Law / Kazakhstan

Kazakhstan

privacy

Kazakhstan's Law No. 94-V "On Personal Data and Their Protection" (21 May 2013, as amended through Law No. 256-VIII, still phasing in as of 09.01.2026) is a single Act covering both public and private processing, built on subject consent (Art. 8) rather than a General Data Protection Regulation (GDPR)-style special-category list.

It requires personal data to be stored in a database physically located in Kazakhstan (Art. 12(2)), unqualified by citizenship and with no textual bar on an additional foreign copy, separately conditions any cross-border transfer on an adequacy test or one of four fallback grounds (Art. 16), and bars bulk database-building from publicly available sources (Art. 7(11)).

Biometric data is never defined in the Act itself; it appears only in scattered clauses, including one that defers biometric confidentiality entirely to unnamed other Kazakh legislation (Art. 11(3)), a deferral pattern this batch also finds word for word in Tajikistan and Turkmenistan.

Breach notification runs to the competent authority only, with no numeric deadline and no confirmed duty to notify affected individuals, and enforcement combines a general civil-damages right (Art. 24(1)(7)) with penalties under the separate Code of Administrative Offences (Art. 79) rather than the Personal Data Law itself.

15 instruments named 6 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Biometric privacy

Law on Personal Data and Their Protection, biometric data provisions

cite Law No. 94-V (21 May 2013), Arts. 7(12), 11(3), 12(2) stage IN FORCE in force since 2013-11-25 effective 2022-03-01 binds public and private bodies source official statute text, Adilet Legal Information System, consolidated English translation
What it requires

The Act has no dedicated special-category article and never defines biometric data as a term; it regulates biometric processing through three scattered clauses instead.

Art. 7(12) restricts collecting biometric data in public places to constitutional-order, public-order, rights, health, or morality purposes unless the subject consents; this clause was reworded by Law No. 96-VII (30 December 2021, in force 1 March 2022), so the currently quoted text has been in effect since that date, not since the Act's 2013 commencement.

Art. 11(3) defers biometric confidentiality entirely to unnamed other Kazakh legislation this research did not identify, and carries no amendment footnote of its own, so it has stood unchanged since the base Act's 25 November 2013 commencement. Art. 12(2)'s domestic-storage duty applies to biometric data as ordinary personal data; that duty was itself introduced by Law No. 419-V, in force 1 January 2016, with no biometric-specific carve-out or heightening found. No modality (face, voice, fingerprint) is named anywhere in the Act.

Breach notification

Law on Personal Data and Their Protection, breach notification

cite Law No. 94-V (21 May 2013), Art. 25(2) stage IN FORCE in force since 2013-11-25 effective 2024-07-01 binds public and private bodies source official statute text, Adilet Legal Information System, consolidated English translation
What it requires

Art. 25(2)(8) requires the owner or operator, from the moment a personal data security breach is detected, to notify the competent authority, naming the contact details of the person responsible for organizing personal data processing where one exists.

No numeric deadline for that notice was found in the text read, and no separate duty to notify the affected data subject of the breach itself was found; a distinct Art. 24(1)(5) duty to notify the subject of a third-party transfer of their data should not be confused with a breach notice.

Article 25 has been amended three times since the base Act's 2013 commencement; this research could confirm a fixed commencement date only for the most recent amendment, Law No. 44-VIII, which states its own effective date directly in the base Act's footnote rather than by a from-publication formula.

Comprehensive regime

Law on Personal Data and Their Protection, comprehensive regime and lawful bases

cite Law No. 94-V (21 May 2013), as amended through Law No. 256-VIII (09.01.2026), Arts. 1, 4-9 stage IN FORCE in force since 2013-11-25 binds public and private bodies source official statute text, Adilet Legal Information System, consolidated English translation
What it requires

Law No. 94-V is Kazakhstan's single personal-data statute, reaching the owner, operator, and third party generally with no separate public and private carve-out found in the text read. Art. 8 requires the subject's written or otherwise confirmable consent for processing, subject to Art. 9's consent-free grounds (law enforcement, court proceedings, state statistics, and others), and confines processing to the stated purpose of collection.

The Law was adopted 21 May 2013, officially published 25 May 2013, and entered into force 25 November 2013 (Art. 31(1), six months after first official publication); Arts. 8 and 9 have each been amended multiple times since, most recently in 2025 and 2026, without displacing the base consent framework this instrument describes.

Cross border transfer

Law on Personal Data and Their Protection, localization and cross-border transfer

cite Law No. 94-V (21 May 2013), Arts. 12(2), 16 stage IN FORCE in force since 2013-11-25 effective 2016-01-01 binds public and private bodies source official statute text, Adilet Legal Information System, consolidated English translation
What it requires

Art. 12(2) requires a database of Kazakhstani personal data to be located inside Kazakhstan, unqualified by citizenship and, on the text read, not framed as forbidding an additional copy abroad; it answers where data is stored, not whether it may also leave the country. This storage duty was introduced by Law No. 419-V, in force 1 January 2016; Art. 12(2) did not exist in this form at the base Act's 2013 commencement.

Art. 16 answers the leaving-the-country question separately, and its general permitted-transfer grounds (paragraphs 1-4: an adequacy-equivalent destination, or one of four fallback grounds, subject consent, a ratified treaty, statutory necessity, or protection of constitutional rights where consent cannot be obtained) are original 2013 text, unamended since the base Act's commencement; a sector law may impose a harder bar than the general Law does.

Data subject rights

Law on Personal Data and Their Protection, data subject rights

cite Law No. 94-V (21 May 2013), Art. 24; Art. 8(7); Art. 19-1 stage IN FORCE in force since 2013-11-25 effective 2026-01-17 binds public and private bodies source official statute text, Adilet Legal Information System, consolidated English translation
What it requires

Art. 24 gives the subject the right to know about and obtain information on processing, demand correction or supplementation, demand blocking where a violation is alleged, demand destruction where a violation is confirmed, withdraw consent (including specifically for a cross-border or third-party transfer), consent or withdraw consent to public-source distribution, and seek protection of rights and compensation for moral and material damage.

Art. 24 was reworded by Law No. 96-VII (30 December 2021, in force 1 March 2022); the version quoted here is that current text, not the Act's original 2013 wording.

Separately, Art. 8(7) requires the owner or operator to stop processing personal data within fifteen working days of a subject withdrawing consent, or to give a reasoned refusal, a duty carried by Article 8 since before its most recent 2025 and 2026 amendments, though this research could not isolate which of Article 8's five stacked amending laws last touched paragraph 7 specifically.

A newer right was added by Law No. 231-VIII (17 November 2025, in force 17 January 2026) at new Art. 19-1: a subject may object to automated processing of their personal data, and the owner, operator, or third party must consider the objection and respond within three working days. This is the automated-decision-objection right this batch's Israel document flagged as unconfirmed either way; Kazakhstan now has one.

Enforcement supervision

Code of Administrative Offences, personal data violations

cite Code of the Republic of Kazakhstan on Administrative Offences No. 235-V (2014), Art. 79 stage IN FORCE in force since 2015-01-01 effective 2025-03-12 binds public and private bodies source official statute text, Adilet Legal Information System, Code of Administrative Offences
What it requires

Art. 79 of the Code of Administrative Offences, not the Personal Data Law itself, sets the fine schedule for a breach of Kazakhstan's personal-data legislation, starting at thirty monthly calculation indices for individuals for illegal collection or processing of personal data and scaling up by entity type. The Code was adopted 5 July 2014 and entered into force 1 January 2015 (Art. 920).

Article 79's fine schedule has since been amended four times; the most recent, Law No. 155-VIII, raised the amounts and took effect 12 March 2025. The Ministry of Artificial Intelligence and Digital Development (formed 28 September 2025) and its Committee for Information Security are the competent authority; no private right of action was found in the Personal Data Law, which instead gives the subject a general civil-damages right at Art. 24(1)(7).

A separate AI-specific fine article and a Criminal Code backstop were not read at primary source and are not recorded here.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.