Law note · Kazakhstan
Law on Personal Data and Their Protection, breach notification
What it requires
- An app that suffers a personal data security breach involving Kazakhstani data subjects must notify the competent authority from the moment the breach is detected. The Law sets no numeric deadline for that notice and, on the text read, imposes no separate duty to notify the affected individuals themselves.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
What we found
Art. 25(2)(8) requires the owner or operator, from the moment a personal data security breach is detected, to notify the competent authority, naming the contact details of the person responsible for organizing personal data processing where one exists.
No numeric deadline for that notice was found in the text read, and no separate duty to notify the affected data subject of the breach itself was found; a distinct Art. 24(1)(5) duty to notify the subject of a third-party transfer of their data should not be confused with a breach notice.
Article 25 has been amended three times since the base Act's 2013 commencement; this research could confirm a fixed commencement date only for the most recent amendment, Law No. 44-VIII, which states its own effective date directly in the base Act's footnote rather than by a from-publication formula.