Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
What it requires →
Chapter 11's own security article, Art. 88, carries no notification duty.
A general incident-notification duty exists instead at Art. 63, "Digital Resilience," outside Chapter 11 proper, now read in full at the official source in a reviewer pass and confirmed word for word: a record-owner or digital-service provider must notify the sectoral regulator of an incident affecting digital resilience or the rights and legitimate interests of subjects of legal relations in the digital environment within 72 hours of discovery (Art. 63(5); a late notice must explain the delay), and a processor must notify the record-owner within 48 hours of discovery (Art. 63(6)), with the notice describing the incident and an estimate of affected users, a responsible contact, a description of consequences, and remedial measures taken (Art. 63(7)), updated as new facts emerge (Art. 63(8)).
Art. 63 remains a general digital-resilience duty positioned outside Chapter 11 rather than a dedicated personal-data breach article, and Chapter 11 was not found to cross-reference it explicitly in what was read, but its own text plainly extends to "the rights and legitimate interests of subjects" in the digital environment, which covers a personal-data incident.
Comprehensive regime
What it requires →
Art. 78, read in full, states lawfulness/fairness/transparency, purpose limitation, data minimization, accuracy, and storage-limitation principles in a structure closely tracking General Data Protection Regulation (GDPR) Art. 5. Art. 88, also read in full, requires privacy-by-design measures, an operations log kept per regulator guidance, a personal-data-responsible person for organizations with more than ten employees, and staff training, with the Cabinet of Ministers setting protection-level requirements by regulation.
Art. 77, read in the reviewer pass, confirms the chapter applies to any personal-data processing including within digital records and resources, exempts a natural person's purely personal or family processing, and voids any conflicting or unpublished regulation. Art. 79 (the general processing-grounds list) was not read in either pass.
A reviewer pass confirmed the official government portal, cbd.minjust.gov.kg, is readable through the crawler's stealth rendering tier (81,674 characters via a direct fetch of the Digital Code's own page, matching every provision the research pass took from third-party mirrors), even though the plain HTTP tier the research pass used serves only a client-rendered JavaScript shell; this document's citations are re-sourced to that official page.
Cross border transfer
What it requires →
Art. 89, read in full and confirmed word for word against the official portal in a reviewer pass, has the sectoral personal-data regulator approve and publish a list of foreign states ensuring adequate protection; transfer to a listed state is carried out under the Code and may not be prohibited or restricted, a notably strong free-flow guarantee once a state is listed, and the record-owner must verify a destination's listing before transferring.
Transfer to a non-listed state may still occur on subject consent, an international treaty, statutory necessity for the constitutional order, national defense, or state security, or contract necessity, with the article's remaining grounds past a fourth not extracted here. No localization or in-country-storage mandate was found anywhere in Art. 89 or elsewhere in what was read, a real jurisdictional contrast with Kazakhstan, Uzbekistan, Tajikistan, and Turkmenistan in this batch.
Enforcement supervision
What it requires →
Art. 90, read in a reviewer pass at the official source (the research pass had not read it), requires the sectoral personal-data regulator to be created under Art. 9 of the Code and to be independent of the persons it oversees, with a head who must hold qualifications and experience in personal-data protection.
Art. 90(3) gives it real powers: applying and overseeing the Code; raising subject and controller awareness; advising state bodies; accrediting inspection bodies under Cabinet of Ministers procedure; hearing complaints and conducting inspections, including on its own initiative; taking preventive, corrective, and enforcement measures for violations; and publishing guidance. Art. 90(4) has it maintain a registry of record-owners recording incidents, inspection results, and binding decisions.
No fine schedule or private-right-of-action provision was found within Art. 90 or elsewhere read in either pass.
The Code's own text never names the regulator (it uses only "отраслевой регулятор в сфере персональных данных," sectoral regulator in the field of personal data, throughout, confirmed by a reviewer-pass search finding zero occurrences of "Агентство" anywhere in the Code); its identity as the State Agency for Protection of Personal Data (DPA) rests on the DPA's own official site, read directly, which describes itself in exactly these Digital-Code terms and institutionally predates the Code, having been established by a 2021 amendment to the now-repealed Law No. 58.
Sensitive categories
What it requires →
Art. 80(1), read in full and confirmed word for word against the official portal in a reviewer pass, prohibits processing by default: data revealing racial or ethnic origin, political views, religious or philosophical beliefs, or trade-union membership; genetic information; biometric data for the digital identification of a natural person; and data concerning health, sex life, or sexual orientation.
Art. 80(2) lifts the prohibition for contract necessity, explicit statutory authorization, vital-interest necessity, data the subject has explicitly made public, medical or public-health purposes, and (in part) membership processing by an association or religious organization.
No definition of biometric data as a general term was found anywhere in the official Code text (confirmed by a reviewer-pass search for the root "биометрич" across the whole document, which surfaces only Art. 48's state-system provisions and Art. 80(1)(3)'s bare category name); the only enumerated biometric-modality list in the Code is Art. 48(3)'s narrower, government-identification-system-specific list, confirmed at the official source to read exactly: digital facial image, papillary-pattern fingerprints of both hands, and handwritten signature, naming no voice modality, which should not be read as governing this general provision.