Skip to content

Evidence request lists

Kazakhstan Law on Personal Data and Their Protection (No. 94-V)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

KZ PDPL Authorized Body + Notification

KZ-PDPL-Authorized-Body-Notification-Article27-29-Ministry-Digital-Development-State-Service-Information-Security
Kazakhstan PDPL Authorized Body Notification + Articles 27-29 + Ministry of Digital Development + State Service for Information Security + Breach Notification 72-Hour + Operational Notification + AIFC Coordination + KNB Committee Coordination

Articles 27-29 of the Kazakhstan PDPL establish the Authorized Body framework and notification obligations. (1) Authorized Body Structure: (a) Ministry of Digital Development Innovation and Aerospace Industry (MDDIAI) primary regulator; (b) State Service for Information Security technical compliance + inspection; (c) State Technical Service technical implementation; (d) KNB Committee for National Security coordination for state secrets + national security; (e) Inter-Ministerial Coordination via Cabinet of Ministers. (2) Article 27 Notification of Processing: (a) Owner of personal data database notify Authorized Body before commencement of processing for certain categories; (b) Notification content - identity + purposes + categories + recipients + retention + security measures; (c) Exemptions - small-scale processing (under 1000 subjects + not sensitive) + personal household + journalism

Artefacts an auditor will ask for
  • Authorized Body notification + Article 27 + records + per establishment + Authorized Body awareness
  • Breach notification + 72-hour + Article 27-Bis + records + per breach + phased updates
  • Subject notification + high-risk + records + per breach + clear Russian + Kazakh
  • Authorized Body inspection + Article 28 + records + per inquiry + document production
  • Documentation + ALL breaches + records + audit-ready + Authorized Body inspection
Where this commonly fails
  • Authorized Body notification absent or expired
  • Breach notification beyond 72 hours without explanation
  • Subject notification skipped (high-risk underestimated)
  • Authorized Body inspection cooperation defensive
  • Documentation only for notified breaches

KZ PDPL Biometric Localization

KZ-PDPL-Biometric-Data-Localization-Article12-Server-Kazakhstan-On-Soil-Data-Storage-Citizens-Residents
Kazakhstan PDPL Biometric Data Localization + Article 12 + Mandatory Server Storage in Kazakhstan + 2022 Amendment + Citizens + Residents + Foreign Cloud Provider Restrictions + Data Sovereignty + State Service for Information Security Oversight

Article 12 of the Kazakhstan PDPL establishes the data localization requirement for biometric personal data of Kazakhstan citizens and residents - a key sovereignty provision strengthened by the 2022 amendment. (1) Article 12 Localization Requirement: (a) Biometric data of Kazakhstan citizens AND residents (residing in Kazakhstan with valid residency) must be stored on servers located in Kazakhstan territory; (b) Data may also be processed (collected + used + analysed + accessed) outside Kazakhstan BUT primary storage location must be in Kazakhstan; (c) Foreign cloud providers must use Kazakhstan-based infrastructure or partner with Kazakhstan data centers; (d) Mirror requirement allowed but Kazakhstan copy must be primary; (e) Data sovereignty enforcement mechanism. (2) Scope of Localized Data: (a) Biometric data per Article 9 - fingerprint + facial recognition + iris + voice + behaviou

Artefacts an auditor will ask for
  • Biometric localization + Article 12 + server Kazakhstan + records + per data class
  • Cloud provider Kazakhstan region + records + per CSP + per service + per region
  • Sub-processor chain + visibility + records + per sub + concentration risk
  • Technical inspection + State Service IS + records + per audit + per data center
  • Foreign authority access + records + per request + Kazakhstan jurisdiction
Where this commonly fails
  • Biometric data on foreign servers (Article 12 violation)
  • Cloud provider Kazakhstan region but data flows out
  • Sub-processor chain opaque (foreign processing hidden)
  • Technical inspection not facilitated
  • Foreign authority access via cloud provider unconsidered

KZ PDPL Cross-Border Transfer

KZ-PDPL-Cross-Border-Transfer-Article16-Adequacy-Consent-Public-Interest-Contract-Authorized-Body-Approval
Kazakhstan PDPL Cross-Border Transfer + Article 16 + Adequacy + Consent + Public Interest + Contract + Authorized Body Approval + EAEU/CIS Coordination + Russia Coordination + Sovereign Risk Considerations

Article 16 of the Kazakhstan PDPL governs cross-border transfers of personal data outside Kazakhstan territory. (1) Article 16 General Framework: Cross-border transfer permitted only on specific grounds (a) Adequacy Determination by Authorized Body; (b) Subject consent (written for sensitive data + specific for transfer); (c) Performance of contract to which subject is party; (d) Vital interests of subject; (e) Public interest as defined by law; (f) Statutory authority; (g) Authorized Body approval for specific transfer mechanism. (2) Adequacy Determinations: (a) Authorized Body determines third country provides adequate level of protection; (b) Consideration includes (i) rule of law + respect for human rights; (ii) data protection legislation + enforcement; (iii) supervisory authority independence; (iv) international commitments; (v) Convention 108+ accession; (c) Reciprocity-based adeq

Artefacts an auditor will ask for
  • Transfer map + per destination + records + per data flow + per category
  • Lawful mechanism + Adequacy/SCC/consent + records + per transfer + per recipient
  • TIA + per transfer + records + per destination + periodic review
  • Article 12 biometric localization + records + per biometric + Kazakhstan-primary
  • Authorized Body approval + records + per transfer mechanism + per material change
Where this commonly fails
  • Transfers without mapping (cloud sprawl)
  • Lawful mechanism not chosen per transfer
  • TIA absent (Schrems II analysis ignored)
  • Article 12 biometric localization not enforced
  • Authorized Body approval absent or expired

KZ PDPL Data Subject Rights

KZ-PDPL-Data-Subject-Rights-Articles24-26-Access-Correction-Erasure-Object-Portability-30-Days-Free
Kazakhstan PDPL Data Subject Rights + Articles 24-26 + Right to Information + Access + Correction + Erasure + Restriction + Object + Portability (Recent Amendments) + 30-Day Response Timeline + Free of Charge + Refusal Grounds Limited

Articles 24-26 of the Kazakhstan PDPL establish comprehensive data subject rights + significantly aligned with Russian Federation Personal Data Law 152-FZ + emerging convergence with GDPR-style rights through recent amendments. (1) Article 24 Right to Information + Access: (a) Right to confirmation whether personal data being processed; (b) Right to copy of personal data; (c) Right to supplementary information (purposes + categories + recipients + retention + sources + automated decision-making); (d) Response within 30 calendar days from receipt of request; (e) Extension possible for complex requests with notification; (f) Free of charge for reasonable requests; (g) Refusal grounds limited - state secrets + criminal investigation + national security + third party rights + manifestly unfounded. (2) Article 25 Right of Correction: (a) Right to correct inaccurate data; (b) Right to complete

Artefacts an auditor will ask for
  • DSAR portal + Article 24 + 30-day SLA + records + per request + Russian + Kazakh
  • Rights implementation + Articles 25-26 + records + per type + Russian + Kazakh
  • Identity verification + IIN + records + per DSAR + per access level
  • Downstream propagation + recipients + records + per action + audit trail
  • Responsible Person oversight + escalation + records + per request + decisions
Where this commonly fails
  • DSAR portal absent (email-only handling)
  • 30-day SLA frequently missed
  • Rights implementation incomplete (portability + restriction emerging unclear)
  • Identity verification weak (impersonation risk)
  • Downstream propagation absent (siloed responses)

KZ PDPL Lawful Basis + Consent

KZ-PDPL-Standard1-Lawful-Basis-Consent-Article7-8-Contract-Legal-Vital-Public-Interest-Statutory-Authority
Kazakhstan PDPL Lawful Basis + Consent + Articles 7-8 + Contract Performance + Legal Obligation + Vital Interests + Public Interest + Statutory Authority + Documented Consent + Form Requirements

Articles 7-8 of the Kazakhstan PDPL establish the lawful basis framework for processing personal data + closely modelled on Russian Federation Personal Data Law 152-FZ with GDPR convergence. (1) Article 7 Lawful Basis: (a) Consent of subject of personal data; (b) Necessary for performance of contract to which subject is party + or for steps requested by subject prior to contract; (c) Necessary for compliance with legal obligation of owner/operator; (d) Necessary to protect vital interests of subject or another person; (e) Necessary for performance of state/municipal function in public interest; (f) Necessary for legitimate interests of owner/operator (subject to balancing); (g) Public sources of personal data (Article 10); (h) Statistical + scientific research with appropriate safeguards. (2) Article 8 Consent Requirements: (a) Freely given - not bundled with non-essential conditions; (b

Artefacts an auditor will ask for
  • Lawful basis register + per processing + Article 7 + records + per activity
  • Consent records + Article 8 + documented + withdrawal + records + per subject
  • Privacy Notice + Article 13 + identity/purpose/rights + records + Russian + Kazakh
  • Sensitive data consent + Article 9 + written + records + per category
  • Biometric consent + Article 12 + written + localization + records + per subject
Where this commonly fails
  • Lawful basis selected after processing (consent bias)
  • Consent records informal (no written form for sensitive)
  • Privacy Notice in English only (Russian + Kazakh required)
  • Sensitive data consent same as general consent
  • Biometric data without written consent + localization

KZ PDPL Scope + Application

KZ-PDPL-Scope-Application-Article1-3-Law-94-V-21-May-2013-Republic-Kazakhstan-Ministry-Digital-Development-State-Service-Information-Security
Kazakhstan PDPL Scope + Application + Articles 1-3 + Law No. 94-V of 21 May 2013 + 2017 + 2019 + 2022 Amendments + Republic of Kazakhstan + Ministry of Digital Development Innovation and Aerospace Industry + State Service for Information Security + AIFC Astana International Financial Centre Exemption

Kazakhstan Law on Personal Data and Their Protection (Заңы О персональных данных и их защите Zaňy O personaľnyh dannyh i ih zaščite) Law No. 94-V of 21 May 2013 + significant amendments 2017 + 2019 + 2022 + recent updates 2024 introducing GDPR-style elements. Foundational comprehensive data protection statute for Republic of Kazakhstan. (1) Statutory Framework: (a) Law No. 94-V adopted 21 May 2013 by Kazakhstan Parliament; (b) Effective date 1 December 2013; (c) Major amendments 2017 (mass media + sensitive data) + 2019 (data subject rights + breach notification) + 2022 (biometric data localization + cross-border restrictions); (d) Implementing Regulations + Ministry orders; (e) Code of Administrative Offences (CoAP) penalty provisions Article 79; (f) Constitutional Court of Kazakhstan oversight. (2) Articles 1-3 Definitions + Scope: (a) Personal Data (Personaľnye dannye персональные дан

Artefacts an auditor will ask for
  • Scope assessment + per processing + records + per business unit + per system
  • Territorial application + per Kazakhstan resident + records + per market
  • Definitions mapping + Article 1 + records + per system + per data flow
  • AIFC vs main law + records + per activity + per location
  • Authorized Body + MDDIAI engagement + records + per inquiry + cooperation
Where this commonly fails
  • Scope misjudged (foreign operators with Kazakhstan data subjects)
  • AIFC boundary unclear (cross-border AIFC issues)
  • Definitions not mapped to Kazakhstan-specific concepts
  • Owner vs Operator distinction not applied (GDPR controller/processor terminology used)
  • Authorized Body engagement absent

KZ PDPL Sensitive Data

KZ-PDPL-Sensitive-Personal-Data-Article9-Special-Categories-Race-Religious-Political-Health-Genetic-Biometric
Kazakhstan PDPL Sensitive Personal Data + Article 9 + Special Categories + Race + Ethnic Origin + Religious + Political + Trade Union + Sexual Life + Criminal + Health + Genetic + Biometric + Enhanced Written Consent + Special Safeguards

Article 9 of the Kazakhstan PDPL establishes enhanced protections for Sensitive Personal Data (Sensitivnye personaľnye dannye). (1) Article 9 Sensitive Personal Data Categories: (a) Race or ethnic origin; (b) Political opinion or party membership; (c) Religious beliefs; (d) Philosophical beliefs; (e) Trade union membership; (f) Physical or mental health condition (medical records + treatments + diagnoses + medications); (g) Genetic data (DNA + heritability + family genetic conditions); (h) Biometric data (fingerprint + facial recognition + iris + voice + behavioural - SUBJECT TO ARTICLE 12 LOCALIZATION); (i) Sexual life; (j) Criminal convictions + offences + arrests; (k) Other categories specified by Authorized Body regulation. (2) Sensitive Data Processing Conditions per Article 9 (PROHIBITED unless one applies): (a) Written Explicit Consent of subject (heightened consent standard); (b)

Artefacts an auditor will ask for
  • Sensitive data inventory + Article 9 + 11+ categories + records + per system
  • Lawful basis sensitive + Article 9 + records + per processing + per condition
  • Written explicit consent + records + per subject + per category + audit + notarisation
  • Children's capacity + Article 23 + records + per service + parental consent
  • AIFC vs main law sensitive + records + per activity + per location
Where this commonly fails
  • Sensitive data uncategorised (treated as general)
  • Lawful basis sensitive same as general (Article 9 not applied)
  • Written explicit consent absent for sensitive (general electronic consent only)
  • Children's age verification + parental consent absent
  • AIFC sensitive data treated under main law rules

KZ PDPL Training + Penalties

KZ-PDPL-Training-Awareness-Penalties-Articles31-32-Administrative-Article79-Civil-Compensation-Criminal-CoAP
Kazakhstan PDPL Training + Awareness + Penalties + Articles 31-32 + Code of Administrative Offences (CoAP) Article 79 + Administrative KZT 500K-30M + Civil Compensation + Criminal Code Articles 147-148 + Up to 3 Years Imprisonment + KZT 1.5M Fine

Articles 31-32 of the Kazakhstan PDPL + Code of Administrative Offences Article 79 + Criminal Code Articles 147-148 establish the comprehensive penalty + enforcement framework. (1) Article 79 Code of Administrative Offences (CoAP) - Standard Administrative Penalties: (a) Individuals - KZT 500,000 to KZT 3,000,000 per violation; (b) Legal entities - KZT 1,500,000 to KZT 30,000,000 per violation; (c) Repeat violations - doubled; (d) Considerations - nature + gravity + duration + intentional/negligent + mitigation + responsibility + previous + cooperation + categories of data + harm. (2) Article 79 Severe Administrative Violations - Heightened: (a) Processing of sensitive personal data without legal basis; (b) Article 12 biometric data localization violation; (c) Violation of cross-border transfer rules; (d) Failure to notify breach (Article 27-Bis); (e) Failure to enable data subject right

Artefacts an auditor will ask for
  • Penalty risk + per article + records + per processing + quantified KZT exposure
  • Reasonable care defence + records + per control + audit trail + training records
  • D and O liability + Criminal Code 147-148 + insurance + records + per officer + Board
  • Training + annual mandatory + role-based + Russian + Kazakh + records + completion
  • Board reporting + privacy risk statement + records + per quarter + Audit Committee
Where this commonly fails
  • Penalty risk not quantified (Board unaware of KZT 30M corporate exposure)
  • Reasonable care defence undocumented
  • D and O insurance excludes Article 147-148 criminal claims
  • Training generic + completed once + not in Russian + Kazakh
  • Board reporting infrequent or absent
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.