DATA PROTECTION · KAZAKHSTAN
Data Protection Compliance in Kazakhstan
Bond Stone advises on data protection compliance programme implementation in Kazakhstan — DPO appointment, internal data protection policies, breach detection and notification to the Ministry of Digital Development, defence against unscheduled inspections, and responding to mandatory prescriptions under Law No. 94-V.
Primary authority: Law of the Republic of Kazakhstan “On Personal Data and Its Protection” No. 94-V dated 21 May 2013 (as amended by Law No. 231-VIII dated 17 November 2025). Verify at adilet.zan.kz
Key Framework
DPO appointment requirement
Organisations processing personal data in Kazakhstan are required to appoint a Data Protection Officer (DPO) responsible for overseeing compliance with the Law No. 94-V requirements. The DPO is responsible for: ensuring compliance with data processing requirements; handling data subject rights requests; managing consent mechanisms; overseeing breach detection and notification; and liaising with the Ministry of Digital Development. Bond Stone advises on DPO appointment, role definition, and the minimum competency requirements for the DPO function.
Breach notification — one working day
Effective 1 July 2024, organisations must notify the Ministry of Digital Development, Innovation, and Aerospace Industry of Kazakhstan within one working day of discovering a personal data security breach. The notification must contain: identification of the organisation; description of the breach; categories and approximate number of data subjects affected; likely consequences; and measures taken or proposed. Bond Stone advises on establishing breach detection processes and notification procedures to meet the one-working-day deadline.
Physical identity document prohibition
Law No. 44-VIII ZRK (effective 11 February 2024) prohibited collecting and processing physical copies of identity documents (passports, ID cards, driving licences). Organisations that previously collected physical document copies — including in HR onboarding, KYC processes, and customer registration — must update their data collection procedures. Bond Stone advises on transitioning document collection and verification processes to compliant alternatives.
Unscheduled inspections — defence
The Ministry of Digital Development is authorised to conduct unscheduled inspections of entities based on specific facts and circumstances — including data subject complaints, breach reports, and media reports. Inspections are registered with the General Prosecutor’s Office Legal Statistics Committee. Bond Stone advises entities subject to inspection on: preparing documentation demonstrating compliance; managing document production during inspection; responding to inspector queries; and challenging unlawful inspection actions.
Internal compliance programme
A complete data protection compliance programme under Law No. 94-V includes: (1) data mapping — identifying all personal data processing activities; (2) lawful basis analysis — consent, contract, legal obligation; (3) privacy notices — employee and customer data processing notices; (4) consent management — collection, recording, and withdrawal mechanisms; (5) data processing agreements with third-party processors; (6) data subject rights procedures; (7) breach response plan; and (8) DPO function and governance. Bond Stone advises on building and implementing compliance programmes for foreign-invested entities.
Experience
DPO Implementation — Manufacturing
Compliance · Kazakhstan · Manufacturing
Advising a foreign manufacturer’s Kazakhstan subsidiary on implementing the DPO function — defining the DPO role, selecting and appointing the DPO, drafting the DPO mandate, and establishing the reporting line to senior management.
Breach Response — E-commerce
Compliance · Kazakhstan · Technology
Advising an e-commerce platform on a personal data breach — initial breach assessment, Ministry of Digital Development notification within one working day, managing Ministry follow-up, notifying affected data subjects, and implementing remediation measures.
Identity Document Process — HR
Compliance · Kazakhstan · Corporate
Advising a company on updating its HR onboarding process following the prohibition on physical identity document copies — transitioning to digital verification systems, updating employment contracts and data collection forms, and retraining HR staff.
Compliance Audit — Energy Sector
Compliance · Kazakhstan · Energy
Conducting a data protection compliance audit for an energy sector entity — reviewing data processing activities against Law No. 94-V requirements, identifying gaps in localisation, consent, breach notification, and DPO function, and producing a remediation roadmap.
Data Processing Agreements
Compliance · Kazakhstan · Corporate
Drafting data processing agreements between a Kazakhstan entity and its foreign IT service providers — processor obligations, sub-processing restrictions, breach notification requirements, and termination provisions aligned with Law No. 94-V.
Privacy Policy — Market Entry
Compliance · Kazakhstan · Technology
Drafting a Kazakhstan-compliant privacy policy and cookie notice for a digital platform entering the Kazakhstan market — covering data categories, processing purposes, localisation, cross-border transfers, data subject rights, and DPO contact details.
Why Bond Stone
✦ Data protection integrated into every market entry and M&A mandate
✦ Ranked Legal 500 EMEA and IFLR1000 — Almaty and Astana offices
Primary authority: adilet.zan.kz
Discuss your data protection matter
Contact Bond Stone for a confidential discussion about Data Protection Compliance in Kazakhstan.
📧 info@bondstonelaw.com
📞 +7 (701) 729 76 72
Request a Confidential Consultation
← Cross-border Transfers
← Data Protection Hub
← Data Protection Hub