Data Protection in Kazakhstan
PRACTICE AREA · KAZAKHSTAN
Data Protection in Kazakhstan
Bond Stone advises international investors and multinational corporations on data protection compliance in Kazakhstan — the Law on Personal Data and Its Protection No. 94-V, data localisation requirements, cross-border transfer restrictions, breach notification obligations to the Ministry of Digital Development, DPO appointment requirements, and sector-specific data protection obligations across financial services, telecommunications, and healthcare. Ranked Legal 500 EMEA and IFLR1000.
Kazakhstan’s data protection framework has evolved significantly — the Law on Personal Data No. 94-V has been amended multiple times since 2013, most recently by Law No. 231-VIII dated 17 November 2025. Every foreign company operating in Kazakhstan, processing employee data, or collecting customer data is subject to the Law. Non-compliance exposes businesses to unscheduled regulatory inspections, mandatory prescriptions, and reputational risk.
Primary authority: Law of the Republic of Kazakhstan “On Personal Data and Its Protection” No. 94-V dated 21 May 2013 (as amended, most recently by Law No. 231-VIII dated 17 November 2025). Verify current text at adilet.zan.kz
Data Protection Services
Compliance Audit & Gap Analysis
Reviewing a foreign-invested entity’s data processing operations against the current requirements of Law No. 94-V — identifying gaps in localisation compliance, consent mechanisms, data subject rights procedures, breach notification protocols, and DPO appointment. Producing a prioritised remediation roadmap aligned with the Ministry of Digital Development’s inspection focus areas.
Data Localisation Advisory
Advising on the obligation to store personal data of Kazakhstani residents on servers located within Kazakhstan — the localisation requirement has been in force since 1 January 2016. Advising on structuring data infrastructure, identifying what categories of data are subject to localisation, and managing cross-border data flows within the localisation framework.
Cross-border Transfer Compliance
Advising on the conditions under which personal data may be transferred outside Kazakhstan — transfer to adequate jurisdictions, obtaining data subject consent, and contractual safeguards for transfers to non-adequate jurisdictions. Advising multinational groups on structuring intercompany data sharing arrangements compliant with Kazakhstan’s transfer restrictions.
Breach Notification & Response
Advising on the obligation — effective 1 July 2024 — to notify the Ministry of Digital Development within one working day of discovering a personal data security breach. Advising on breach response procedures, notification content, and managing regulatory engagement following a breach. The Ministry is authorised to conduct unscheduled inspections following breach notifications.
DPO Appointment & Policies
Advising on the requirement to appoint a Data Protection Officer (DPO) responsible for overseeing data protection compliance. Drafting internal data protection policies, consent forms, data processing agreements with third parties, and employee data processing notices aligned with the Law No. 94-V requirements.
Regulatory Inspection Support
Advising entities subject to unscheduled inspections by the Ministry of Digital Development — preparing for inspection, managing document requests, responding to mandatory prescriptions, and challenging unlawful inspection actions before the courts or the General Prosecutor’s Office.
Kazakhstan Data Protection Framework
Law on Personal Data No. 94-V — scope
Law No. 94-V applies to all organisations processing personal data in Kazakhstan — including public and private entities, and foreign businesses processing data of Kazakhstani residents where they operate within Kazakhstan or use local data processing infrastructure. The Law covers collection, processing, storage, use, transfer, and destruction of personal data. It does not apply to personal data processing for purely personal or family use, archival purposes, or state secrets operations.
Data localisation — from 1 January 2016
Personal data of Kazakhstani residents must be stored in databases located within Kazakhstan. This localisation requirement has been in force since 1 January 2016. Foreign companies operating in Kazakhstan must ensure that personal data collected from Kazakhstani residents is stored on Kazakhstan-located servers — whether through local infrastructure, a local cloud provider, or a qualifying data centre in Kazakhstan.
Key 2024 amendments — breach notification and identity documents
Law No. 44-VIII ZRK dated 11 December 2023 (in effect from 11 February 2024) introduced: (1) the concept of “personal data security breach”; (2) mandatory notification of the Ministry of Digital Development within one working day of discovering a breach (effective 1 July 2024); (3) prohibition on collecting and processing physical copies of identity documents; and (4) authorisation for the Ministry to conduct unscheduled compliance inspections. These amendments materially increased the enforcement risk for non-compliant businesses.
2025 amendments — Law No. 231-VIII dated 17 November 2025
The most recent amendment — Law No. 231-VIII dated 17 November 2025, entering into force sixty calendar days after first official publication — introduced further updates to the Personal Data Law. Bond Stone advises on the practical implications of these latest amendments for foreign-invested entities operating in Kazakhstan. Verify current provisions at adilet.zan.kz.
Data subject rights
Data subjects in Kazakhstan have the right to: access their personal data; request correction of inaccurate data; request deletion of their data under certain conditions; withdraw consent to data processing at any time; and request blocking of restricted personal data. Organisations must establish internal procedures for handling data subject requests within the timeframes prescribed by the Law.
Detailed Guides
Experience
Bond Stone advises on data protection as part of market entry, M&A due diligence, and regulatory compliance mandates in Kazakhstan. Client confidentiality is maintained across all matters.
Localisation Audit — Manufacturing
Data Protection · Kazakhstan · Manufacturing
Advising a foreign manufacturer establishing a Kazakhstan subsidiary on data localisation — identifying employee and customer data subject to Law No. 94-V localisation, structuring Kazakhstan-based HR data infrastructure, and drafting employee data processing notices.
M&A Due Diligence — Data Risk
Data Protection · Kazakhstan · M&A
Including data protection compliance as a component of legal due diligence on a Kazakhstan target — reviewing the target’s localisation compliance, consent framework, data processing agreements, breach history, and Ministry of Digital Development correspondence.
Breach Response — Financial Services
Data Protection · Kazakhstan · Financial Services
Advising a financial services entity on breach notification — preparing the one-working-day notification to the Ministry of Digital Development, managing the Ministry’s follow-up, and implementing remediation measures to reduce inspection risk.
Cross-border Transfer — Intercompany
Data Protection · Kazakhstan · Corporate
Advising a multinational group on structuring intercompany data sharing arrangements for a Kazakhstan subsidiary — identifying transfer restrictions, obtaining required data subject consents, and drafting intragroup data transfer agreements.
Market Entry — Data Compliance
Data Protection · Kazakhstan · Market Entry
Advising a European company entering the Kazakhstan market on data protection requirements as part of the market entry legal package — localisation infrastructure, DPO appointment, privacy policy drafting, and employee data processing framework.
Inspection Defence
Data Protection · Kazakhstan · Regulatory
Advising an entity subject to an unscheduled Ministry of Digital Development inspection — reviewing the inspection grounds, managing document production, responding to the inspector’s queries, and challenging a mandatory prescription before the courts.
Why Bond Stone
✦ Data protection advisory integrated into every market entry and M&A mandate
✦ Direct engagement with the Ministry of Digital Development on breach notification and inspections
✦ Ranked Legal 500 EMEA and IFLR1000 — Almaty and Astana offices
Primary authority: adilet.zan.kz
Discuss your data protection matter
Contact Bond Stone for a confidential discussion about data protection compliance in Kazakhstan.
📧 info@bondstonelaw.com
📞 +7 (701) 729 76 72
Request a Confidential Consultation
Data Localisation →
Cross-border Transfers →
Compliance & Breach Response →