Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
What it requires →
The Act has no dedicated special-category article and never defines biometric data as a term; it regulates biometric processing through three scattered clauses instead.
Art. 7(12) restricts collecting biometric data in public places to constitutional-order, public-order, rights, health, or morality purposes unless the subject consents; this clause was reworded by Law No. 96-VII (30 December 2021, in force 1 March 2022), so the currently quoted text has been in effect since that date, not since the Act's 2013 commencement.
Art. 11(3) defers biometric confidentiality entirely to unnamed other Kazakh legislation this research did not identify, and carries no amendment footnote of its own, so it has stood unchanged since the base Act's 25 November 2013 commencement. Art. 12(2)'s domestic-storage duty applies to biometric data as ordinary personal data; that duty was itself introduced by Law No. 419-V, in force 1 January 2016, with no biometric-specific carve-out or heightening found. No modality (face, voice, fingerprint) is named anywhere in the Act.
Breach notification
cite Law No. 94-V (21 May 2013), Art. 25(2)
stage IN FORCE in force since 2013-11-25
effective 2024-07-01
binds public and private bodies
source official statute text, Adilet Legal Information System, consolidated English translation
What it requires →
Art. 25(2)(8) requires the owner or operator, from the moment a personal data security breach is detected, to notify the competent authority, naming the contact details of the person responsible for organizing personal data processing where one exists.
No numeric deadline for that notice was found in the text read, and no separate duty to notify the affected data subject of the breach itself was found; a distinct Art. 24(1)(5) duty to notify the subject of a third-party transfer of their data should not be confused with a breach notice.
Article 25 has been amended three times since the base Act's 2013 commencement; this research could confirm a fixed commencement date only for the most recent amendment, Law No. 44-VIII, which states its own effective date directly in the base Act's footnote rather than by a from-publication formula.
Comprehensive regime
What it requires →
Law No. 94-V is Kazakhstan's single personal-data statute, reaching the owner, operator, and third party generally with no separate public and private carve-out found in the text read. Art. 8 requires the subject's written or otherwise confirmable consent for processing, subject to Art. 9's consent-free grounds (law enforcement, court proceedings, state statistics, and others), and confines processing to the stated purpose of collection.
The Law was adopted 21 May 2013, officially published 25 May 2013, and entered into force 25 November 2013 (Art. 31(1), six months after first official publication); Arts. 8 and 9 have each been amended multiple times since, most recently in 2025 and 2026, without displacing the base consent framework this instrument describes.
Cross border transfer
cite Law No. 94-V (21 May 2013), Arts. 12(2), 16
stage IN FORCE in force since 2013-11-25
effective 2016-01-01
binds public and private bodies
source official statute text, Adilet Legal Information System, consolidated English translation
What it requires →
Art. 12(2) requires a database of Kazakhstani personal data to be located inside Kazakhstan, unqualified by citizenship and, on the text read, not framed as forbidding an additional copy abroad; it answers where data is stored, not whether it may also leave the country. This storage duty was introduced by Law No. 419-V, in force 1 January 2016; Art. 12(2) did not exist in this form at the base Act's 2013 commencement.
Art. 16 answers the leaving-the-country question separately, and its general permitted-transfer grounds (paragraphs 1-4: an adequacy-equivalent destination, or one of four fallback grounds, subject consent, a ratified treaty, statutory necessity, or protection of constitutional rights where consent cannot be obtained) are original 2013 text, unamended since the base Act's commencement; a sector law may impose a harder bar than the general Law does.
Data subject rights
What it requires →
Art. 24 gives the subject the right to know about and obtain information on processing, demand correction or supplementation, demand blocking where a violation is alleged, demand destruction where a violation is confirmed, withdraw consent (including specifically for a cross-border or third-party transfer), consent or withdraw consent to public-source distribution, and seek protection of rights and compensation for moral and material damage.
Art. 24 was reworded by Law No. 96-VII (30 December 2021, in force 1 March 2022); the version quoted here is that current text, not the Act's original 2013 wording.
Separately, Art. 8(7) requires the owner or operator to stop processing personal data within fifteen working days of a subject withdrawing consent, or to give a reasoned refusal, a duty carried by Article 8 since before its most recent 2025 and 2026 amendments, though this research could not isolate which of Article 8's five stacked amending laws last touched paragraph 7 specifically.
A newer right was added by Law No. 231-VIII (17 November 2025, in force 17 January 2026) at new Art. 19-1: a subject may object to automated processing of their personal data, and the owner, operator, or third party must consider the objection and respond within three working days. This is the automated-decision-objection right this batch's Israel document flagged as unconfirmed either way; Kazakhstan now has one.
Enforcement supervision
What it requires →
Art. 79 of the Code of Administrative Offences, not the Personal Data Law itself, sets the fine schedule for a breach of Kazakhstan's personal-data legislation, starting at thirty monthly calculation indices for individuals for illegal collection or processing of personal data and scaling up by entity type. The Code was adopted 5 July 2014 and entered into force 1 January 2015 (Art. 920).
Article 79's fine schedule has since been amended four times; the most recent, Law No. 155-VIII, raised the amounts and took effect 12 March 2025. The Ministry of Artificial Intelligence and Digital Development (formed 28 September 2025) and its Committee for Information Security are the competent authority; no private right of action was found in the Personal Data Law, which instead gives the subject a general civil-damages right at Art. 24(1)(7).
A separate AI-specific fine article and a Criminal Code backstop were not read at primary source and are not recorded here.