🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
KZ · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 10 sources retrieved model claude-sonnet-5 ·

Kazakhstan

KZ schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 19 claims · 10 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
19Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core statute and a newly consolidated supervisory body are confirmed (T1/T2), but registration/filing mechanics and territorial-scope language remain unconfirmed in available sources.

Primary frameworkLaw of the Republic of Kazakhstan of 21 May 2013 No. 94-V On Personal Data and its Protection (as amended by Law No. 347-VI of 25 June 2020)
Supervisory authorityInformation Security Committee under the Ministry of Artificial Intelligence and Digital Development (MAIDD)
Traffic-light rationale — AmberCore statute and a newly consolidated supervisory body are confirmed (T1/T2), but registration/filing mechanics and territorial-scope language remain unconfirmed in available sources.

Sub-modules (5)

Regulator And AuthorityAmber

Supervisory function now sits with the Information Security Committee under MAIDD, established by government decision to regulate and enforce data-protection and information-security law.

Claims: CLM-KZ-a1b2c3d4

Act And InstrumentsGreen

Primary instrument is Law No. 94-V (2013), amended/operationalised by Law No. 347-VI (2020) which introduced the data protection authority function and consent/legitimate-purpose collection requirements.

Claims: CLM-KZ-b2c3d4e5, CLM-KZ-c3d4e5f6

Material ScopeAmber

Material scope is elaborated via subordinate MDAI Rules for the Collection and Processing of Personal Data, covering data-subject rights to information and rectification.

Claims: CLM-KZ-d4e5f6a7

Territorial ScopeRed

No confirmed statutory language on extraterritorial/non-established-controller application was located in available sources.

Absence provenance: not recorded. Searched: Kazakhstan personal data law territorial scope non-established controllers, Kazakhstan extraterritorial application data protection.

Regulator Registration And FilingRed

A registrar/notification model for data-processing operators has been proposed via draft amendments but had no confirmed enactment timeline as of the last located public consultation record.

Claims: CLM-KZ-e5f6a7b8

Category narrative153 words

Kazakhstan's data-protection regime rests on the omnibus Law No. 94-V of 21 May 2013 On Personal Data and its Protection, amended and operationalised by the Law of 25 June 2020 No. 347-VI. <cite index="95-3,95-4">The Law provides for the establishment of a data protection authority, which will carry out its competencies in the management of data protection supervision and enforcement and issue guidance and clarifications, and introduces new data collection and processing requirements such as the need for data to be collected and processed both with valid consent and through legitimate purposes.</cite> Supervisory capacity has since been consolidated: <cite index="34-1,34-2">the government approved the Information Security Committee under the Ministry of Artificial Intelligence and Digital Development (MAIDD), which will regulate, implement, and oversee activities in informatization, personal data protection, and information security.</cite> Registration/filing obligations remain in a state of flux, with a registrar/notification model only at draft stage as of the last confirmed public consultation.

Sources and claims (5)
  1. ConfirmedDataGuidanceThe Government of Kazakhstan approved the Information Security Committee under the Ministry of Artificial Intelligence and Digital Development (MAIDD) to regulate, implement, and oversee personal data protection and information security, including issuing penalties for violations.
  2. ConfirmedDataGuidance (mirroring official text)The Law of the Republic of Kazakhstan of 21 May 2013 No. 94-V On Personal Data and its Protection is the primary omnibus instrument governing personal data processing in Kazakhstan.
  3. ConfirmedDataGuidanceThe Law of 25 June 2020 No. 347-VI on Amendments and Regulation of Digital Technologies established a data protection authority function and introduced requirements that personal data be collected and processed with valid consent and legitimate purpose.
  4. ConfirmedDataGuidanceThe MDAI Rules for the Collection and Processing of Personal Data (approved 23 October 2020) set requirements for collection, use and processing of personal data and set out data-subject rights including the right to be informed of what data is collected and for what purpose, and the right to rectify.
  5. ProbableDataGuidanceDraft amendments published for public consultation by MDAI in April 2021 proposed introducing a registrar and notification requirements for data-processing operators, with no confirmed enactment timeline.

#

Consent threshold is confirmed at T1/T2; special categories, pseudonymisation/anonymisation safe-harbours are unconfirmed gaps.

Primary frameworkLaw No. 94-V (2013), as amended by Law No. 347-VI (2020)
Supervisory authorityInformation Security Committee under MAIDD
Traffic-light rationale — AmberConsent threshold is confirmed at T1/T2; special categories, pseudonymisation/anonymisation safe-harbours are unconfirmed gaps.

Sub-modules (4)

Lawful BasesAmber

Draft amendments would prohibit collection/dissemination of personal data from public resources without consent; not yet confirmed as enacted.

Claims: CLM-KZ-f6a7b8c9

Special CategoriesRed

No confirmed statutory enumeration of special/sensitive data categories was located.

Absence provenance: not recorded. Searched: Kazakhstan special categories sensitive personal data biometric genetic health law.

Pseudonymisation And AnonymisationRed

No confirmed statutory definition or safe-harbour for pseudonymisation/anonymisation was located.

Absence provenance: not recorded. Searched: Kazakhstan pseudonymisation anonymisation personal data law.

Category narrative43 words

Lawful-basis and consent standards derive from Law No. 347-VI (2020), which conditions collection/processing on valid consent and legitimate purpose. Draft amendments would further restrict use of publicly available personal data absent consent, but special-category and pseudonymisation/anonymisation rules were not confirmed in available sources.

Sources and claims (2)
  1. ProbableIAPPDraft amendments to the Personal Data Law reintroduced by Kazakhstan's digital-development ministry would ban the collection and dissemination of personal data from public resources without consent.
  2. ConfirmedDataGuidanceLaw No. 347-VI requires that personal data be collected and processed both with valid consent and through legitimate purposes.

#

Partial rights (access/rectification) confirmed in force; erasure is draft-stage only; portability, restriction/objection and deadlines are unconfirmed gaps.

Primary frameworkLaw No. 94-V (2013); MDAI Rules for the Collection and Processing of Personal Data (2020)
Supervisory authorityInformation Security Committee under MAIDD
Traffic-light rationale — AmberPartial rights (access/rectification) confirmed in force; erasure is draft-stage only; portability, restriction/objection and deadlines are unconfirmed gaps.

Sub-modules (5)

Access RightGreen

Right to be informed on what personal data is collected/stored and for what purpose is set out in the 2020 Rules.

Claims: CLM-KZ-b8c9d0e1

Rectification And ErasureAmber

Right to rectify is confirmed in force; right to erasure exists only as a draft-amendment proposal.

Claims: CLM-KZ-c9d0e1f2, CLM-KZ-d0e1f2a3

Restriction And ObjectionRed

No confirmed restriction/objection (including profiling opt-out) right was located.

Absence provenance: not recorded. Searched: Kazakhstan right to restrict processing right to object profiling opt-out.

Data PortabilityRed

No confirmed data-portability right was located.

Absence provenance: not recorded. Searched: Kazakhstan data portability right personal data law.

Deadlines And Response WindowsRed

No confirmed statutory deadline for controller response to data-subject requests was located.

Absence provenance: not recorded. Searched: Kazakhstan personal data subject access request deadline response time.

Category narrative42 words

Confirmed data-subject rights are limited to the right to be informed and the right to rectify, set out in the 2020 MDAI Rules. A right to erasure appears only in unenacted draft amendments; portability, restriction/objection and statutory response deadlines were not confirmed.

Sources and claims (3)
  1. ConfirmedDataGuidanceThe 2020 MDAI Rules for the Collection and Processing of Personal Data include the right to be informed on what personal data is collected and stored and for what purposes.
  2. ConfirmedDataGuidanceThe 2020 MDAI Rules for the Collection and Processing of Personal Data include the right to rectify personal data.
  3. ProbableDataGuidanceDraft amendments to the Personal Data Law would introduce a right to erasure not present in the current operative regime.

#

Only retention-related and draft security-measure findings are confirmed; DPO, ROPA, joint-controller, breach-notification and DPIA sub-modules are unconfirmed gaps on a regime that otherwise claims omnibus status.

Primary frameworkLaw No. 94-V (2013); Government Decree of 12 November 2013
Supervisory authorityInformation Security Committee under MAIDD
Traffic-light rationale — RedOnly retention-related and draft security-measure findings are confirmed; DPO, ROPA, joint-controller, breach-notification and DPIA sub-modules are unconfirmed gaps on a regime that otherwise claims omnibus status.

Sub-modules (7)

Accountability And DpiaRed

No confirmed DPIA trigger or accountability-documentation requirement was located.

Absence provenance: not recorded. Searched: Kazakhstan DPIA data protection impact assessment requirement.

Dpo RequirementsRed

A DataGuidance guidance note on DPO appointment references the 2013 Personal Data Law and a 2013 government decree, but the specific appointment threshold text could not be confirmed from available search results.

Absence provenance: not recorded. Searched: Kazakhstan DPO appointment threshold personal data law.

Claims: CLM-KZ-e1f2a3b4

Ropa RequirementsRed

No confirmed records-of-processing (ROPA) obligation was located.

Absence provenance: not recorded. Searched: Kazakhstan records of processing activities requirement.

Joint Controller ArrangementsRed

No confirmed joint-controller regime was located.

Absence provenance: not recorded. Searched: Kazakhstan joint controller personal data law.

Security MeasuresAmber

Draft amendments propose new data-security measures and obligations for operators, alongside stricter data-subject informing requirements.

Claims: CLM-KZ-f2a3b4c5

Breach NotificationRed

No confirmed statutory breach-notification threshold or timeline (to regulator or data subjects) was located.

Absence provenance: not recorded. Searched: Kazakhstan personal data breach notification requirement timeline.

Retention And DisposalAmber

A 2013 government decree approved rules for determining the list of personal data necessary and sufficient for an owner/operator to perform its task, functioning as a data-minimisation constraint.

Claims: CLM-KZ-a3b4c5d6

Category narrative46 words

Retention is partially addressed via a 2013 government decree limiting data holdings to what is necessary and sufficient for the operator's task. Draft amendments propose new security-measure obligations. DPO appointment thresholds, ROPA duties, joint-controller arrangements, breach-notification timelines and DPIA triggers were not confirmed in available sources.

Sources and claims (3)
  1. UncertainDataGuidanceKazakhstan's Personal Data Law regime is accompanied by a specific DPO-appointment guidance note referencing the 2013 Law and the 2013 government decree on necessary/sufficient personal data, though the precise appointment threshold could not be confirmed from available sources.
  2. ProbableDataGuidanceDraft amendments to the Personal Data Law published for consultation in April 2021 proposed new data-security measures and obligations for data operators.
  3. ConfirmedDataGuidanceA Government Decree of 12 November 2013 approved Rules for Determining the List of Personal Data Necessary and Sufficient for the Owner and/or Operator to Perform their Task under the Personal Data Law.

#

Data-localisation mandate is clearly confirmed at T2; adequacy/SCC/BCR/TIA mechanisms are unconfirmed gaps, consistent with a localisation-first rather than adequacy-based transfer model.

Primary frameworkLaw No. 94-V (2013); Law on Informatisation No. 418-V (2015), as amended by Law No. 128-VI (2017)
Supervisory authorityInformation Security Committee under MAIDD
Traffic-light rationale — AmberData-localisation mandate is clearly confirmed at T2; adequacy/SCC/BCR/TIA mechanisms are unconfirmed gaps, consistent with a localisation-first rather than adequacy-based transfer model.

Sub-modules (6)

Transfer MechanismsAmber

Legal commentary indicates that parallel storage of a database both in Kazakhstan and abroad would evidently also not be permitted, underscoring the localisation-first approach to transfers.

Claims: CLM-KZ-b4c5d6e7

Adequacy ReceivedRed

No adequacy decision received by Kazakhstan from another regime was located.

Absence provenance: not recorded. Searched: Kazakhstan adequacy decision received EU GDPR.

Adequacy GrantedRed

No adequacy decision granted by Kazakhstan to another regime was located.

Absence provenance: not recorded. Searched: Kazakhstan adequacy decision granted to other jurisdictions.

Sccs And BcrsRed

No confirmed SCC or BCR mechanism was located.

Absence provenance: not recorded. Searched: Kazakhstan standard contractual clauses binding corporate rules data transfer.

Transfer Impact AssessmentRed

No confirmed transfer-impact-assessment requirement was located.

Absence provenance: not recorded. Searched: Kazakhstan transfer impact assessment cross-border data.

Data LocalisationGreen

Personal-data databases must be maintained in Kazakhstan, and website/telecom operator user data is subject to a cross-border transfer prohibition except for roaming.

Claims: CLM-KZ-c5d6e7f8, CLM-KZ-d6e7f8a9

Category narrative45 words

Kazakhstan operates a data-localisation-centric transfer regime rather than an adequacy/SCC-based model. Data operators must maintain personal-data databases within Kazakhstan, and website/telecommunications operators are further restricted from transferring collected user data abroad except for roaming purposes. No adequacy decisions, SCC/BCR mechanisms, or transfer-impact-assessment requirements were confirmed.

Sources and claims (3)
  1. ProbableDataGuidanceLegal commentary on Kazakhstan's localisation regime concluded that parallel storage of a database both within Kazakhstan and abroad would also not be permitted.
  2. ConfirmedDataGuidanceUnder the Personal Data Law No. 94-V, data operators are required to maintain their personal information databases within the territory of Kazakhstan.
  3. ConfirmedDataGuidanceThe Law of 28 December 2017 No. 128-VI requires website operators and telecommunications operators to store subscriber/user data solely within Kazakhstan and prohibits cross-border transfer of such data except where necessary to provide roaming services.

#

Single confirmed sectoral overlay (telecoms) against six unconfirmed sub-modules; broad sectoral picture is materially incomplete.

Primary frameworkLaw on Informatisation No. 418-V (2015), as amended by Law No. 128-VI (2017)
Supervisory authorityInformation Security Committee under MAIDD
Traffic-light rationale — RedSingle confirmed sectoral overlay (telecoms) against six unconfirmed sub-modules; broad sectoral picture is materially incomplete.

Sub-modules (7)

Financial Sector OverlayRed

No confirmed financial-sector-specific personal-data overlay (e.g., National Bank rules) was located.

Absence provenance: not recorded. Searched: Kazakhstan banking secrecy law National Bank personal data financial sector.

Health Sector OverlayRed

No confirmed health-sector-specific personal-data overlay was located.

Absence provenance: not recorded. Searched: Kazakhstan health data protection law patient records.

Telecoms And EprivacyAmber

Website and telecommunications operators must identify users intending to publish information on their platforms, under the Informatisation Law as amended.

Claims: CLM-KZ-e7f8a9b0

Employment DataRed

No confirmed employment-data-specific overlay was located.

Absence provenance: not recorded. Searched: Kazakhstan employment data protection labour code personal data.

Credit And ScoringRed

No confirmed credit-scoring-specific personal-data overlay was located.

Absence provenance: not recorded. Searched: Kazakhstan credit scoring bureau personal data law.

EducationRed

No confirmed education-sector-specific personal-data overlay was located.

Absence provenance: not recorded. Searched: Kazakhstan education sector student data protection law.

InsuranceRed

No confirmed insurance-sector-specific personal-data overlay was located.

Absence provenance: not recorded. Searched: Kazakhstan insurance sector personal data law.

Category narrative34 words

Only a telecoms/online-identification overlay is confirmed: website and telecommunications operators face user-identification obligations under the Informatisation Law regime. Financial, health, employment, credit-scoring, education and insurance sector-specific personal-data overlays were not confirmed in available sources.

Sources and claims (1)
  1. ConfirmedDataGuidanceUnder the Law of 24 November 2015 No. 418-V on Informatisation, as amended by Law No. 128-VI of 28 December 2017, owners of publicly available electronic informational resources (website operators) are required to identify website users who intend to publish information on an operator's website.

#

No sub-module returned confirmed evidence; this module carries a full absent-field gap rather than a substantive finding.

Traffic-light rationale — RedNo sub-module returned confirmed evidence; this module carries a full absent-field gap rather than a substantive finding.

Sub-modules (6)

Cookies And TrackersRed

No confirmed cookie/tracker consent rule located.

Absence provenance: not recorded. Searched: Kazakhstan cookie consent law tracker regulation.

Dark PatternsRed

No confirmed dark-pattern prohibition located.

Absence provenance: not recorded. Searched: Kazakhstan dark patterns consumer protection data law.

Opt Out SignalsRed

No confirmed recognition of opt-out signals (e.g., GPC) located.

Absence provenance: not recorded. Searched: Kazakhstan global privacy control opt-out signal recognition.

Clean Rooms And DcrRed

No confirmed clean-room/data-collaboration-room rule located.

Absence provenance: not recorded. Searched: Kazakhstan data clean room data collaboration regulation.

Cross Context AdvertisingRed

No confirmed cross-context-advertising rule (sale/share analogue) located.

Absence provenance: not recorded. Searched: Kazakhstan cross-context advertising data sale share regulation.

Direct MarketingRed

No confirmed direct-marketing consent/suppression regime located.

Absence provenance: not recorded. Searched: Kazakhstan direct marketing consent suppression list law.

Category narrative25 words

No confirmed cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room framework, cross-context-advertising rule, or direct-marketing consent/suppression regime specific to Kazakhstan was located in available sources.

#

No sub-module returned confirmed evidence in this research pass; full absent-field gap.

Traffic-light rationale — RedNo sub-module returned confirmed evidence in this research pass; full absent-field gap.

Sub-modules (6)

Profiling RestrictionsRed

No confirmed profiling-restriction provision located.

Absence provenance: not recorded. Searched: Kazakhstan profiling restriction automated decision personal data law.

Automated Decision Making TransparencyRed

No confirmed ADM transparency/explanation right located.

Absence provenance: not recorded. Searched: Kazakhstan automated decision making transparency right explanation.

Ai Risk AssessmentsRed

No confirmed AI-specific risk-assessment obligation located.

Absence provenance: not recorded. Searched: Kazakhstan artificial intelligence law risk assessment data.

Biometric RegimeRed

No confirmed biometric-data-specific regime (facial recognition, fingerprint, gait) located.

Absence provenance: not recorded. Searched: Kazakhstan biometric data law facial recognition fingerprint.

Genetic DataRed

No confirmed genetic-data-specific regime located.

Absence provenance: not recorded. Searched: Kazakhstan genetic data protection law.

State Surveillance CarveoutsRed

No confirmed national-security/state-surveillance carve-out and its limits located.

Absence provenance: not recorded. Searched: Kazakhstan national security exemption data protection surveillance.

Category narrative26 words

No confirmed profiling restriction, ADM-transparency right, AI-specific risk-assessment obligation, biometric-data regime, genetic-data regime, or state-surveillance carve-out specific to Kazakhstan's personal-data framework was located in available sources.

#

No sub-module returned confirmed Kazakhstan-specific evidence in this research pass; full absent-field gap.

Traffic-light rationale — RedNo sub-module returned confirmed Kazakhstan-specific evidence in this research pass; full absent-field gap.

Sub-modules (5)

Age VerificationRed

No confirmed statutory age-of-consent threshold for data processing located.

Absence provenance: not recorded. Searched: Kazakhstan child personal data age consent minors law.

Minor Profiling BansRed

No confirmed profiling ban specific to minors located.

Absence provenance: not recorded. Searched: Kazakhstan minors profiling ban personal data.

Education SettingsRed

No confirmed education-setting-specific rule located.

Absence provenance: not recorded. Searched: Kazakhstan school student data protection rule.

Dependent AdultsRed

No confirmed dependent-adult protection provision located.

Absence provenance: not recorded. Searched: Kazakhstan dependent adults incapacitated persons data protection.

Category narrative19 words

No confirmed Kazakhstan-specific age-of-consent threshold, parental-consent mechanism, minor-profiling ban, education-setting rule, or dependent-adult protection was located in available sources.

#

Penalty framework and a 2025 institutional consolidation are confirmed; enforcement track record, funding/capacity, and collective/private redress remain unconfirmed gaps.

Primary frameworkCode of the Republic of Kazakhstan of 5 July 2014 No. 235-V on Administrative Infractions
Supervisory authorityInformation Security Committee under MAIDD
Traffic-light rationale — AmberPenalty framework and a 2025 institutional consolidation are confirmed; enforcement track record, funding/capacity, and collective/private redress remain unconfirmed gaps.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The Administrative Infractions Code No. 235-V provides the administrative-liability framework applicable to personal-data violations; the 2025 Information Security Committee holds express power to issue penalties.

Claims: CLM-KZ-f8a9b0c1, CLM-KZ-a9b0c1d2

Enforcement Activity IndexRed

No confirmed record of major enforcement decisions or fines in the last 12 months was located.

Absence provenance: not recorded. Searched: Kazakhstan data protection enforcement fine decision 2025 2026.

Regulator Funding And CapacityRed

No confirmed headcount or funding data for the Information Security Committee/MAIDD data-protection function was located.

Absence provenance: not recorded. Searched: Kazakhstan Information Security Committee MAIDD budget staffing.

Collective Redress And Class ActionsRed

No confirmed collective-redress or class-action mechanism for data-subject claims was located.

Absence provenance: not recorded. Searched: Kazakhstan class action collective redress personal data.

Private Right Of ActionRed

No confirmed private right of direct court access for data-subject claims was located.

Absence provenance: not recorded. Searched: Kazakhstan private right of action personal data court claim.

Recent Developments 180DAmber

The most recent confirmed development is the government's approval of the Information Security Committee under MAIDD, consolidating data-protection and information-security oversight, penalty issuance, and incident response.

Claims: CLM-KZ-a9b0c1d2

Category narrative65 words

Administrative liability for personal-data violations is grounded in the Code of the Republic of Kazakhstan of 5 July 2014 No. 235-V on Administrative Infractions. The most material recent development is the government's 2025 establishment of an Information Security Committee under MAIDD with express power to issue penalties for violations. Enforcement-activity track record, regulator funding/capacity, collective-redress mechanisms and private-right-of-action provisions were not confirmed in available sources.

Sources and claims (2)
  1. ProbableDataGuidance (mirroring official text)The Code of the Republic of Kazakhstan of 5 July 2014 No. 235-V on Administrative Infractions provides the administrative-liability framework applicable to violations of personal data protection requirements.
  2. ConfirmedDataGuidanceThe Government of Kazakhstan approved the Information Security Committee under MAIDD, which will monitor information security across state bodies, individuals, and legal entities, respond to incidents, issue penalties for violations of personal-data and information-security legislation, and coordinate with national and international partners on cybersecurity policy.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Kazakhstan
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 19 claim(s), 29 source(s) in the cumulative register.