In brief

On 24 June 2026, the President of the Republic of Kazakhstan signed the Law "On Amendments and Additions to Certain Legislative Acts of the Republic of Kazakhstan on Digitalization, Personal Data Protection, Road Traffic, and the Regulation of Advanced Technologies in Transport" ("Law"). Most of the provisions of the Law relating to personal data protection will enter into force on 25 August 2026.

In addition, a new version of the Rules for the Implementation of Personal Data Protection Measures by Data Owners and/or Operators and Third Parties ("Rules") will enter into force on 12 July 2026. The updated Rules introduce revised organizational and technical requirements for personal data protection, including additional security measures applicable to the processing of restricted-access personal data.

Key takeaways

The Law introduces a risk-based classification of personal data controllers into small, medium, and large categories based on the volume of personal data processed. Small controllers include data owners and/or operators, as well as third parties, that collect and process personal data relating to no more than 10,000 unique data subjects. Medium controllers are those processing personal data relating to between 10,000 and 500,000 unique data subjects, while large controllers are those processing personal data relating to 500,000 or more unique data subjects. Where restricted-access personal data is collected and processed, the category of the data owner and/or operator is increased by one level. A controller's classification determines the personal data protection requirements applicable to its operations, with the processing of restricted-access personal data triggering a higher classification and, consequently, more stringent compliance obligations.

A register of entities engaged in the collection and/or processing of personal data will be established. In addition, large controllers will be required to notify the competent authority of the commencement and termination of personal data processing activities.

To strengthen government oversight and incident monitoring, the Law also establishes a Personal Data Security Breach Register, which will record instances of unauthorized access to personal data.

The Law defines a list of personal data identifiers, which include: (i) a data subject's surname, first name, and patronymic (if indicated in the identity document), taken together; (ii) the individual identification number (IIN); (iii) the data subject's facial image; and (iv) the data subject's facial biometric template (vector) or any derivatives thereof that can be reconstructed to their original form.

In more detail

The Rules significantly expand the obligations of data owners, operators, and third parties engaged in the processing of restricted-access personal data.

In particular, such entities are required to define the purposes of personal data processing, ensure the ability to block personal data upon a data subject's request, notify the competent authority of incidents involving unlawful access to personal data, and implement additional information security measures.

The new requirements include, among other things:

  • The use of data integrity control tools and mechanisms
  • The transmission of personal data through secure communication channels or with the use of encryption
  • The storage of personal data using cryptographic protection measures
  • The implementation of user identification and/or authentication mechanisms, including biometric authentication for databases containing more than 100,000 records of restricted-access personal data
  • The timely updating of information security tools and software; and the maintenance of database management system event logs to record operations involving the processing of restricted-access personal data.
Explore More Insight