of 19 June 2026 No. 332/НҚ, in force from 12 July 2026 — so the March 2026 wording no longer applies to that clause.

The power to approve those rules sits with the authorised body under article 27-1(7-2) and (7-4) of Law No. 94-V:it “утверждает правила функционирования государственного сервиса контроля доступа к персональным данным” and “утверждает правила интеграции с государственным сервисом контроля доступа к персональным данным”.

Processing without consent is permitted only on the grounds listed in article 9 of Law No. 94-V. The list is exhaustive and is extended regularly. As at 25 August 2026 the operative numbering ends at sub-paragraph 9-5), inserted by Law No. 326-VIII, with 10) as the article’s final sub-paragraph. Sub-paragraph 9-6) is inserted by the Law of 12 June 2026 No. 311-VIII with effect from 1 January 2027, and 9-7) by the Law of 14 July 2026 No. 350-VIII with effect from 14 September 2026; neither applies as at 25 August 2026.

Author’s assessment: the closed nature of the article 9 list is the fundamental divergence from the European model. Under the GDPR, a controller’s legitimate interest is a free-standing basis for processing. Law No. 94-V has no equivalent: if the situation is not described in article 9, processing requires consent. The practical consequence is that lawful bases developed for European compliance cannot be carried across into Kazakh documentation — a legitimate interests assessment achieves nothing here as a matter of law.

Two practically important timing rules sit in the statute itself rather than in subordinate legislation, and the distinction matters. Article 8(5) of Law No. 94-V: “Срок действия согласия… не может превышать срок, необходимый для достижения целей сбора и обработки”; article 8(7): “В течение пятнадцати рабочих дней собственник и (или) оператор, а также третье лицо обязаны прекратить обработку…”. Both were inserted by the Law of 17 November 2025 No. 231-VIII and have applied since 18 January 2026. The Rules on collecting and processing personal data, approved by order of 21 October 2020 No. 395/НҚ and amended by order of 11 March 2026 No. 133/НҚ, merely restate them.

The legal form chosen for a Kazakh presence determines which consent route has to be built first: AIFC companies and ordinary LLPs interact with state digital objects differently — the comparison of the two jurisdictions inside the country is set out in AIFC or LLP: Choosing a Jurisdiction Inside Kazakhstan in 2026.

Localisation: What Exactly Has to Sit in Kazakhstan

Article 12(2) of Law No. 94-V, in the version in force from 25 August 2026, requires personal data to be stored “в базе и (или) цифровом объекте, которые находятся на территории Республики Казахстан”. Before that date the provision spoke only of a “база, находящаяся на территории Республики Казахстан”.

The operative text of article 12(2):

“Хранение персональных данных осуществляется собственником и (или) оператором, а также третьим лицом в базе и (или) цифровом объекте, которые находятся на территории Республики Казахстан. Срок хранения персональных данных определяется датой достижения целей их сбора и обработки, если иное не предусмотрено законодательством Республики Казахстан.”

Why the 2026 rewording is substantive rather than cosmetic. After the Law No. 326-VIII amendments, “база” means a paper record set only. The former wording, which required storage “в базе”, on a literal reading did not reach server storage at all. The new wording closes that gap by naming the digital object expressly. The practical consequence: the argument that the localisation requirement does not reach electronic systems is, from 25 August 2026, finally spent.

The localisation requirement carries no exemption by data category, sector or processing volume. It is addressed to the composite “собственник и (или) оператор, а также третье лицо” and attaches to storage as such.

What is required

Provision

Content

Storage in Kazakhstan

Article 12(2) of Law No. 94-V

The database and/or digital object must be located in the territory of Kazakhstan

Collection and processing of restri­cted-a­ccess data through digital objects in Kazakhstan

Clause 13 of the Rules approved by order No. 179/НҚ

“Сбор и обработка персональных данных ограниченного доступа осу­ще­ствляются посредством цифровых объектов, размещенных на территории Республики Казахстан”

Physical location — a server room or data centre in Kazakhstan

Clause 14 of the Rules approved by order No. 179/НҚ

Storage takes place “в базе, находящейся в серверном помещении или центре обработки данных, расположенном на территории Республики Казахстан

Retention period

Article 12(2) of Law No. 94-V

Determined by the date the collection and processing purposes are achieved, unless a statute provides otherwise

The subordinate rules are stricter than the statute, and the difference needs reading precisely. The Rules on measures to protect personal data taken by the owner, operator and third party were approved by order of the Minister of Digital Development, Innovation and Aerospace Industry of 12 June 2023 No. 179/НҚ, registered with the Ministry of Justice on 15 June 2023 under No. 32810. Clause 13 of those Rules requires the collection and processing of restricted-access personal data — not merely its storage — to be carried out through digital objects hosted in Kazakhstan.

The distinction that resolves most interpretive disputes here. Article 12 of the statute is a rule about where data is stored. Clause 13 of the Rules is a rule about where it is collected and processed, and only for restricted-access data. The practical consequence: for publicly available personal data, processing outside Kazakhstan is not prohibited provided storage is localised; for restricted-access data, the processing itself cannot be moved offshore either.

Localisation does not prohibit cross-border transfer. That is a separate regime, governed by article 16 and analysed in the next section. Localising storage while transferring data abroad is legally possible — on the article 16 conditions.

The order No. 179/НҚ Rules were restated in a new edition by order of the Deputy Prime Minister — Minister of Artificial Intelligence and Digital Development of 22 June 2026 No. 338/НҚ, in force from 12 July 2026. The content of that restatement is analysed below, in the section on protective measures.

> Author’s assessment: localisation in Kazakhstan is an infrastructure obligation rather than a documentary one, and that sets it apart from most of the statute’s other requirements. Consent forms, a processing policy and notices can be put right in weeks. Moving a production database into a Kazakh data centre is a project measured in months, with migration, testing and the re-pointing of integrations. The practical consequence: where the localisation decision is not taken before a product goes to market, the cost of remediation exceeds the cost of building the architecture correctly by an order of magnitude.

Cross-Border Transfer: A Two-Tier Test and No Country List

Article 16 of Law No. 94-V permits cross-border transfer of personal data to foreign states only where those states ensure the protection of personal data, and where they do not, only on four exhaustive grounds. Cross-border transfer is defined in article 16(1) itself as “передача персональных данных на территорию иностранных государств”.

Article 16, verbatim:

“2. В соответствии с настоящим Законом трансграничная передача персональных данных на территорию иностранных государств осуществляется только в случае обеспечения этими государствами защиты персональных данных. 3. Трансграничная передача персональных данных на территорию иностранных государств, не обеспечивающих защиту персональных данных, может осуществляться в случаях: 1) наличия согласия субъекта или его законного представителя на трансграничную передачу его персональных данных; 2) предусмотренных международными договорами, ратифицированными Республикой Казахстан; 3) предусмотренных законами Республики Казахстан, если это необходимо в целях защиты конституционного строя, охраны общественного порядка, прав и свобод человека и гражданина, здоровья и нравственности населения; 4) защиты конституционных прав и свобод человека и гражданина, если получение согласия субъекта или его законного представителя невозможно. 4. Трансграничная передача персональных данных на территорию иностранных государств может быть запрещена или ограничена законами Республики Казахстан. 5. Особенности трансграничной передачи служебной информации об абонентах и (или) пользователях услуг связи определяются Законом Республики Казахстан «О связи».”

Tier

Condition

What is required

First — the state ensures protection

Article 16(2)

Transfer is permitted with no further basis

Second — the state does not ensure protection

Article 16(3)

One of four grounds: the data subject’s consent; a ratified international treaty; a Kazakh statute serving the listed public purposes; protection of consti­tu­tional rights where consent cannot be obtained

Prohibition or restriction

Article 16(4)

May be imposed by Kazakh statutes

Sectoral carve-out

Article 16(5)

Service information on commu­nica­tions subscribers — under the Law “On Commu­nica­tions”

Kazakhstan publishes no list of states that ensure the protection of personal data. The phrase “перечень государств” does not appear anywhere in Law No. 94-V, and article 27-1, which sets out the authorised body’s competence, confers no power to adopt one. The practical consequence: adequacy of the destination state is assessed by the transferring party itself, and that assessment is verified by nobody in advance. The only way to remove the uncertainty is to obtain the data subject’s consent to the cross-border transfer under article 16(3)(1) rather than rely on a self-made adequacy classification.

Article 16 is the only substantive article of Law No. 94-V whose last amendment dates from 2017. That amendment came from the Law of 28 December 2017 No. 128-VI. For precision: nine articles — 2, 4, 5, 11, 13, 14, 21, 29 and 30 — have never been amended at all since 2013, and several are substantive, including article 5 on the principles of collection, processing and protection and article 11 on confidentiality. The reform packages of 2021, 2025 and 2026 all left it alone: Law No. 96-VII, Law No. 231-VIII, Law No. 326-VIII and the Digital Code alike.

Author’s assessment: article 16 standing still through three waves of tightening is architecture, not oversight. Kazakhstan has staked its control over data on localisation of storage rather than on regulating cross-border flows. What that means for an international group: the bottleneck is not at the border but in the data centre. Configuring a lawful cross-border transfer is easier than relocating storage — and it is article 12, not article 16, that dictates the shape of the solution.

The Digital Code laid down no cross-border transfer rules for personal data. Article 98 of the Code, on the protection of digital data, addresses technical and organisational measures and cryptography and contains neither a localisation rule nor a transfer rule. Article 31(9) is addressed to a narrow class — “собственникам и (или) владельцам платформ обмена и оборота продуктов цифровых данных” — and prohibits them, among other things, from “осуществлять размещение или хранение продуктов цифровых данных вне территории Республики Казахстан, если такое размещение или хранение ограничено”, and from trading in raw data including personal data. The qualifier “если такое размещение или хранение ограничено” makes it a cross-reference rather than a free-standing localisation requirement.

The practical side of cross-border settlement and currency control, which usually travels alongside cross-border data transfer, is covered in Opening a Bank Account in Kazakhstan for a Foreign Company.

The Ban on Automated Decisions: Article 19-1, and Why It Is a Prohibition Rather Than a Right to Object

Article 19-1 of Law No. 94-V prohibits automated processing of personal data that creates, alters or terminates a data subject’s rights and legitimate interests, save where the subject’s consent has been obtained or where a statute so provides. The article was inserted by the Law of 17 November 2025 No. 231-VIII and took effect on 18 January 2026, sixty calendar days after first official publication.

Article 19-1 in full:

Статья 19-1. Требования к автоматизированной обработке персональных данных 1. Запрещается автоматизированная обработка персональных данных, в результате которой у субъекта возникают, изменяются или прекращаются права, законные интересы, за исключением случая, когда получено согласие субъекта, или в случаях, предусмотренных законами Республики Казахстан. 2. Собственник и (или) оператор, а также третье лицо обязаны разъяснить субъекту порядок автоматизированной обработки его персональных данных и возможные последствия, предоставить возможность заявить возражение против автоматизированной обработки его персональных данных, а также разъяснить порядок защиты субъектом своих прав, свобод и законных интересов. 3. Собственник и (или) оператор, а также третье лицо обязаны рассмотреть возражение, указанное в пункте 2 настоящей статьи, в течение трех рабочих дней со дня его получения и уведомить субъекта о результатах рассмотрения такого возражения. Субъект вправе обжаловать действия (бездействие) собственников и (или) оператора, а также третьего лица в порядке, установленном законами Республики Казахстан.”

Automated processing is defined in article 1(2-3) as “обработка персональных данных объектом информатизации, исключающая участие собственника и (или) оператора, а также третьего лица в процессе обработки”.

Duty under article 19-1

Content

Deadline

Do not carry out automated processing with legal consequences without consent

Paragraph 1 — a prohibition; consent or statute is the exception

Continuously, from 18 January 2026

Explain the processing and its possible conse­que­nces

Paragraph 2

Before processing

Provide a means of lodging an objection

Paragraph 2

Before processing

Explain how the subject may protect their rights

Paragraph 2

Before processing

Consider the objection and notify the outcome

Paragraph 3

Three working days from receipt of the objection

The drafting differs from article 22 of the GDPR, and the difference is fundamental. The European provision gives the data subject a right not to be subject to a decision based solely on automated processing, with carve-outs for contract, law and explicit consent. The Kazakh provision states an outright prohibition on the processing, from which consent is the exit. The practical consequence: in Kazakhstan the absence of an objection legitimises nothing — without consent or an express statutory basis, automated processing with legal consequences is prohibited from the outset.

Three working days to deal with an objection is the shortest response deadline anywhere in Law No. 94-V. For comparison: withdrawal of consent obliges the owner or operator to stop processing within fifteen working days under article 8(7), and the authorised body enters details in the register within thirty working days. The practical consequence: objections to automated decisions cannot be routed into the general complaints queue — they need a separate, faster procedure with a named person responsible for it.

Article 19-1 reaches a substantially wider set of processes than is generally assumed. Legal consequences do not arise only from credit scoring: an automatic refusal to open an account, automatic termination of a contract under anti-fraud rules, automatic suspension of an account that removes access to a paid service, automatic screening-out of job applicants — in each case the subject’s rights and legitimate interests are altered or terminated.

> Author’s assessment: the principal exposure here is not missing consent but a missing objection mechanism. Companies collect consent more or less reliably. A mechanism that lets a person object specifically to the automated character of a decision, and a procedure for disposing of that objection within three working days, is simply not designed into most products. On an inspection, failure to comply with article 19-1(2) is characterised as a failure to take protective measures — which is part 3 of article 79 of the Code of Administrative Offences.

Article 43 of the Digital Code: Algorithmic Systems and the Right to Human Review

Article 43 of the Digital Code, in force from 12 July 2026, gives the individual three rights in respect of fully automated decisions: to be told that an algorithmic system was used, to receive an explanation of the key factors, and to demand review of the decision by a qualified specialist. The right to human involvement lives here, not in article 19-1 of Law No. 94-V.

Article 43, verbatim:

“1. Алгоритмическая система – цифровая система, принимающая либо влияющая на принятие решений на основе автоматизированной обработки данных, включая системы искусственного интеллекта. 2. Решения, принимаемые с использованием алгоритмических систем, не должны приводить к дискриминации, включая дискриминацию по признакам, установленным законами Республики Казахстан. 3. Полностью автоматизированным решением признается решение, принятие которого осуществляется без участия человека в оценке обстоятельств либо утверждении результата в случаях, предусмотренных законами Республики Казахстан или соглашением. 4. Субъект, в отношении которого принимается полностью автоматизированная алгоритмическая система, вправе в случаях и порядке, установленных законодательством Республики Казахстан: 1) получить информацию о факте применения алгоритмической системы; 2) получить объяснение ключевых факторов и критериев, повлиявших на решение, без раскрытия алгоритмов, исходного кода или сведений, составляющих охраняемую законом тайну; 3) потребовать пересмотра решения с участием уполномоченного специалиста (специалистов), если решение влечет юридические последствия либо способно повлиять на права и законные интересы лица, в сроки, установленные законодательством Республики Казахстан. 5. Особенности применения алгоритмических систем, полностью автоматизированных решений устанавливаются законодательством Республики Казахстан.”

Provision

What it gives the data subject

What it requires of business

Article 19-1 of Law No. 94-V, from 18 January 2026

A right to object to automated processing

Do not process without consent; explain the procedure and consequences; dispose of an objection within three working days

Article 43 of the Digital Code, from 12 July 2026

A right to know an algorithm was used; a right to an explanation of key factors; a right to human review

Disclose the use; be able to explain the criteria without disclosing code; provide for specialist review

Article 22 GDPR(for comparison)

A right not to be subject to a decision based solely on automated processing

Provide human intervention, the ability to express a view and to contest

The right to an explanation is expressly bounded by trade-secret protection, and the boundary is written into the provision itself. Article 43(4)(2) requires an explanation of “ключевые факторы и критерии” but “без раскрытия алгоритмов, исходного кода или сведений, составляющих охраняемую законом тайну”. The practical consequence: a demand to disclose the model or its feature weights need not be met; the explanation is pitched at the level of factors, not mechanics.

Both article 43(4) rights are qualified by the words “в случаях и порядке, установленных законодательством Республики Казахстан”, and that matters. The provision is not directly effective: it defers to downstream regulation that had not been published at the time of writing. The practical consequence: an individual can currently invoke the human-review right only where a procedure already exists in sectoral legislation. The non-discrimination duty in paragraph 2, by contrast, is unqualified and has applied since 12 July 2026.

Artificial intelligence got no chapter of its own in the Digital Code. It enters the Code only as a species of algorithmic system under article 43(1). Standalone AI regulation sits in the Law of the Republic of Kazakhstan “On Artificial Intelligence” of 17 November 2025 No. 230-VIII, in force from 18 January 2026 — the same day as article 19-1 of Law No. 94-V, because both provisions came from the same legislative package.

> Author’s assessment: the two automated-decision provisions have to be applied together, not chosen between. Article 19-1 answers the question “may we process this way at all” — and the answer is no without consent. Article 43 answers “what must we give the individual if we do” — information, an explanation and a review. The practical consequence: automated-decision compliance in Kazakhstan is assembled from two instruments at once, and a position resting on only one of them is incomplete.

The First Register: Notification of the Start of Processing Under Article 10-1

Article 10-1 of Law No. 94-V, in force from 25 August 2026, requires the authorised body to be notified of the start and the end of personal data processing, with the details entered in the register of persons collecting and/or processing personal data. The article was inserted by the Law of 24 June 2026 No. 326-VIII.

The duty does not fall on everyone. Article 10-1(2) exempts small and medium processors as defined in article 25-1 from prior notification — that is, those processing the data of fewer than five hundred thousand unique subjects. Notification is mandatory only for the large class.

Element

Content under article 10-1

Who notifies

Owners and operators falling into the large class under article 25-1; the small and medium classes are exempt from prior notification

When

Before processing begins, and on its cessation

What is stated

The person’s name and identifying details; protective measures applied; the start date of processing; transfers to third parties; whether cross-border transfer occurs; dissemination in publicly available sources; categories of data collected; the location of the database; and other particulars

Deadline for entry in the register

The authorised body enters the details within thirty working days

Deadline for removal

Thirty working days from receipt of a notice of cessation

Note what the notification actually asks for: it reproduces the substance of a record of processing activities. It calls for protective measures, data categories, transfers to third parties, the existence of cross-border transfer and the location of the database. The practical consequence: the notification cannot be prepared without a prior processing inventory. A company with no register of its processing operations will be unable to complete it correctly — and will discover that at the point the deadline has already arrived.

The statute is explicit about the form of the notification, and that is worth noting. Article 10-1(3) provides for filing “в виде документа на бумажном, цифровом и (или) ином материальном носителе, который подписывается уполномоченным лицом”. The form is therefore settled; what remains undefined is the electronic filing channel.

The subordinate rules on notification and on maintaining the register had not been published at the time of writing. Neither rules on notifying the start of processing nor rules on maintaining the register of persons could be found in the legal databases or on the government portal. The practical consequence: the electronic filing channel — elicense.kz, egov.kz or another — and whether any fee applies were not officially settled as at 25 August 2026. Any claim about a specific filing channel encountered in secondary sources should be treated as unconfirmed.

The Code of Administrative Offences contains no dedicated offence of failing to notify or of being absent from the register. Law No. 326-VIII created the registers but added no corresponding provision to article 79. Exposure for failure to notify therefore arises under the general limbs — parts 1 and 3 of article 79 — and through the state control powers in articles 27-2 and 27-3 of Law No. 94-V.

> Author’s assessment: the absence of a dedicated offence is a temporary fact rather than a structural one, and planning around it would be a mistake. The registers took effect on 25 August 2026; the subordinate rules are not yet adopted; the sanction for failure to notify is not yet drafted. The practical consequence: in Kazakh practice a gap between a duty and its sanction is usually closed by the next amendment package to the Code of Administrative Offences. For a company in the large class, building the notification process now is the cheaper course than waiting for the fine to appear.

The Second Register: Security Breaches and the Notification Deadlines

Article 23-2 of Law No. 94-V, in force from 25 August 2026, creates the register of personal data security breaches.The register is defined in article 1(15-1) as “перечень персональных данных, безопасность которых нарушена”. The article was inserted by the Law of 24 June 2026 No. 326-VIII and placed in Chapter 3 on the protection of personal data.

The second register differs from the first in a fundamental way: it is populated from detected breaches, not from filings by business. The first register — of persons — is fed by processors’ notifications. The second — of breaches — is maintained by the authorised body from open sources and from the named cybersecurity bodies, and the data in it is processed on the basis of established facts of unauthorised third-party access without the subject’s consent. Notifying the subjects themselves is a separate mechanism under the order No. 481/НҚ Rules, not a function of the register; article 23-2 imposes no notification duty.

The procedure for notifying data subjects of a security breach sits in separate Rules, approved by order of 9 August 2024 No. 481/НҚ and amended by order of 30 April 2026 No. 232/НҚ, in force from 12 July 2026.

Link in the chain

Who notifies whom

Deadline

First

Owner and/or operator → the authorised body

One working day

Second

The cybersecurity operations centre, the cybersecurity incident response service, the national cybersecurity coordination centre, sectoral cybersecurity centres and the other bodies named in clause 5 of the Rules → the authorised body

Three hours

Third

The authorised body → the “digital government” operator

One working day

Fourth

The “digital government” operator → the data subject

Via the personal account, mobile application or SMS

One working day is not comparable with the GDPR’s seventy-two hours, and an incident response plan built to the European regulation will not work here. Article 33 of the GDPR gives a controller 72 hours from becoming aware of a breach. The Kazakh requirement is one working day. The practical consequence: an incident discovered on a Friday evening has to reach the authorised body on Monday, and there is no room for a completed investigation before filing. The response plan has to provide for an initial notification on incomplete facts, supplemented later.

The duty to inform the data subject of actions taken with their personal data sits in article 19 of Law No. 94-V, and that notification function is delivered in part through the state service under article 8-1.

The Digital Code added an element of its own — the citizen’s digital space. Article 77(4) of the Code obliges “digital government” digital objects, when a citizen’s digital data is requested, to “формировать цифровое событие о факте использования таких данных и передавать его в цифровое пространство гражданина Республики Казахстан”. Article 77(1) defines the digital space as a section of the personal account on the “digital government” web portal.

The access log is confined to state digital objects, and that limit is decisive. Article 77 of the Digital Code gives the citizen visibility of who accessed their data, and when, within state systems. It does not apply to private owners and operators. Access transparency in the private sector is delivered differently — through the state access control service under article 8-1 of Law No. 94-V, and only for those integrated with it.

> Author’s assessment: the two registers serve different regulatory purposes and should not be conflated. The register of persons under article 10-1 is a supervisory census: it tells the state who in the country processes data at scale and where that data sits. The breach register under article 23-2 is a notification tool: it enables a specific individual to be told their data has been compromised. The practical consequence: appearing in the first register is normal and evidences compliance; having your data appear in the second is an event that inspections follow.

The Article 25-1 Classification: Three Classes, and What Turns on Them

Article 25-1 of Law No. 94-V, in force from 25 August 2026, divides owners and/or operators, and third parties, into three classes by the number of unique data subjects whose personal data they process, with article 25-1(3) applying the criteria “независимо от их организационно-правовой формы, формы собственности и вида деятельности”. The article was inserted by the Law of 24 June 2026 No. 326-VIII.

Class

Threshold in unique data subjects

Consequence

Small

Up to ten thousand unique subjects

Exempt from prior notification under article 10-1

Medium

From ten thousand to five hundred thousand unique subjects

Exempt from prior notification under article 10-1

Large

Five hundred thousand and above

Must notify the start of processing and be entered in the register of persons

E­scala­tion

Processing of restri­cted-a­ccess personal data

The class moves up one level

The escalation rule is the most underestimated provision in this article. Processing restricted-access personal data — biometric, health and other data to which access is restricted — moves an organisation up one step. A medium-volume processor handling health data becomes large, and with it acquires the article 10-1 notification duty.

A worked example of how the rule bites. A medical clinic with a database of one hundred and twenty thousand patients is formally medium by volume. But it processes health data — restricted-access personal data — and therefore escalates to the large class, with every article 10-1 obligation that follows. An online service with the same one hundred and twenty thousand users, processing only name, telephone number and order history, stays medium.

Protective measures by class are set by the authorised body. Article 25-1 provides expressly: “Меры по защите персональных данных по категориям определяются уполномоченным органом.” At the time of writing no separate instrument setting class-differentiated measures could be found; the general Rules under order No. 179/НҚ, as restated by order No. 338/НҚ, apply.

The count is of unique subjects, not records, and the distinction changes the answer by an order of magnitude. The article 25-1 threshold is framed in “уникальных субъектов”. The practical consequence: a database of two million transactions relating to thirty thousand customers is thirty thousand unique subjects — medium, not large. The opposite error is more common: an organisation counts active customers and forgets the archive, former employees, job applicants and people who declined the service, and so understates its class.

Author’s assessment: volume-based classification is new to Kazakh law and it changes how compliance is planned. Before 25 August 2026 Law No. 94-V imposed identical obligations on everyone without exception — from a sole trader to a bank. Article 25-1 introduced gradation, and with it the need to evidence your class. The practical consequence: counting unique subjects has stopped being an internal metric and become part of the evidential record on an inspection. The counting methodology and its result are worth recording in writing, with a date.

A sourcing caveat. The article 25-1 thresholds — ten thousand and five hundred thousand — and the escalation rule for restricted-access data were read verbatim in the text of the amending Law of 24 June 2026 No. 326-VIII on the official Әділет portal. That portal is closed to automated fetching, so the text was read manually in a browser; the same route was used for articles 10-1 and 23-2.

Protective Measures: The Order No. 179/НҚ Rules as Restated on 12 July 2026

The Rules on the measures owners, operators and third parties take to protect personal data were restated by order of the Deputy Prime Minister — Minister of Artificial Intelligence and Digital Development of 22 June 2026 No. 338/НҚ, in force from 12 July 2026. The base instrument is the order of the Minister of Digital Development, Innovation and Aerospace Industry of 12 June 2023 No. 179/НҚ, registered with the Ministry of Justice on 15 June 2023 under No. 32810.

Requirement in the restated Rules

Content

Data segregation

Personal data is split into publicly available and restri­cted-a­ccess, with different handling regimes

Process inventory

Mandatory ide­ntifi­cation of the business processes in which personal data is processed

Responsible person

Mandatory appointment of a person responsible for organising the processing of personal data

Internal control

Internal compliance control and employee briefing

Cry­ptogra­phy

Cryptographic protection to standard СТ РК 1073-2007 at security level three or aboveonly for the storage and transmission of restri­cted-a­ccess personal data; the sub-clause expressly does not apply to cross-border transfer under article 16 of the Law

Recording of actions

Registration and accounting of the actions listed in article 8(4)(3)–(6) of the Law — clause 9(5) of the Rules

User ide­ntifi­cation and authe­ntica­tion

Means of identifying and authe­nti­cating users, including by biometric authe­ntica­tion, for a database exceeding one hundred thousand records where restri­cted-a­ccess data is worked with — applyingexclusively to persons with access to the database

Blocking

Restri­cted-a­ccess data must be blocked pending a decision on the subject’s request

Inte­gra­tion

Mandatory integration with the state access control service where there is interaction with state digital objects containing personal data, save in the cases in article 9(1), (2), (9) and (9-2) of the Law — clause 10 of the Rules

Breach noti­fica­tion

Notification of the authorised body within one working day

Lo­calisa­tion

Collection and processing of restri­cted-a­ccess data through digital objects in Kazakhstan; storage in a server room or data centre in Kazakhstan

A clarification on biometric authentication that removes a common misreading. The requirement applies exclusively to persons with access to the database — administrators and system operators, not data subjects. Biometrics is named as only one of the available means: clause 9(10) of the Rules speaks of “средства идентификации и (или) аутентификации пользователей, в том числе биометрической аутентификации”, and the duty arises only where restricted-access personal data is worked with. The practical consequence: biometrics belong in the internal access perimeter, and should not be imposed on customers logging into the service.

A divergence between the Rules and the statute worth knowing about. The list of exceptions to the integration duty in clause 10 of the Rules — article 9(1), (2), (9) and (9-2) — does not match the list in article 8-1(1) of the Law, which also includes sub-paragraph (2-1). The practical consequence: the statute prevails on a conflict, but in a contested case the divergence will need explaining, and the position is better prepared in advance.

The duty to appoint a responsible person is personal, not notional. The Rules require the appointment of a “лицо, ответственное за организацию обработки персональных данных”. Article 25 of Law No. 94-V sets out that person’s rights and duties alongside those of the owner and operator. The practical consequence: on an inspection the first question is whether the appointment order exists and is current. The absence of an appointed person is characterised as a failure to take protective measures — part 3 of article 79 of the Code of Administrative Offences.

The Rules’ definition of personal data has been brought into exact alignment with the statute. Clause 2(1) of the restated Rules defines personal data as “сведения или совокупность сведений о субъекте персональных данных, дополненные одним или несколькими идентификаторами персональных данных” — word for word as in article 1(2) of Law No. 94-V. The practical consequence: the Rules widen nothing relative to the statute; the earlier divergence between the statutory and the subordinate definition has been removed.

Author’s assessment: the restated Rules turn Kazakh compliance from a documentary exercise into a process one, and that is a change of substance. The old practice amounted to holding a processing policy, consent forms and an appointment order. Requirements for a business-process inventory, internal compliance control, the registration and accounting of actions taken with personal data, and cryptography to a national standard are requirements of a working system, not of a folder. The practical consequence: an inspection can now be technical, and preparing for one calls for the IT function, not the lawyer alone.

СТ РК 1073-2007 is Kazakhstan’s national standard for cryptographic protection, and the “level three or above” requirement is a gradation within it. A qualification easy to miss: the same sub-clause of the Rules expressly excludes cross-border transfers under article 16 of the Law from the cryptographic requirement. The practical consequence: national-standard cryptography is required for the domestic storage and transmission of restricted-access data, but it is not a condition of a lawful cross-border transfer.

Biometrics and Individual Rights: What the Digital Code Added

Article 48(3) of the Digital Code permits mandatory processing of biometric data and mandatory biometric authentication only in cases established by Kazakh statutes. The provision has applied since 12 July 2026.

Article 48 of the Digital Code, in its key paragraphs:

“1. Биометрические данные, используемые для цифровой аутентификации, признаются персональными данными и подлежат защите в соответствии с Законом Республики Казахстан «О персональных данных и их защите». 2. Каждый гражданин Республики Казахстан имеет право на биометрическую регистрацию в целях цифровой аутентификации. 3. Обязательная обработка биометрических данных и проведение биометрической аутентификации допускаются только в случаях, установленных законами Республики Казахстан.”

Article 48(8) disapplies the article to intelligence, counter-intelligence, operational-search and protective-security activity. Financial and payment organisations are carved out into a separate regime under article 48(6), involving the Agency for Regulation and Development of the Financial Market and the National Bank.

A general prohibition on compelled digital identification sits in article 40(2) of the Digital Code: “Никто не может быть принужден к цифровой идентификации, за исключением случаев, когда такая обязанность прямо предусмотрена законами Республики Казахстан.”

Right

Provision

Content

Erasure, anonymisation and restriction of processing

Article 41 of the Digital Code

The right to demand deletion, anonymisation or restriction of data placed or processed in the digital environment, regardless of how it was obtained, save where statutes provide otherwise

Freedom from compelled digital identi­fica­tion

Article 40(2) of the Digital Code

Compulsion only where a statute expressly provides

Right to biometric regi­stra­tion

Article 48(2) of the Digital Code

A citizen’s right, not an obligation

Freedom from mandatory biometrics

Article 48(3) of the Digital Code

Mandatory biometrics only where a statute expressly provides

Rights on algorithmic decisions

Article 43 of the Digital Code

Notification of use, explanation of factors, specialist review

The citizen’s digital space

Article 77 of the Digital Code

An access log — for state digital objects only

Data subject rights under the sectoral law

Article 24 of Law No. 94-V

The rights and duties of the data subject

The article 41 erasure right is not absolute, and its boundaries repay precision. Where a mandatory retention period applies, the remedy converts from deletion into restriction of access and suspension of processing. The carve-outs cover third-party rights, the investigation of breaches, court proceedings, the public interest, statistical and research purposes, and the discharge of state functions. The practical consequence: a customer’s demand to “delete everything about me” cannot be met literally where accounting, tax or banking law prescribes retention — but processing must be restricted.

Author’s assessment: the Digital Code’s biometrics block solved a policy problem and opened a legal gap.The Code prohibited compulsion into biometrics and into digital identification — a direct and legible prohibition. At the same time the companion Law No. 256-VIII deleted the definition of biometric data from Law No. 94-V, while the Code defines only “биометрическая аутентификация”. The practical consequence: as at August 2026 the scope of “biometric data” in Kazakhstan is derived by systematic interpretation rather than from an express provision, and borderline attributes — voice timbre, keystroke dynamics, gait — are classified without a statutory definition to anchor them.

The duties of the owner, the operator and the responsible person sit in article 25 of Law No. 94-V, and the data subject’s rights in article 24. Both articles were amended by Law No. 326-VIII with effect from 25 August 2026.

The Regulator: The Ministry of Artificial Intelligence and Digital Development

The authorised body for personal data protection in 2026 is the Ministry of Artificial Intelligence and Digital Development of the Republic of Kazakhstan. The former name — the Ministry of Digital Development, Innovation and Aerospace Industry — survives only in the titles of instruments adopted before October 2025.

Article 1(11-1) of Law No. 94-V defines the authorised body functionally: “центральный исполнительный орган, осуществляющий руководство в сфере защиты персональных данных”. The statute does not name a specific ministry — that is settled by government instruments.

Instrument

Date

Effect

Pre­side­ntial Decree No. 997

18 September 2025

“On measures to further improve the system of public admi­nistra­tion” — the reo­rgani­sation

Government Resolution No. 846

9 October 2025

Approved the Regulation on the Ministry of Artificial Intelligence and Digital Development

Order of the Deputy Prime Minister — Minister of Artificial Intelligence and Digital Development No. 527/НҚ

21 October 2025

Approved the Regulation on the Committee for Information Security — the agency that delivers policy in the personal data field

The Ministry’s Regulation expressly lists among its functions participation in delivering state policy on personal data and their protection, and the processing of personal data whose security has been breached in order to inform data subjects through the personal account on the “digital government” web portal. That second function is the executive counterpart of the article 23-2 breach register.

The authorised body’s competence sits in article 27-1 of Law No. 94-V. Its opening sub-paragraphs read: “1) формирует и реализует государственную политику в сфере персональных данных и их защиты; 1-1) осуществляет государственный контроль за соблюдением законодательства Республики Казахстан о персональных данных и их защите; 2) разрабатывает порядок осуществления собственником и (или) оператором, а также третьим лицом мер по защите персональных данных”.

State control is governed by two separate articles. Article 27-2 sets out the general procedure for state control over compliance with personal data legislation; article 27-3 sets out a separate procedure for control over state bodies.Both were inserted by the Law of 11 December 2023 No. 44-VIII.

The checklist inspectors work from is approved by a separate order. It is the checklist for compliance with personal data legislation by owners, operators and third parties. The practical consequence: preparing for an inspection means reconciling against the checklist rather than open-ended “getting compliant”. The document is a public normative act.

The enforcement figures given at an interdepartmental meeting on 20 August 2026 come from two different bodies, and the attribution has to be separated. The Deputy Prime Minister — Minister of Artificial Intelligence and Digital Development reported 77 inspections in the personal data field during 2025, a further 44 since the start of 2026, and administrative case numbers up more than fourfold. A representative of the Prosecutor General’s Office reported 90 criminal offences registered in January–July 2026 against 172 in the same period of 2025, a fall of 47.7 per cent, and 58 persons convicted.

A caveat on the level of confirmation for these figures. The government portal gov.kz is unusable for automated access: its pages return only a JavaScript shell with no content. The figures above come from business media reporting the named official’s statement and belong to the second tier of sources. No primary regulator report or dataset on data.egov.kz carrying them could be found.

> Author’s assessment: administrative cases up more than fourfold while criminal offences fall 47.7 per cent is not a softening but a change of instrument. A prosecution under article 147 of the Criminal Code requires proof of substantial harm. An administrative fine under article 79 requires neither harm nor intent — a failure to take protective measures suffices. The practical consequence: the probability of an administrative penalty for a well-meaning but unprepared company is higher in 2026 than at any point before.

The Fines: Article 79 of the Code of Administrative Offences in Tenge, and Criminal Liability Under Article 147

Administrative liability for breaches of personal data legislation sits in article 79 of the Code of the Republic of Kazakhstan on Administrative Offences of 5 July 2014 No. 235-V. The article has four parts. There is no article 79-1: article 79 is followed by article 80 on medical care.

The tenge figures are computed at the monthly calculation index of KZT 4,325, set by article 7(4) of the Law “On the Republican Budget for 2026–2028” of 8 December 2025 No. 239-VIII.

Part 1 — unlawful collection and/or processing of personal data, where the act carries no criminal element.

Category of offender

MCI

Fine in KZT

Individual

30

129,750

Official, private notary, private bailiff, advocate, legal consultant, small business or non-profit organisation

60

259,500

Medium-sized business

100

432,500

Large business

200

865,000

Part 2 — the same acts committed by an owner, operator or third party using their official position.

Category of offender

MCI

Fine in KZT

Individual

100

432,500

Official, small business, non-profit organisation

200

865,000

Medium-sized business

300

1,297,500

Large business

600

2,595,000

Part 3 — failure by an owner, operator or third party to take measures to protect personal data.

Category of offender

MCI

Fine in KZT

Individual

150

648,750

Official, small business, non-profit organisation

300

1,297,500

Medium-sized business

450

1,946,250

Large business

600

2,595,000

Part 4 — a part 3 act that has resulted in loss, or in unlawful collection and/or processing, of personal data.

Category of offender

MCI

Fine in KZT

Individual

200

865,000

Official, small business, non-profit organisation

750

3,243,750

Medium-sized business

1,000

4,325,000

Large business

2,000

8,650,000

The Law of 10 January 2025 No. 155-VIII, in force from 13 March 2025, raised the amounts across all four parts of article 79, not part 1 alone. Part 1: from 10 to 30, 20 to 60, 30 to 100 and 70 to 200 MCI. Part 2: from 50 to 100, 75 to 200, 100 to 300 and 200 to 600. Part 3: from 50 to 150, 100 to 300, 150 to 450 and 200 to 600. Part 4: from 500 to 750, 700 to 1,000 and 1,000 to 2,000. The practical consequence: the part 4 ceiling doubled from 1,000 to 2,000 MCI, and part 3 — the limb under which a localisation breach is charged — tripled. An exposure model built on the 2024 text understates liability by a factor of two to three.

Article 79 contains no repeat-offence aggravation, and the point repays precision. The article has exactly four parts and no note. Part 2 aggravates by use of official position; part 4 aggravates by outcome, namely loss or unlawful processing. Neither is a repeat-offence provision. The assertion that article 79 carries “increased fines on repetition” does not match the text.

The Code of Administrative Offences contains no dedicated offence for breaching localisation or for failing to notify the start of processing. A breach of article 12 of Law No. 94-V is characterised as a failure to take protective measures — part 3 of article 79 — and, where loss follows, part 4. The practical consequence: the absence of a bespoke offence does not mean the absence of liability; it means liability arises under the general limb, with a ceiling of 2,000 MCI.

Article 79 is not, however, the Code’s only personal-data provision, and the conclusion about repeat offences does not extend to the Code as a whole. Article 641, “Нарушение законодательства Республики Казахстан об информатизации”, carries parallel limbs: part 1 covers a failure, or an inadequate performance, by the owner or holder of information systems containing personal data of the prescribed requirements; part 4 covers the use of resources containing personal data to cause pecuniary or moral harm; and part 3 expressly imposes heavier liability for acts committed again within a year of a penalty being imposed. A caveat: the article 641 sanction amounts could not be reconciled against primary sources and are not stated here.

Criminal liability sits in article 147 of the Criminal Code of the Republic of Kazakhstan of 3 July 2014 No. 226-V, “Нарушение неприкосновенности частной жизни и законодательства Республики Казахстан о персональных данных и их защите”. The article has five parts.

Part of article 147

Offence

Sanction

Part 1

Failure to take protective measures by a person obliged to take them, where this caused substantial harm to rights and legitimate interests

A fine of up to 3,000 MCI — up to KZT 12,975,000; or corrective labour, community service up to 600 hours, restriction or deprivation of liberty up to 2 years, with or without disqua­lifi­cation from office or activity for up to three years

Part 2

Unlawful gathering of private-life information constituting personal or family secrets; substantial harm from unlawful collection and processing

A fine of up to 5,000 MCI — up to KZT 21,625,000; or corrective labour in the same amount, community service up to 800 hours, restriction or deprivation of liberty up to 3 years

Part 3

The same acts using official position or special technical means, by unlawful access to digital resources, or for gain

Deprivation of liberty up to 5 years, with disqua­lifi­cation from office

Part 4

Dissemination of private-life information without consent; substantial harm from unlawful dissemination

Deprivation of liberty from 3 to 6 years

Part 5

The same in a public address, a publicly displayed work, in mass media, teleco­mmuni­cations networks, on digital objects or on online platforms

Deprivation of liberty from 3 to 7 years

Author’s assessment: the line between administrative and criminal liability runs through substantial harm, and that is exactly why the administrative article is the greater exposure for business. Article 147(1) of the Criminal Code requires proof of substantial harm to rights and legitimate interests. Part 3 of article 79 requires neither harm nor intent — it is enough to establish that protective measures were not observed. The practical consequence: a company with no appointed responsible person, or no process inventory, sits in the administrative risk zone permanently, whether or not an incident has occurred.

A sourcing caveat. The text of article 79 was read from the Kontinent legal database’s consolidated text; the part 1 amounts were additionally reconciled against the Paragraf analysis of Law No. 155-VIII taking effect. The official portal adilet.zan.kz is closed to automated access. The texts of parts 2 to 4 of article 79 and of article 147 of the Criminal Code were reconciled across two independent sources returning identical figures.

How the Kazakh Regime Differs from the GDPR

The defining difference is that Kazakhstan controls data through localisation of storage while the European Union controls it through the regulation of cross-border flows. Almost every other difference follows from that one.

Feature

Kazakhstan — Law No. 94-V and the Digital Code

European Union — GDPR

Storage loca­lisa­tion

Mandatory for everyone — article 12(2); for restri­cted-a­ccess data the processing itself is localised too

None as a general requirement

Cro­ss-bo­rder transfer

A two-tier adequacy test with no published country list — article 16

Adequacy decisions, standard contractual clauses, binding corporate rules

Lawful bases

Consent or the exhaustive article 9 list; no equivalent of legitimate interests

Six bases under article 6, including legitimate interests

Automated decisions

A pro­hibi­tion with consent as the exception — article 19-1; rights to information, explanation and review — article 43 of the Digital Code

A right not to be subject to such a decision — article 22, with carve-outs for contract, law and explicit consent

Deadline to deal with an objection to automated processing

Three working days — article 19-1(3)

One month for a subject request generally

Breach notification to the regulator

One working day

72 hours — article 33

Re­gistra­tion or noti­fica­tion

No­tifi­cation of the start of processing for the large class — article 10-1, from 25 August 2026

No general registration; an internal record of processing — article 30

Size classi­fica­tion

Three classes by unique data subjects — article 25-1

A conditional exemption from the record of processing below 250 employees — article 30(5); it falls away where processing is not occasional, carries a risk to data subjects’ rights, or covers specia­l-ca­tegory data

Responsible person

Mandatory for everyone under the order No. 179/НҚ Rules

A DPO is mandatory in three cases only — article 37

Maximum admi­nistra­tive fine

2,000 MCI — KZT 8,650,000, roughly EUR 16,000 at August 2026 rates

EUR 20 million or 4 per cent of worldwide turnover — article 83(5)

Criminal liability

Yes — article 147 of the Criminal Code, up to 7 years’ imprisonment

A matter for member state law

The relative size of the fines makes the Kazakh regime look mild, and the impression misleads. The ceiling in Kazakhstan is about sixteen thousand euro; in the European Union it is twenty million euro or four per cent of worldwide turnover. But the Kazakh regime carries criminal liability for a failure to take protective measures that causes substantial harm, punishable by up to two years’ imprisonment under article 147(1), and a mandatory localisation duty whose breach stops operations technically rather than financially. The practical consequence: measuring Kazakh risk by the size of the fine is the wrong metric — the criminal track and the infrastructure requirement are what govern.

Three rows in that table explain why European documentation does not port across. First, the absence of legitimate interests as a lawful basis disables a substantial share of European bases. Second, the prohibitory structure of article 19-1 means the European model of “process, but offer a right to object” is unlawful in Kazakhstan without consent. Third, mandatory localisation has no European counterpart at all. The practical consequence: adapting GDPR documentation to Kazakhstan is a rebuild of the lawful bases, not a translation.

A forward-looking caveat. The Digital Omnibus package under discussion in the European Union would, among other things, move the article 33 notification deadline from 72 to 96 hours and simplify the article 30 record of processing. As at August 2026 it is a proposal that has not been finally adopted, and the table above reflects the GDPR as it currently stands.

There is also substantial overlap, and it makes the task easier. Requirements to inventory processing operations, appoint a responsible person, assess and document protective measures, keep access logs and notify incidents correspond conceptually. A company that has already built a working GDPR programme covers a good part of the Kazakh requirements in substance — but not localisation, not the lawful bases and not the response deadlines.

Kazakhstan’s tax and accounting perimeter is changing in 2026 no less visibly than its data regime: the VAT rate rose to 16 per cent and the compulsory registration threshold was halved — analysed in VAT in Kazakhstan 2026: Registration, the 10,000 MCI Threshold and the 16% Rate.

A Step-by-Step Route to Compliance

Bringing a business into line with the Kazakh personal data regime as it stands on 25 August 2026 runs to eighteen steps, and the first four determine the scope of all the rest.

1.        Inventory the processing operations. The restated order No. 179/НҚ Rules expressly require identification of the business processes in which personal data is processed. Without it neither the article 25-1 classification nor the article 10-1 notification can be done.

2.        Count unique data subjects, not records. Include the archive, former employees, job applicants and people who declined the service. Record the counting methodology and its result in writing, with a date.

3.        Determine whether you process restricted-access personal data. If you do, the article 25-1 class moves up one level and collection and processing must run through digital objects in Kazakhstan under clause 13 of the Rules.

4.        Fix your article 25-1 class — small, medium or large — and build the rest of the plan from it.

5.        Establish where the storage physically sits. Article 12(2) requires the database and/or digital object to be located in Kazakhstan; clause 14 of the Rules specifies a server room or data centre in Kazakhstan.

6.        If storage is offshore, plan the migration as a project rather than a document edit. It is the one statutory requirement no internal order can close.

7.        Establish whether you interact with state bodies’ digital objects. If you do, integration with the state access control service is mandatory under article 8-1(1).

8.        Rebuild the lawful bases. The basis is either consent under article 8 or a specific sub-paragraph of article 9. A legitimate interests analysis is legally inoperative.

9.        Review consent durations. Consent may not exceed the period needed to achieve the collection purposes; withdrawal obliges cessation within fifteen working days.

10.    Identify every process caught by article 19-1. That is any automated processing which creates, alters or terminates rights and legitimate interests: scoring, anti-fraud, automatic refusals, automated candidate screening, automatic account suspension.

11.    For each such process, obtain consent or identify an express statutory basis. Without one or the other, the processing has been prohibited since 18 January 2026.

12.    Build an objection mechanism and a three-working-day disposal procedure, with a named person responsible for it and a record of notifying the subject of the outcome.

13.    Prepare the article 43 disclosures: notification that an algorithmic system was used, and an explanation of the key factors without disclosing code.

14.    Appoint, by order, a person responsible for organising the processing of personal data, and keep the order current.

15.    Align technical protection with the restated Rules: cryptography to СТ РК 1073-2007 at security level three or above, DBMS event logging, and biometric authentication for persons with access to databases exceeding one hundred thousand records.

16.    Rewrite the incident response plan to a one-working-day clock, providing for an initial notification on incomplete facts, supplemented later.

17.    If you fall into the large class, prepare the article 10-1 notification and monitor for publication of the subordinate rules on notification and on maintaining the register.

18.    Reconcile against the authorised body’s inspection checklist before the inspection, not after.

Common Mistakes and What They Cost

Mistake 1. Assuming the Digital Code replaced Law No. 94-V. Article 106 of the Digital Code repealed only the 2003 law on electronic documents and electronic digital signatures. Law No. 94-V is in force in its 25 August 2026 version. Cost: a programme built on the Digital Code alone covers neither localisation, nor the lawful bases, nor the consent requirements — which is to say it covers none of what article 79 fines are actually levied for.

Mistake 2. Relying on legitimate interests as a lawful basis. Article 9 of Law No. 94-V contains no equivalent, and the list of grounds is exhaustive. Cost: processing without a basis is characterised as unlawful collection and processing under part 1 of article 79 — up to KZT 865,000 for a large business, and up to KZT 2,595,000 under part 2 where official position was used.

Mistake 3. Implementing article 19-1 as a European right to object. The provision is drafted as a prohibition from which consent is the exception. Cost: all automated processing with legal consequences carried on without consent and without an express statutory basis has been unlawful since 18 January 2026. For a scoring or anti-fraud platform, that makes the core business process unlawful, not merely a discrete breach.

Mistake 4. Failing to build the objection mechanism and the three-working-day procedure. Article 19-1(2) requires that a means of objecting be provided, and article 19-1(3) that the objection be disposed of within three working days with notification of the outcome. Cost: non-compliance is characterised as a failure to take protective measures — part 3 of article 79, up to KZT 2,595,000 — and that limb requires neither harm nor intent.

Mistake 5. Storing data offshore in reliance on the data subject’s consent. Consent lifts the cross-border transfer restriction under article 16(3)(1) but does not displace the article 12(2) localisation duty. Cost: these are two independent requirements and satisfying one does not satisfy the other. A localisation breach travels under part 3 of article 79 and, if data is lost, under part 4 — up to KZT 8,650,000.

Mistake 6. Measuring the article 25-1 threshold by record count. The threshold is framed in unique data subjects. Cost in both directions: overstating the class produces an unnecessary notification and heightened requirements; understating it leaves the article 10-1 duty unperformed by a company that is in fact in the large class.

Mistake 7. Overlooking the escalation rule for restricted-access data. Processing biometric, health or other restricted-access data moves the class up one level. Cost: a clinic, a recruitment agency or an insurer with medium processing volumes is in fact in the large class and must notify, even though its subject count does not say so.

Mistake 8. Planning breach response to the GDPR’s seventy-two hours. The Kazakh deadline for notifying the authorised body is one working day. Cost: missing the notification deadline is itself a failure to take protective measures under part 3 of article 79, and it bites regardless of how successfully the incident was contained technically.

Mistake 9. Not appointing a responsible person by order. The order No. 179/НҚ Rules require the appointment of a person responsible for organising the processing of personal data. Cost: it is the first question on an inspection and the easiest possible breach to record in the inspection report. Part 3 of article 79 — up to KZT 2,595,000 for a large business.

Mistake 10. Demanding biometrics from customers after reading the Rules’ hundred-thousand-record requirement. The requirement applies exclusively to persons with access to the database. Cost: over-collecting biometrics from customers is a breach in its own right, because mandatory biometric authentication is permitted only in cases established by statute under article 48(3) of the Digital Code.

Mistake 11. Computing fines from the pre-13 March 2025 redaction of the Code of Administrative Offences. The Law of 10 January 2025 No. 155-VIII tripled the part 1 amounts. Cost: a risk figure understated threefold and, in consequence, a mis-prioritised compliance budget.

Mistake 12. Concluding that because there is no dedicated offence for failing to notify under article 10-1, notification can be skipped. No bespoke offence exists, but liability arises under the general parts 1 and 3 of article 79 and through the state control powers in articles 27-2 and 27-3. Cost: in Kazakh practice a gap between a duty and its bespoke sanction is closed by the next amendment package — at which point the company is already in breach retrospectively.

Who This Reaches, Who It Does Not, and When to Take Advice

Law No. 94-V applies to any person collecting and processing personal data in Kazakhstan, irrespective of sector, ownership or processing volume. The size gradation introduced by article 25-1 governs not whether the statute applies but which obligations arise within it.

The regime bites hardest on:

•          fintech, banks and microfinance organisations — automated scoring under article 19-1 combined with restricted-access data and the large class under article 25-1;

•          medical organisations and insurers — processing health data escalates the class by one level automatically;

•          marketplaces and online services with large user bases — the large class, automatic suspensions and anti-fraud decisions;

•          recruitment agencies and HR platforms — automated candidate screening falls under article 19-1, and the subject count is habitually understated;

•          foreign groups serving Kazakh customers from offshore data centres — the article 12(2) localisation duty applies regardless of where the operator is incorporated.

The regime is lightest on:

•          companies with up to ten thousand unique data subjects that process no restricted-access data — the small class, with no notification duty;

•          businesses that use no automated decisions with legal consequences — article 19-1 does not reach them;

•          organisations with no dealings with state digital objects — integration with the state service is voluntary for them.

Professional review is warranted in at least five situations: determining the article 25-1 class where volumes are near a threshold or restricted-access data is involved; characterising a process as automated processing with legal consequences under article 19-1; designing the storage architecture for an international group; preparing an article 10-1 notification before the subordinate rules are published; and investigating an incident on a one-working-day notification clock.

Frequently Asked Questions

Is Law No. 94-V still in force after the Digital Code?

Yes. The Digital Code of 9 January 2026 No. 255-VIII, in force from 12 July 2026, repealed only the 2003 Law “On Electronic Documents and Electronic Digital Signatures” — the sole repealing provision in the whole Code, in article 106(2). Law No. 94-V is in force in its 25 August 2026 version and remains the principal personal data statute.

Must the personal data of Kazakh residents be stored in Kazakhstan?

Yes. Article 12(2) of Law No. 94-V requires personal data to be stored “в базе и (или) цифровом объекте, которые находятся на территории Республики Казахстан”. The provision carries no exemption by data category, sector or processing volume. Clause 14 of the order No. 179/НҚ Rules specifies a server room or data centre in Kazakhstan.

Can personal data be transferred abroad if storage is localised?

Yes, subject to article 16 of Law No. 94-V. A transfer to a state that ensures the protection of personal data requires no further basis; a transfer to a state that does not requires the subject’s consent, a ratified international treaty, or one of two public-law grounds. Kazakhstan publishes no list of states ensuring protection, so the most reliable basis is the data subject’s consent.

What exactly does article 19-1 of Law No. 94-V prohibit?

Automated processing of personal data that creates, alters or terminates a subject’s rights and legitimate interests — save where the subject’s consent has been obtained or a statute so provides. It has applied since 18 January 2026. It is a prohibition, not a right to object: the absence of an objection legitimises nothing.

How long is there to deal with an objection to automated processing?

Three working days from receipt, with mandatory notification of the outcome to the subject — article 19-1(3). It is the shortest response deadline anywhere in Law No. 94-V.

Which two state registers appeared in 2026?

The register of persons collecting and/or processing personal data — article 10-1 — and the register of personal data security breaches — article 23-2. Both articles were inserted by the Law of 24 June 2026 No. 326-VIII and took effect on 25 August 2026.

Who must notify the start of personal data processing?

Only owners and operators in the large class under article 25-1 — those processing the data of five hundred thousand or more unique subjects. The small class, up to ten thousand subjects, and the medium class, from ten thousand to five hundred thousand, are exempt from prior notification. Processing restricted-access personal data escalates the class by one level.

Through which portal is the article 10-1 notification filed?

As at 25 August 2026 this is not officially settled. The subordinate rules on notifying the start of processing and on maintaining the register of persons had not been published, in the legal databases or on the government portal, at the time of writing. Claims about a specific filing channel found in secondary sources are unconfirmed.

What is the maximum fine for breaches of the personal data rules?

2,000 MCI — KZT 8,650,000 at the 2026 index of KZT 4,325. It applies to a large business under part 4 of article 79 of the Code of Administrative Offences: a failure to take protective measures that has resulted in loss, or in unlawful collection and processing, of personal data.

Are there increased fines for repeat offences?

No. Article 79 has exactly four parts and no note on repetition. Part 2 aggravates for use of official position and part 4 for the occurrence of loss or unlawful processing; neither is a repeat-offence provision.

Within what period must the regulator be notified of a data breach?

Within one working day. The procedure sits in the Rules approved by order of 9 August 2024 No. 481/НҚ and amended by order of 30 April 2026 No. 232/НҚ with effect from 12 July 2026. The cybersecurity bodies named in clause 5 of the Rules notify the authorised body within three hours.

Who is the personal data regulator in Kazakhstan in 2026?

The Ministry of Artificial Intelligence and Digital Development of the Republic of Kazakhstan. The Ministry was created in the reorganisation under Presidential Decree of 18 September 2025 No. 997, and its Regulation was approved by Government Resolution of 9 October 2025 No. 846. The operational agency is the Committee for Information Security.

Key Takeaways

•          The Digital Code did not repeal Law No. 94-V. Article 106(2) repealed only the 2003 law on electronic documents and electronic digital signatures.

•          The operative redaction of Law No. 94-V is that of 25 August 2026, the day the Law No. 326-VIII package took effect.

•          Storage localisation is mandatory with no exemptions — article 12(2); for restricted-access data, collection and processing are localised as well.

•          No official list of states ensuring protection exists, so the reliable basis for cross-border transfer is the data subject’s consent.

•          Article 19-1 prohibits automated processing with legal consequences absent consent and allows three working days to dispose of an objection.

•          The right to human review of a decision sits in article 43 of the Digital Code, not in Law No. 94-V, and is qualified by a reference to procedures established by legislation.

•          Two registers have operated since 25 August 2026: the register of persons under article 10-1 and the breach register under article 23-2.

•          Only the large class must notify the start of processing — from five hundred thousand unique subjects; restricted-access data escalates the class by one level.

•          The subordinate rules on notification and on the register are unpublished, and the filing channel is not officially settled.

•          The maximum administrative fine is 2,000 MCI, KZT 8,650,000; article 79 contains no repeat-offence aggravation.

•          Criminal liability under article 147 requires substantial harm and reaches seven years’ imprisonment under part 5.

•          Breach notification to the regulator is one working day, not seventy-two hours.

Summary

Personal data regulation in Kazakhstan in 2026 operates on two layers: the Law of the Republic of Kazakhstan “On Personal Data and Their Protection” of 21 May 2013 No. 94-V, in force in the version as at 25 August 2026 and remaining the principal sectoral act, and the Digital Code of the Republic of Kazakhstan of 9 January 2026 No. 255-VIII, in force from 12 July 2026, which did not repeal Law No. 94-V: article 106(2) of the Code repealed only the 2003 Law “On Electronic Documents and Electronic Digital Signatures”, and on biometric data the Code refers expressly back to Law No. 94-V. The localisation requirement sits in article 12(2) of Law No. 94-V, was introduced by the Law of 24 November 2015 No. 419-V with effect from 1 January 2016, and in the version in force from 25 August 2026 requires personal data to be stored in a database and/or digital object located in the territory of Kazakhstan, while clauses 13 and 14 of the Rules approved by order of 12 June 2023 No. 179/НҚ as restated by order of 22 June 2026 No. 338/НҚ additionally require restricted-access data to be collected and processed through digital objects in Kazakhstan and stored in a server room or data centre in the country. Cross-border transfer is governed by article 16, untouched since 2017: transfer to states that ensure protection is free, and transfer to others requires the subject’s consent, a ratified international treaty or one of two public-law grounds, with no official list of states ensuring protection published in Kazakhstan. Article 19-1, inserted by the Law of 17 November 2025 No. 231-VIII with effect from 18 January 2026, prohibits automated processing of personal data that creates, alters or terminates a subject’s rights and legitimate interests other than with consent or where a statute so provides, and requires the processing and its consequences to be explained, a means of objection to be provided, and the objection to be disposed of within three working days; the right to review by a qualified specialist and to an explanation of key factors without disclosure of algorithms or source code sits in article 43 of the Digital Code. The Law of 24 June 2026 No. 326-VIII introduced, with effect from 25 August 2026, two state registers — the register of persons collecting and/or processing personal data under article 10-1, with notification of the start and end of processing and entry within thirty working days, and the register of personal data security breaches under article 23-2 — together with the article 25-1 classification into a small class up to ten thousand unique subjects, a medium class from ten thousand to five hundred thousand and a large class from five hundred thousand, with processing of restricted-access personal data escalating the class by one level and the notification duty falling on the large class alone. Notification of the authorised body about a security breach is due within one working day under the Rules approved by order of 9 August 2024 No. 481/НҚ as amended by order of 30 April 2026 No. 232/НҚ, with a three-hour deadline for the cybersecurity bodies named in clause 5 of the Rules. The authorised body is the Ministry of Artificial Intelligence and Digital Development of the Republic of Kazakhstan, created under Presidential Decree of 18 September 2025 No. 997 with its Regulation approved by Government Resolution of 9 October 2025 No. 846. Administrative liability sits in article 79 of the Code of Administrative Offences of 5 July 2014 No. 235-V, which has four parts and no repeat-offence aggravation: part 1 imposes 30, 60, 100 and 200 MCI, part 2 imposes 100, 200, 300 and 600 MCI, part 3 imposes 150, 300, 450 and 600 MCI, and part 4 imposes 200, 750, 1,000 and 2,000 MCI, which at the monthly calculation index of KZT 4,325 under article 7(4) of the Law of 8 December 2025 No. 239-VIII gives a maximum of KZT 8,650,000 for a large business; the part 1 amounts were tripled by the Law of 10 January 2025 No. 155-VIII with effect from 13 March 2025. Criminal liability under article 147 of the Criminal Code of 3 July 2014 No. 226-V requires substantial harm and ranges from a fine of up to 3,000 MCI under part 1 to imprisonment of three to seven years under part 5.

Planning a product launch in Kazakhstan, a migration of data storage, or a review of existing processing operations? The UPPERSETUP team can help establish your article 25-1 class, rebuild the lawful bases and prepare the documentation — company registration and corporate support in Kazakhstan.

Sources

Statutes and codes

1.        Law of the Republic of Kazakhstan of 21 May 2013 No. 94-V “On Personal Data and Their Protection” — the official Әділет legal information system

2.        Law No. 94-V in its consolidated text as at 25 August 2026 — Paragraf

3.        Law No. 94-V — consolidated redaction, Kontinent legal database

4.        Law No. 94-V — the Әділет mirror on zakon.uchet.kz

5.        Code of the Republic of Kazakhstan of 9 January 2026 No. 255-VIII “Digital Code of the Republic of Kazakhstan” — the official Әділет system

6.        Digital Code No. 255-VIII — Paragraf

7.        Paragraf note that the Digital Code took effect on 12 July 2026

8.        Law of the Republic of Kazakhstan of 7 January 2003 No. 370-II “On Electronic Documents and Electronic Digital Signatures” — repealed by the Digital Code with effect from 12 July 2026

9.        Law of the Republic of Kazakhstan of 9 January 2026 No. 256-VIII on amendments concerning digitalisation, transport and entrepreneurship

10.    Law of the Republic of Kazakhstan of 24 June 2026 No. 326-VIII on amendments concerning digitalisation, personal data protection, road traffic and advanced transport technologies

11.    Code of the Republic of Kazakhstan on Administrative Offences of 5 July 2014 No. 235-V — Kontinent

12.    Code of Administrative Offences — Paragraf

13.    Code of Administrative Offences — the Әділет mirror

14.    Criminal Code of the Republic of Kazakhstan of 3 July 2014 No. 226-V — Paragraf

15.    Law of the Republic of Kazakhstan of 8 December 2025 No. 239-VIII “On the Republican Budget for 2026–2028” — article 7(4): the monthly calculation index of KZT 4,325

16.    Law No. 239-VIII — a second independent source

17.    Paragraf analysis of the fine increases taking effect on 13 March 2025 under Law No. 155-VIII

18.    Law of the Republic of Kazakhstan of 24 November 2015 No. 418-V, now titled “On Cybersecurity” — renamed when the Digital Code took effect

Subordinate legislation

19.    Order of the Minister of Digital Development, Innovation and Aerospace Industry of 12 June 2023 No. 179/НҚ approving the Rules on measures to protect personal data — Әділет

20.    Order of 22 June 2026 No. 338/НҚ — the restated personal data protection Rules, in force from 12 July 2026

21.    Order of 30 April 2026 No. 232/НҚ — amendments to the Rules on notifying data subjects of a personal data security breach, in force from 12 July 2026

22.    Order of 11 March 2026 No. 133/НҚ — amendments to the Rules on collecting and processing personal data

23.    Order of the Minister of Digital Development, Innovation and Aerospace Industry of 29 April 2022 No. 144/НҚ approving the Rules on the functioning of the state personal data access control service

24.    Government Resolution of the Republic of Kazakhstan of 9 October 2025 No. 846 — the Regulation on the Ministry of Artificial Intelligence and Digital Development

25.    Order of the Deputy Prime Minister — Minister of Artificial Intelligence and Digital Development of 21 October 2025 No. 527/НҚ — the Regulation on the Committee for Information Security

State bodies and services

26.    The electronic government portal of the Republic of Kazakhstan

27.    The government portal of the Republic of Kazakhstan

28.    The permits and notifications portal, elicense.kz

29.    The open data portal of the Republic of Kazakhstan

Commentary and enforcement — second-tier sources

30.    Kazinform — the Digital Code takes effect on 12 July 2026

31.    zakon.kz — analysis of the Digital Code: what changes for citizens and business

32.    zakon.kz — new obligations for companies handling personal data under Law No. 326-VIII

33.    zakon.kz — the personal data protection Rules updated

34.    zakon.kz — the personal data access control Rules amended

35.    zakon.kz — the functions of the Ministry of Artificial Intelligence and Digital Development updated

36.    EY Kazakhstan — review of the updated personal data protection Rules, July 2026

37.    Kapital.kz — enforcement statistics in the personal data field

A note on sources and levels of confirmation. The official legislation portal of the Republic of Kazakhstan, adilet.zan.kz, is closed to automated access: every path on the domain is refused under its robots.txt rules. Links to it are retained in the list as the canonical addresses of the instruments. One route around the block did work: the Әділет portal opens manually in a browser, and through it the consolidated texts of Law No. 94-V, the Digital Code, the Code of Administrative Offences, the budget law and four ministerial orders were read in preparing this version, together with the texts of the amending Laws No. 231-VIII, No. 256-VIII and No. 326-VIII — the last of which supplied the verbatim wording of articles 10-1, 23-2 and 25-1. The texts were additionally reconciled against the consolidated versions published by Paragraf, the Kontinent legal database and the Әділет mirror on zakon.uchet.kz. Confirmed verbatim: article 8-1(1), article 12(2), the whole of article 16, the whole of article 19-1, the article 1 definitions, and article 27-1(7-2) and (7-4) of Law No. 94-V; articles 106, 43 and 48 of the Digital Code. The numbers and dates of all six key amending laws, and the numbers and dates of the subordinate orders, were reconciled against the amendment registers in the legal databases.

What could not be confirmed, and is therefore not asserted here. The verbatim text of articles 10-1, 23-2 and 25-1 was read in the amending Law No. 326-VIII itself on the Әділет portal; the consolidated body text of Law No. 94-V did not yet carry them at the date of writing. The subordinate rules on notifying the start of processing and on maintaining the register of persons are unpublished; the filing channel and any fee are not officially settled and are not asserted here. The calendar commencement date of the Digital Code — 12 July 2026 — rests on the Paragraf note, Kazinform reporting and, more weightily, on two registered ministerial orders — No. 338/НҚ and No. 232/НҚ — which are expressly brought into force “с 12.07.2026”. The Code itself states only the formula “по истечении шести месяцев после дня его первого официального опубликования”; first official publication occurred on 10 January 2026, from which individual databases derive 9 and 11 July. This analysis gives 12 July as the best-evidenced date but does not present it as an arithmetic consequence of article 106. The article 79 fine amounts for parts 2, 3 and 4 were reconciled across two independent sources returning identical figures; the part 1 amounts are additionally corroborated by the Paragraf analysis of Law No. 155-VIII. The 2025–2026 inspection and prosecution statistics are second-tier: the gov.kz portal is unusable for automated access and no primary regulator report or data.egov.kz dataset could be found. The attribution is separated in the text: the inspection figures and the growth in administrative cases come from the Ministry of Artificial Intelligence and Digital Development, and the criminal statistics from the Prosecutor General’s Office. The exact official name of the Ministry of Artificial Intelligence and Digital Development is confirmed by Government Resolution No. 846 and order No. 527/НҚ on the Әділет portal, both read in preparing this analysis.

On non-primary sources. This analysis does not rely on publications by hosting providers, IT service vendors, HR portals or “how to comply with the personal data law” round-ups. Commentary by international accounting firms and business media has been used solely for cross-checking and for enforcement data, and every such instance is marked in the text.

Current as at August 2026.

Disclaimer. This material is informational and does not constitute legal, tax, financial, investment or consulting advice. Before acting, obtain individual professional advice addressed to the specific circumstances, jurisdiction, status of the company and the requirements regulators apply at the time.

Read more on the topic

All services on the platform

Everything you need to start and run a business - in one place

  • 2–10 days

    Company Setup

    Kazakhstan company with a complete set of incorporation documents


    Start
  • Monthly

    Accounting Services

    Accounting and Tax Compliance, Reporting, and Support in Accordance with Kazakhstan Requirements


  • 4–8 weeks

    Immigration Services

    Visas, Work Permits


  • 7–30 days

    Banking Services

    Corporate Bank Accounts in Kazakhstan and Payment Services


  • Custom timeline

    Permits and Licenses

    Business Licenses and Activity Permits


  • Custom timeline

    Legal Services

    Corporate Documents, Contracts, Compliance, Licensing, and Company Structure Changes


Personal Data and Localisation in Kazakhstan in 2026: Law No. 94-V After the Amendments, the Ban on Automated Decisions, Two State Registers and the Fines | UPPERSETUP