Country:哈萨克斯坦 · Data Privacy
Kazakhstan · Data Privacy
Kazakhstan personal data protection is governed by Law No.94-V (latest amendment 7 January 2025, strengthening international alignment). Processing requires a legal basis (consent/contract/statutory obligation), follows purpose limitation, and must ensure data security. Cross-border transfers are only allowed where the receiving country provides adequate protection or safeguards are in place. From 22 December 2025, databases with 100,000+ records must mandatorily implement biometric multi-factor authentication. Regulation is by the Ministry of Digital Development and the Personal Data Protection Service; fines range from 100 to 10,000 MCI. Chinese enterprises must also comply with China's PIPL outbound requirements.
Key points
- Legal basis: Law No.94-V (2013, amended 2021, 2022, 2025); latest version effective 2025-01-07.
- Lawful processing: consent, contractual necessity or statutory obligation; data only used for purposes stated at collection.
- Cross-border transfers: only where the receiving country provides adequate protection or specific safeguards (e.g. standard contracts/certification).
- 2025-12-22 new rule: owners/operators of databases with no fewer than 100,000 records must implement MFA including biometric verification.
- Data subject rights: access, rectification, erasure, portability, objection, restriction of processing.
- DPO: operators doing large-scale processing or processing sensitive data (biometric/health/financial/criminal) must appoint a data protection officer.
- Penalties: administrative fines 100 to 10,000 MCI (about USD 300 to 30,000); serious cases may suspend processing and trigger criminal liability.
- Dual compliance: processing Kazakhstan resident data must simultaneously satisfy PIPL outbound requirements (security assessment/standard contract/certification) and local Kazakhstan law.
- China data outbound obligations (pkulaw verified 2026-07): transfers back to China must choose one of security assessment (CAC Order 11), standard contract (Order 13) or certification (CAC-SAMR Order 20, effective 2025-10-14); 2024-2025 regulatory scope eased - Provisions on Promoting and Regulating Cross-border Data Flows (Order 16) and Regulations on Network Data Security Administration (State Council Order 790) exempt certain cases.
Procedure
- Inventory processing activities and build a ROPA.
- Determine legal basis (prefer consent or contract), publish Kazakh/Russian bilingual privacy policy.
- Assess receiving-country adequacy or sign SCCs/obtain certification before cross-border transfers.
- Deploy biometric MFA for databases with 100,000+ records (mandatory from 2025-12-22).
- Appoint a DPO (if triggered), build data subject request response and breach response mechanisms.
- Align with the Chinese parent's PIPL outbound compliance.
Hard requirements
- Legal basis and transparent notice.
- Adequacy/safeguards for cross-border transfers.
- Biometric MFA for large databases (mandatory from end-2025).
- DPO and processing records.
Costs
Compliance consulting and DPO setupMFA and security technology investmentCross-border transfer assessment and contract costs⏱ ⏱ Timeline:Compliance system build 1-2 months; MFA deployment must have been completed by 2025-12-22 (deadline passed - existing systems must remediate)⚠ Common risks
- Databases ≥100,000 records without biometric MFA constitute a violation (effective end-2025)
- Cross-border transfers back to China without a lawful mechanism violate rules - use SCC or certification
- Fines and business suspension risk; sensitive data breaches carry criminal liability
- Kazakhstan local law and China PIPL dual obligations intersect - need a unified plan
Handbook
📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)
Applies to:Chinese enterprises processing personal data of Kazakhstan residents, or transferring it back to China (governed by the Personal Data Law No.94-V, latest amendment 2025-01-07 in force).
Prerequisites
- Processing activities and legal basis clarified (consent/contract/statutory obligation)
- Database record scale assessed (≥100,000 records require biometric MFA)
- DPO and security technology budget reserved
| Step | Action | Owner | Timeline | Cost | Official form / system | Notes & penalties |
|---|---|---|---|---|---|---|
| 1 | Inventory processing activities and build ROPA Map processing purposes, legal bases, data categories and recipients; build a processing record (ROPA) | Legal / IT | 2-3 weeks | Internal cost | ROPA, data inventory | Use data only for collection purposes Penalty:No record-keeping aggravates penalties on inspection |
| 2 | Determine legal basis and publish bilingual privacy policy Publish privacy policy in Kazakh and Russian, stating consent (preferred) or other legal bases and notice items | Legal | 1-2 weeks | Internal and translation costs | Kazakh/Russian bilingual privacy policy | Transparent notice obligation Penalty:Fines 100 to 10,000 MCI |
| 3 | Cross-border transfer assessment and mechanism Assess whether the receiving country has adequate protection; otherwise sign SCCs or use certification safeguards; align with PIPL outbound requirements | Legal | 2-4 weeks | Internal and lawyer fees | Adequacy assessment, SCCs, certification | Transfers back to China need a China-side mechanism Penalty:Transfers without lawful mechanism may be penalized and suspended |
| 4 | Databases with 100,000+ records deploy biometric MFA Owners/operators of databases with 100,000+ records must mandatorily implement MFA including biometric verification (effective 2025-12-22) | IT security | Deadline passed - existing systems must remediate | Security technology investment | MFA implementation plan | Mandatory deadline cannot be deferred Penalty:Non-deployment is a violation; penalties and liability |
| 5 | Appoint a data protection officer (if triggered) Operators doing large-scale processing or processing sensitive data (biometric/health/financial/criminal) must appoint an officer | Management | Continuous | DPO headcount | DPO appointment | Clear responsibilities Penalty:Failure to appoint is a violation |
| 6 | Data subject requests and breach response Build response mechanisms for access, rectification, erasure, portability and objection requests; draft breach response plans | DPO/IT | Continuous | Internal cost | DSAR process, response plan | Respond promptly Penalty:Refusing to respond may be penalized |
| 7 | Align with China PIPL outbound requirements Data processed in Kazakhstan and transferred back to China must additionally satisfy China PIPL outbound compliance (security assessment/standard contract/certification) | Legal | Continuous | Internal cost | PIPL outbound documents | Unified plan for dual obligations Penalty:Dual violation risk |
✅ Self-check list
⚠ Common pitfalls
Databases ≥100,000 without biometric MFA影响:Direct violation (effective end-2025)规避:Deploy MFA immediately
Cross-border transfers back to China without lawful mechanism影响:Dual penalties (Kazakhstan and China)规避:Sign SCCs/certification and complete PIPL outbound
Privacy policy only in Chinese影响:Insufficient notice规避:Kazakh/Russian bilingual notice
Sensitive data special obligations ignored影响:Missing DPO and security measures规避:Treat as sensitive data
Kazakhstan law and PIPL managed separately影响:Conflicting plans规避:Unified cross-border plan
No processing records影响:Aggravated on inspection规避:Maintain ROPA continuously
📅 Ongoing post-incorporation obligations
- MFA continuously running for databases ≥100,000 records
- DPO duties and reporting
- Continuous data subject rights response
- China PIPL outbound mechanism continuously valid
- Annual review, training and record retention
🔗 Official portals
📎 Source:Kazakhstan Law on Personal Data Protection No.94-V (2013, latest amendment 2025-01-07); Ministry of Digital Development, Innovation and Aerospace Industry (incl. Personal Data Protection Service); Lexology data protection framework review; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?
CompliGo · Outbound Compliance Automation
You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.
CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.