Law note · Kyrgyzstan
Digital Code, cross-border transfer of personal data
What it requires
- An app transferring the personal data of a Kyrgyzstani data subject, including a voiceprint or other biometric identifier, to a state the sectoral regulator has listed as adequate may do so freely. Transfer to a non-listed state requires the subject's consent, a qualifying treaty, statutory necessity, or contract necessity. Kyrgyzstan imposes no domestic-storage or localization requirement on the data itself.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
What we found
Art. 89, read in full and confirmed word for word against the official portal in a reviewer pass, has the sectoral personal-data regulator approve and publish a list of foreign states ensuring adequate protection; transfer to a listed state is carried out under the Code and may not be prohibited or restricted, a notably strong free-flow guarantee once a state is listed, and the record-owner must verify a destination's listing before transferring.
Transfer to a non-listed state may still occur on subject consent, an international treaty, statutory necessity for the constitutional order, national defense, or state security, or contract necessity, with the article's remaining grounds past a fourth not extracted here. No localization or in-country-storage mandate was found anywhere in Art. 89 or elsewhere in what was read, a real jurisdictional contrast with Kazakhstan, Uzbekistan, Tajikistan, and Turkmenistan in this batch.
Primary source
official government portal
Centralized Bank of Legal Information of the Kyrgyz Republic (cbd.minjust.gov.kg), which serves this page's text only to a rendering tier: a plain HTTP fetch of this same URL returns a 1,961-character JavaScript shell with zero hits for any Chapter 11 term, while the crawler's STEALTH_PLUS rendering tier returns the full 657,172-character document confirmed directly against this URL