Country:哈萨克斯坦 · Data Privacy
Medium confidenceUpdated 2026-08-03Handbook

Kazakhstan · Data Privacy

Kazakhstan personal data protection is governed by Law No.94-V (latest amendment 7 January 2025, strengthening international alignment). Processing requires a legal basis (consent/contract/statutory obligation), follows purpose limitation, and must ensure data security. Cross-border transfers are only allowed where the receiving country provides adequate protection or safeguards are in place. From 22 December 2025, databases with 100,000+ records must mandatorily implement biometric multi-factor authentication. Regulation is by the Ministry of Digital Development and the Personal Data Protection Service; fines range from 100 to 10,000 MCI. Chinese enterprises must also comply with China's PIPL outbound requirements.

Key points

Procedure

  1. Inventory processing activities and build a ROPA.
  2. Determine legal basis (prefer consent or contract), publish Kazakh/Russian bilingual privacy policy.
  3. Assess receiving-country adequacy or sign SCCs/obtain certification before cross-border transfers.
  4. Deploy biometric MFA for databases with 100,000+ records (mandatory from 2025-12-22).
  5. Appoint a DPO (if triggered), build data subject request response and breach response mechanisms.
  6. Align with the Chinese parent's PIPL outbound compliance.

Hard requirements

Costs

Compliance consulting and DPO setupMFA and security technology investmentCross-border transfer assessment and contract costs⏱ ⏱ Timeline:Compliance system build 1-2 months; MFA deployment must have been completed by 2025-12-22 (deadline passed - existing systems must remediate)

⚠ Common risks

  • Databases ≥100,000 records without biometric MFA constitute a violation (effective end-2025)
  • Cross-border transfers back to China without a lawful mechanism violate rules - use SCC or certification
  • Fines and business suspension risk; sensitive data breaches carry criminal liability
  • Kazakhstan local law and China PIPL dual obligations intersect - need a unified plan
Handbook

📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)

Applies to:Chinese enterprises processing personal data of Kazakhstan residents, or transferring it back to China (governed by the Personal Data Law No.94-V, latest amendment 2025-01-07 in force).

Prerequisites

  • Processing activities and legal basis clarified (consent/contract/statutory obligation)
  • Database record scale assessed (≥100,000 records require biometric MFA)
  • DPO and security technology budget reserved
StepActionOwnerTimelineCostOfficial form / systemNotes & penalties
1Inventory processing activities and build ROPA
Map processing purposes, legal bases, data categories and recipients; build a processing record (ROPA)
Legal / IT2-3 weeksInternal costROPA, data inventoryUse data only for collection purposes
Penalty:No record-keeping aggravates penalties on inspection
2Determine legal basis and publish bilingual privacy policy
Publish privacy policy in Kazakh and Russian, stating consent (preferred) or other legal bases and notice items
Legal1-2 weeksInternal and translation costsKazakh/Russian bilingual privacy policyTransparent notice obligation
Penalty:Fines 100 to 10,000 MCI
3Cross-border transfer assessment and mechanism
Assess whether the receiving country has adequate protection; otherwise sign SCCs or use certification safeguards; align with PIPL outbound requirements
Legal2-4 weeksInternal and lawyer feesAdequacy assessment, SCCs, certificationTransfers back to China need a China-side mechanism
Penalty:Transfers without lawful mechanism may be penalized and suspended
4Databases with 100,000+ records deploy biometric MFA
Owners/operators of databases with 100,000+ records must mandatorily implement MFA including biometric verification (effective 2025-12-22)
IT securityDeadline passed - existing systems must remediateSecurity technology investmentMFA implementation planMandatory deadline cannot be deferred
Penalty:Non-deployment is a violation; penalties and liability
5Appoint a data protection officer (if triggered)
Operators doing large-scale processing or processing sensitive data (biometric/health/financial/criminal) must appoint an officer
ManagementContinuousDPO headcountDPO appointmentClear responsibilities
Penalty:Failure to appoint is a violation
6Data subject requests and breach response
Build response mechanisms for access, rectification, erasure, portability and objection requests; draft breach response plans
DPO/ITContinuousInternal costDSAR process, response planRespond promptly
Penalty:Refusing to respond may be penalized
7Align with China PIPL outbound requirements
Data processed in Kazakhstan and transferred back to China must additionally satisfy China PIPL outbound compliance (security assessment/standard contract/certification)
LegalContinuousInternal costPIPL outbound documentsUnified plan for dual obligations
Penalty:Dual violation risk

✅ Self-check list

⚠ Common pitfalls

Databases ≥100,000 without biometric MFA影响:Direct violation (effective end-2025)规避:Deploy MFA immediately
Cross-border transfers back to China without lawful mechanism影响:Dual penalties (Kazakhstan and China)规避:Sign SCCs/certification and complete PIPL outbound
Privacy policy only in Chinese影响:Insufficient notice规避:Kazakh/Russian bilingual notice
Sensitive data special obligations ignored影响:Missing DPO and security measures规避:Treat as sensitive data
Kazakhstan law and PIPL managed separately影响:Conflicting plans规避:Unified cross-border plan
No processing records影响:Aggravated on inspection规避:Maintain ROPA continuously

📅 Ongoing post-incorporation obligations

  • MFA continuously running for databases ≥100,000 records
  • DPO duties and reporting
  • Continuous data subject rights response
  • China PIPL outbound mechanism continuously valid
  • Annual review, training and record retention

🔗 Official portals

📎 Source:Kazakhstan Law on Personal Data Protection No.94-V (2013, latest amendment 2025-01-07); Ministry of Digital Development, Innovation and Aerospace Industry (incl. Personal Data Protection Service); Lexology data protection framework review; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?

CompliGo · Outbound Compliance Automation

You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.

CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.