{
 "jurisdiction_id": "KZ",
 "jurisdiction": "Kazakhstan",
 "url": "https://dataprotection.gi/jurisdictions/kazakhstan/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 19,
  "sub_modules": 57,
  "source_register": 29
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kazakhstan/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Core statute and a newly consolidated supervisory body are confirmed (T1/T2), but registration/filing mechanics and territorial-scope language remain unconfirmed in available sources.",
   "claims": [
    {
     "statement": "The Government of Kazakhstan approved the Information Security Committee under the Ministry of Artificial Intelligence and Digital Development (MAIDD) to regulate, implement, and oversee personal data protection and information security, including issuing penalties for violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/kazakhstan-government-establishes-information-security",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Law of the Republic of Kazakhstan of 21 May 2013 No. 94-V On Personal Data and its Protection is the primary omnibus instrument governing personal data processing in Kazakhstan.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (mirroring official text)",
     "source_url": "https://www.dataguidance.com/legal-research/law-republic-kazakhstan-21-may-2013-no-94-v-personal-data-and-its-protection",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Law of 25 June 2020 No. 347-VI on Amendments and Regulation of Digital Technologies established a data protection authority function and introduced requirements that personal data be collected and processed with valid consent and legitimate purpose.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/kazakhstan-provisions-processing-requirements-and-data-protection-authority-enter-force",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The MDAI Rules for the Collection and Processing of Personal Data (approved 23 October 2020) set requirements for collection, use and processing of personal data and set out data-subject rights including the right to be informed of what data is collected and for what purpose, and the right to rectify.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/kazakhstan-mdai-approves-rules-collection-and",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Draft amendments published for public consultation by MDAI in April 2021 proposed introducing a registrar and notification requirements for data-processing operators, with no confirmed enactment timeline.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/kazakhstan-mdai-publishes-proposed-amendments-data",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kazakhstan/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Consent threshold is confirmed at T1/T2; special categories, pseudonymisation/anonymisation safe-harbours are unconfirmed gaps.",
   "claims": [
    {
     "statement": "Draft amendments to the Personal Data Law reintroduced by Kazakhstan's digital-development ministry would ban the collection and dissemination of personal data from public resources without consent.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/kazakhstan-reintroduces-draft-data-protection-legislation-amendments/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Law No. 347-VI requires that personal data be collected and processed both with valid consent and through legitimate purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/kazakhstan-provisions-processing-requirements-and-data-protection-authority-enter-force",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kazakhstan/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Partial rights (access/rectification) confirmed in force; erasure is draft-stage only; portability, restriction/objection and deadlines are unconfirmed gaps.",
   "claims": [
    {
     "statement": "The 2020 MDAI Rules for the Collection and Processing of Personal Data include the right to be informed on what personal data is collected and stored and for what purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/kazakhstan-mdai-approves-rules-collection-and",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The 2020 MDAI Rules for the Collection and Processing of Personal Data include the right to rectify personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/kazakhstan-mdai-approves-rules-collection-and",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Draft amendments to the Personal Data Law would introduce a right to erasure not present in the current operative regime.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/kazakhstan-mdai-publishes-proposed-amendments-data",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "red",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kazakhstan/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Only retention-related and draft security-measure findings are confirmed; DPO, ROPA, joint-controller, breach-notification and DPIA sub-modules are unconfirmed gaps on a regime that otherwise claims omnibus status.",
   "claims": [
    {
     "statement": "Kazakhstan's Personal Data Law regime is accompanied by a specific DPO-appointment guidance note referencing the 2013 Law and the 2013 government decree on necessary/sufficient personal data, though the precise appointment threshold could not be confirmed from available sources.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/kazakhstan-data-protection-officer-appointment",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Draft amendments to the Personal Data Law published for consultation in April 2021 proposed new data-security measures and obligations for data operators.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/kazakhstan-mdai-publishes-proposed-amendments-data",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "A Government Decree of 12 November 2013 approved Rules for Determining the List of Personal Data Necessary and Sufficient for the Owner and/or Operator to Perform their Task under the Personal Data Law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/kazakhstan-data-protection-officer-appointment",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kazakhstan/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Data-localisation mandate is clearly confirmed at T2; adequacy/SCC/BCR/TIA mechanisms are unconfirmed gaps, consistent with a localisation-first rather than adequacy-based transfer model.",
   "claims": [
    {
     "statement": "Legal commentary on Kazakhstan's localisation regime concluded that parallel storage of a database both within Kazakhstan and abroad would also not be permitted.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/kazakhstan-new-user-identification-regulates-website-telecommunications-operators/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Under the Personal Data Law No. 94-V, data operators are required to maintain their personal information databases within the territory of Kazakhstan.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/kazakhstan-new-user-identification-regulates-website-telecommunications-operators/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Law of 28 December 2017 No. 128-VI requires website operators and telecommunications operators to store subscriber/user data solely within Kazakhstan and prohibits cross-border transfer of such data except where necessary to provide roaming services.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/kazakhstan-new-user-identification-regulates-website-telecommunications-operators/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "red",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kazakhstan/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Single confirmed sectoral overlay (telecoms) against six unconfirmed sub-modules; broad sectoral picture is materially incomplete.",
   "claims": [
    {
     "statement": "Under the Law of 24 November 2015 No. 418-V on Informatisation, as amended by Law No. 128-VI of 28 December 2017, owners of publicly available electronic informational resources (website operators) are required to identify website users who intend to publish information on an operator's website.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/kazakhstan-new-user-identification-regulates-website-telecommunications-operators/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kazakhstan/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "No sub-module returned confirmed evidence; this module carries a full absent-field gap rather than a substantive finding.",
   "claims": []
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "red",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kazakhstan/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "No sub-module returned confirmed evidence in this research pass; full absent-field gap.",
   "claims": []
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "red",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kazakhstan/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "No sub-module returned confirmed Kazakhstan-specific evidence in this research pass; full absent-field gap.",
   "claims": []
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kazakhstan/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Penalty framework and a 2025 institutional consolidation are confirmed; enforcement track record, funding/capacity, and collective/private redress remain unconfirmed gaps.",
   "claims": [
    {
     "statement": "The Code of the Republic of Kazakhstan of 5 July 2014 No. 235-V on Administrative Infractions provides the administrative-liability framework applicable to violations of personal data protection requirements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance (mirroring official text)",
     "source_url": "https://www.dataguidance.com/legal-research/code-republic-kazakhstan-5-july-2014-no-235-v-administrative-infractions",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Government of Kazakhstan approved the Information Security Committee under MAIDD, which will monitor information security across state bodies, individuals, and legal entities, respond to incidents, issue penalties for violations of personal-data and information-security legislation, and coordinate with national and international partners on cybersecurity policy.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/kazakhstan-government-establishes-information-security",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  }
 ]
}