Law note · Kazakhstan

Law on Personal Data and Their Protection, breach notification

cite Law No. 94-V (21 May 2013), Art. 25(2) stage IN FORCE in force since 2013-11-25 effective 2024-07-01 kind Breach notification binds public and private bodies reviewed 2026-08-29

What it requires

  • An app that suffers a personal data security breach involving Kazakhstani data subjects must notify the competent authority from the moment the breach is detected. The Law sets no numeric deadline for that notice and, on the text read, imposes no separate duty to notify the affected individuals themselves.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • processes_voice

What we found

Art. 25(2)(8) requires the owner or operator, from the moment a personal data security breach is detected, to notify the competent authority, naming the contact details of the person responsible for organizing personal data processing where one exists.

No numeric deadline for that notice was found in the text read, and no separate duty to notify the affected data subject of the breach itself was found; a distinct Art. 24(1)(5) duty to notify the subject of a third-party transfer of their data should not be confused with a breach notice.

Article 25 has been amended three times since the base Act's 2013 commencement; this research could confirm a fixed commencement date only for the most recent amendment, Law No. 44-VIII, which states its own effective date directly in the base Act's footnote rather than by a from-publication formula.

← Back to the example  ·  Lint your app →