Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
KZ PDPL Authorized Body + Notification
Articles 27-29 of the Kazakhstan PDPL establish the Authorized Body framework and notification obligations. (1) Authorized Body Structure: (a) Ministry of Digital Development Innovation and Aerospace Industry (MDDIAI) primary regulator; (b) State Service for Information Security technical compliance + inspection; (c) State Technical Service technical implementation; (d) KNB Committee for National Security coordination for state secrets + national security; (e) Inter-Ministerial Coordination via Cabinet of Ministers. (2) Article 27 Notification of Processing: (a) Owner of personal data database notify Authorized Body before commencement of processing for certain categories; (b) Notification content - identity + purposes + categories + recipients + retention + security measures; (c) Exemptions - small-scale processing (under 1000 subjects + not sensitive) + personal household + journalism
- Authorized Body notification + Article 27 + records + per establishment + Authorized Body awareness
- Breach notification + 72-hour + Article 27-Bis + records + per breach + phased updates
- Subject notification + high-risk + records + per breach + clear Russian + Kazakh
- Authorized Body inspection + Article 28 + records + per inquiry + document production
- Documentation + ALL breaches + records + audit-ready + Authorized Body inspection
- Authorized Body notification absent or expired
- Breach notification beyond 72 hours without explanation
- Subject notification skipped (high-risk underestimated)
- Authorized Body inspection cooperation defensive
- Documentation only for notified breaches
KZ PDPL Biometric Localization
Article 12 of the Kazakhstan PDPL establishes the data localization requirement for biometric personal data of Kazakhstan citizens and residents - a key sovereignty provision strengthened by the 2022 amendment. (1) Article 12 Localization Requirement: (a) Biometric data of Kazakhstan citizens AND residents (residing in Kazakhstan with valid residency) must be stored on servers located in Kazakhstan territory; (b) Data may also be processed (collected + used + analysed + accessed) outside Kazakhstan BUT primary storage location must be in Kazakhstan; (c) Foreign cloud providers must use Kazakhstan-based infrastructure or partner with Kazakhstan data centers; (d) Mirror requirement allowed but Kazakhstan copy must be primary; (e) Data sovereignty enforcement mechanism. (2) Scope of Localized Data: (a) Biometric data per Article 9 - fingerprint + facial recognition + iris + voice + behaviou
- Biometric localization + Article 12 + server Kazakhstan + records + per data class
- Cloud provider Kazakhstan region + records + per CSP + per service + per region
- Sub-processor chain + visibility + records + per sub + concentration risk
- Technical inspection + State Service IS + records + per audit + per data center
- Foreign authority access + records + per request + Kazakhstan jurisdiction
- Biometric data on foreign servers (Article 12 violation)
- Cloud provider Kazakhstan region but data flows out
- Sub-processor chain opaque (foreign processing hidden)
- Technical inspection not facilitated
- Foreign authority access via cloud provider unconsidered
KZ PDPL Cross-Border Transfer
Article 16 of the Kazakhstan PDPL governs cross-border transfers of personal data outside Kazakhstan territory. (1) Article 16 General Framework: Cross-border transfer permitted only on specific grounds (a) Adequacy Determination by Authorized Body; (b) Subject consent (written for sensitive data + specific for transfer); (c) Performance of contract to which subject is party; (d) Vital interests of subject; (e) Public interest as defined by law; (f) Statutory authority; (g) Authorized Body approval for specific transfer mechanism. (2) Adequacy Determinations: (a) Authorized Body determines third country provides adequate level of protection; (b) Consideration includes (i) rule of law + respect for human rights; (ii) data protection legislation + enforcement; (iii) supervisory authority independence; (iv) international commitments; (v) Convention 108+ accession; (c) Reciprocity-based adeq
- Transfer map + per destination + records + per data flow + per category
- Lawful mechanism + Adequacy/SCC/consent + records + per transfer + per recipient
- TIA + per transfer + records + per destination + periodic review
- Article 12 biometric localization + records + per biometric + Kazakhstan-primary
- Authorized Body approval + records + per transfer mechanism + per material change
- Transfers without mapping (cloud sprawl)
- Lawful mechanism not chosen per transfer
- TIA absent (Schrems II analysis ignored)
- Article 12 biometric localization not enforced
- Authorized Body approval absent or expired
KZ PDPL Data Subject Rights
Articles 24-26 of the Kazakhstan PDPL establish comprehensive data subject rights + significantly aligned with Russian Federation Personal Data Law 152-FZ + emerging convergence with GDPR-style rights through recent amendments. (1) Article 24 Right to Information + Access: (a) Right to confirmation whether personal data being processed; (b) Right to copy of personal data; (c) Right to supplementary information (purposes + categories + recipients + retention + sources + automated decision-making); (d) Response within 30 calendar days from receipt of request; (e) Extension possible for complex requests with notification; (f) Free of charge for reasonable requests; (g) Refusal grounds limited - state secrets + criminal investigation + national security + third party rights + manifestly unfounded. (2) Article 25 Right of Correction: (a) Right to correct inaccurate data; (b) Right to complete
- DSAR portal + Article 24 + 30-day SLA + records + per request + Russian + Kazakh
- Rights implementation + Articles 25-26 + records + per type + Russian + Kazakh
- Identity verification + IIN + records + per DSAR + per access level
- Downstream propagation + recipients + records + per action + audit trail
- Responsible Person oversight + escalation + records + per request + decisions
- DSAR portal absent (email-only handling)
- 30-day SLA frequently missed
- Rights implementation incomplete (portability + restriction emerging unclear)
- Identity verification weak (impersonation risk)
- Downstream propagation absent (siloed responses)
KZ PDPL Lawful Basis + Consent
Articles 7-8 of the Kazakhstan PDPL establish the lawful basis framework for processing personal data + closely modelled on Russian Federation Personal Data Law 152-FZ with GDPR convergence. (1) Article 7 Lawful Basis: (a) Consent of subject of personal data; (b) Necessary for performance of contract to which subject is party + or for steps requested by subject prior to contract; (c) Necessary for compliance with legal obligation of owner/operator; (d) Necessary to protect vital interests of subject or another person; (e) Necessary for performance of state/municipal function in public interest; (f) Necessary for legitimate interests of owner/operator (subject to balancing); (g) Public sources of personal data (Article 10); (h) Statistical + scientific research with appropriate safeguards. (2) Article 8 Consent Requirements: (a) Freely given - not bundled with non-essential conditions; (b
- Lawful basis register + per processing + Article 7 + records + per activity
- Consent records + Article 8 + documented + withdrawal + records + per subject
- Privacy Notice + Article 13 + identity/purpose/rights + records + Russian + Kazakh
- Sensitive data consent + Article 9 + written + records + per category
- Biometric consent + Article 12 + written + localization + records + per subject
- Lawful basis selected after processing (consent bias)
- Consent records informal (no written form for sensitive)
- Privacy Notice in English only (Russian + Kazakh required)
- Sensitive data consent same as general consent
- Biometric data without written consent + localization
KZ PDPL Scope + Application
Kazakhstan Law on Personal Data and Their Protection (Заңы О персональных данных и их защите Zaňy O personaľnyh dannyh i ih zaščite) Law No. 94-V of 21 May 2013 + significant amendments 2017 + 2019 + 2022 + recent updates 2024 introducing GDPR-style elements. Foundational comprehensive data protection statute for Republic of Kazakhstan. (1) Statutory Framework: (a) Law No. 94-V adopted 21 May 2013 by Kazakhstan Parliament; (b) Effective date 1 December 2013; (c) Major amendments 2017 (mass media + sensitive data) + 2019 (data subject rights + breach notification) + 2022 (biometric data localization + cross-border restrictions); (d) Implementing Regulations + Ministry orders; (e) Code of Administrative Offences (CoAP) penalty provisions Article 79; (f) Constitutional Court of Kazakhstan oversight. (2) Articles 1-3 Definitions + Scope: (a) Personal Data (Personaľnye dannye персональные дан
- Scope assessment + per processing + records + per business unit + per system
- Territorial application + per Kazakhstan resident + records + per market
- Definitions mapping + Article 1 + records + per system + per data flow
- AIFC vs main law + records + per activity + per location
- Authorized Body + MDDIAI engagement + records + per inquiry + cooperation
- Scope misjudged (foreign operators with Kazakhstan data subjects)
- AIFC boundary unclear (cross-border AIFC issues)
- Definitions not mapped to Kazakhstan-specific concepts
- Owner vs Operator distinction not applied (GDPR controller/processor terminology used)
- Authorized Body engagement absent
KZ PDPL Sensitive Data
Article 9 of the Kazakhstan PDPL establishes enhanced protections for Sensitive Personal Data (Sensitivnye personaľnye dannye). (1) Article 9 Sensitive Personal Data Categories: (a) Race or ethnic origin; (b) Political opinion or party membership; (c) Religious beliefs; (d) Philosophical beliefs; (e) Trade union membership; (f) Physical or mental health condition (medical records + treatments + diagnoses + medications); (g) Genetic data (DNA + heritability + family genetic conditions); (h) Biometric data (fingerprint + facial recognition + iris + voice + behavioural - SUBJECT TO ARTICLE 12 LOCALIZATION); (i) Sexual life; (j) Criminal convictions + offences + arrests; (k) Other categories specified by Authorized Body regulation. (2) Sensitive Data Processing Conditions per Article 9 (PROHIBITED unless one applies): (a) Written Explicit Consent of subject (heightened consent standard); (b)
- Sensitive data inventory + Article 9 + 11+ categories + records + per system
- Lawful basis sensitive + Article 9 + records + per processing + per condition
- Written explicit consent + records + per subject + per category + audit + notarisation
- Children's capacity + Article 23 + records + per service + parental consent
- AIFC vs main law sensitive + records + per activity + per location
- Sensitive data uncategorised (treated as general)
- Lawful basis sensitive same as general (Article 9 not applied)
- Written explicit consent absent for sensitive (general electronic consent only)
- Children's age verification + parental consent absent
- AIFC sensitive data treated under main law rules
KZ PDPL Training + Penalties
Articles 31-32 of the Kazakhstan PDPL + Code of Administrative Offences Article 79 + Criminal Code Articles 147-148 establish the comprehensive penalty + enforcement framework. (1) Article 79 Code of Administrative Offences (CoAP) - Standard Administrative Penalties: (a) Individuals - KZT 500,000 to KZT 3,000,000 per violation; (b) Legal entities - KZT 1,500,000 to KZT 30,000,000 per violation; (c) Repeat violations - doubled; (d) Considerations - nature + gravity + duration + intentional/negligent + mitigation + responsibility + previous + cooperation + categories of data + harm. (2) Article 79 Severe Administrative Violations - Heightened: (a) Processing of sensitive personal data without legal basis; (b) Article 12 biometric data localization violation; (c) Violation of cross-border transfer rules; (d) Failure to notify breach (Article 27-Bis); (e) Failure to enable data subject right
- Penalty risk + per article + records + per processing + quantified KZT exposure
- Reasonable care defence + records + per control + audit trail + training records
- D and O liability + Criminal Code 147-148 + insurance + records + per officer + Board
- Training + annual mandatory + role-based + Russian + Kazakh + records + completion
- Board reporting + privacy risk statement + records + per quarter + Audit Committee
- Penalty risk not quantified (Board unaware of KZT 30M corporate exposure)
- Reasonable care defence undocumented
- D and O insurance excludes Article 147-148 criminal claims
- Training generic + completed once + not in Russian + Kazakh
- Board reporting infrequent or absent
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.