Skip to the content
Global Data RulesData governance rules, country by country

Kazakhstan

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Kazakhstan — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

A copy must stayWork: HighEnforcement: Active

A copy of personal data must stay inside Kazakhstan. The law says personal data has to be kept in a database on Kazakh territory. You may still send data abroad. But the receiving country must protect it as well as Kazakh law does, or the person must agree. Some industries go further and allow no copy abroad at all.

Data governance in Kazakhstan

The eight things that decide how you handle data about people in Kazakhstan. Same eight on every country page, so you can compare.

Who has to follow these rules

Almost certainly yes, but the law is vague about it. Kazakhstan's personal data law does not clearly say that it applies to companies with no office in the country. It sets no size or revenue threshold either. What it does say is that whoever owns or runs the database must store it inside Kazakhstan. That pulls in foreign services that handle Kazakh customers. We found no requirement to appoint a local representative.

Not fully verified — see “What we're not sure about” below.

Where the data is allowed to live

Yes, a copy can leave, but the original has to stay. Kazakh law requires personal data to sit in a database on Kazakh soil. It separately allows you to send data abroad when the destination country protects it to the same standard, or when the person has clearly agreed. That is the general rule. Four areas are stricter. In those, the data, or the machine holding it, simply cannot leave.

What you have to do here:
Keep the data in the country

What to do: Plan for a database inside Kazakhstan: this data is not allowed to leave.

Sending data out of the country

Before data goes abroad you need one of two things. Proof that the destination country protects personal data to the Kazakh standard. Or the clear agreement of the person concerned. There is no government form to file and no permit to get. The catch is that Kazakhstan has not published a list of approved countries. So the judgement is yours to make and yours to defend.

Ways to send data out:
Official 'this country is safe' decision · Explicit consent · Legal claims · Government sign-off needed · Standard contract clauses

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

Not fully verified — see “What we're not sure about” below.

The regulator, and whether it actually acts

The Ministry of Artificial Intelligence and Digital Development is the authority. It works through its Information Security Committee. It is real, staffed and busy. It runs inspections, brings administrative cases and hands files to the police. The fines are small by international standards, in the low tens of thousands of dollars at most. Firms inside the Astana International Financial Centre answer instead to that centre's own Commissioner of Data Protection.

What it costs if you get it wrong:
Fixed maximum fine
Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

There is a floor and a ceiling, and they are set in different places. The clearest floor is in payments. A payment service provider must keep the information identifying who sent money and who received it for five years. The ceiling comes from the privacy law. Data may be kept only until the purpose it was collected for has been achieved. Since July 2026 people can also ask for their data to be deleted or made anonymous.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Let people delete their data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

There are at least two clocks, and neither is stated in hours. Under the national privacy law you must tell the authority as soon as you detect a breach of personal data security. You must also give it the contact details of the person in your organisation responsible for how data is used. Inside the Astana International Financial Centre you must tell the Commissioner as soon as practicable. You must also tell the affected people when the risk to them is high.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

Not fully verified — see “What we're not sure about” below.

What catches people out

Five things. One: your website is caught. A .KZ or .ҚАЗ address must be hosted on machines inside Kazakhstan, whatever the site is for. Two: telecoms operators must keep subscriber records locally, and pay for the interception equipment themselves. Three: gambling servers must sit at the operator's own premises in Kazakhstan. Four: the financial centre in Astana is a legal island with its own regulator and no local storage duty. Five: the official English translations of Kazakh laws lag behind the Russian originals. A fine you read as small may already have been multiplied.

What you have to do here:
Keep the data in the country
What it costs if you get it wrong:
Fixed maximum fine
Not fully verified — see “What we're not sure about” below.

What's changing next

The big change has already landed. Kazakhstan's Digital Code was signed on 9 January 2026 and took effect on 12 July 2026. The government says a law on artificial intelligence and a law on digital assets were adopted alongside it. The Digital Code gives people the right to have their data deleted, made anonymous, or held back from further use. It limits the use of face and fingerprint data. It lets people challenge decisions taken by automated systems. The next twelve months will be about the detailed rules underneath it.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Telecoms data must stay in the country

Official name: Закон Республики Казахстан «О связи» · Law No. 567 of 5 July 2004, Article 15(1), as amended 19 April 2023 · Act of parliament

In forceNo — it stays put

Telecoms operators must collect and store service information about subscribers and their communications. That storage must happen inside Kazakhstan. Operators also have to pay for the equipment that lets the security services run investigative and counter-intelligence measures on their networks.

In force since 5 July 2004Enforced from 19 April 2023

Enforced by Ministry of Artificial Intelligence and Digital Development

How this country controls where data goes: Not allowed

Online gaming

Online gaming data must stay in the country

Official name: Закон Республики Казахстан «Об игорном бизнесе» · Law No. 219 of 12 January 2007, Articles 12-1 and 12-2; single accounting system added by Law No. 116-VIII of 8 July 2024 · Act of parliament

In forceNo — it stays put

Gambling and betting operators must keep their servers at their own premises inside Kazakhstan. The servers of the national single accounting system introduced in July 2024 must also sit on Kazakh territory. Hosting abroad is not available to this industry at all.

In force since 12 January 2007Enforced from 8 July 2024

Enforced by Ministry of Artificial Intelligence and Digital Development

How this country controls where data goes: Not allowed

Finance

Rules for sending data abroad

Official name: AIFC Data Protection Regulations · AIFC Regulations No. 10 of 2017, enacted 20 December 2017, amendments incorporated to 1 April 2025 · Directly binding regulation

In forceYes, with paperwork

Firms registered in the Astana International Financial Centre follow this European-style rulebook instead of the national privacy law. It does not require data to stay in Kazakhstan. But it does control transfers out of the centre. The destination must protect data well enough, or you need a permit from the Commissioner of Data Protection. Standard contract wording may also be published. Fines currently have no stated ceiling.

In force since 1 January 2018Enforced from 1 April 2025

Enforced by Commissioner of Data Protection, Astana International Financial Centre

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Standard contract clauses, Explicit consent, Needed for a contract, To save someone’s life, Legal claims

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Personal data needs a copy kept in the country

Official name: Заң «Дербес деректер және оларды қорғау туралы» / Закон «О персональных данных и их защите» · Law of the Republic of Kazakhstan No. 94-V of 21 May 2013 · Act of parliament

In forceA copy must stay

This is Kazakhstan's general privacy law. It requires personal data to be stored in a database inside Kazakhstan. It separately allows you to send a copy abroad in only two cases. The destination country protects the data to the Kazakh standard. Or a narrow exception applies, such as the person's consent. Penalties are fixed cash amounts scaled by business size, not a share of turnover.

Enforced by Ministry of Artificial Intelligence and Digital Development

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Important public interest, To save someone’s life

Biometric data rules

Official name: Цифровой кодекс Республики Казахстан / Цифрлық кодекс · Code signed 9 January 2026; official number not verified · Act of parliament

In forceA copy must stay

An outline code for the digital world, signed in January 2026 and in force since 12 July 2026. It gives people new rights to have data deleted, made anonymous, or held back from further use. It limits identification by face or fingerprint. It creates a right to human review of decisions made by automated and artificial-intelligence systems. Its exact effect on the 2013 personal data law is not yet settled from an official text.

In force since 12 July 2026

Enforced by Ministry of Artificial Intelligence and Digital Development

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent

Not fully verified — see “What we're not sure about” below.

Data rules

Official name: Единые требования в области информационно-коммуникационных технологий и обеспечения информационной безопасности · Government Decree No. 832 of 20 December 2016, paragraph 62-1 · Directly binding regulation

In forceNo — it stays put

Any website using a .KZ or .ҚАЗ domain name must run on equipment physically located in Kazakhstan. This is a hosting rule rather than a data-protection rule, and it catches ordinary marketing sites as easily as it catches state systems.

Enforced by Ministry of Artificial Intelligence and Digital Development

How this country controls where data goes: Not allowed

Who you would hear from

  • Министерство искусственного интеллекта и цифрового развития Республики Казахстан

    National authority for personal data protection, information security, telecoms and digital policy. Acts through its Information Security Committee.

    Staffed and active. Headed by a deputy prime minister as of July 2026. Ran a joint unscheduled inspection with the National Security Committee and the State Technical Service. That followed the July 2025 leak said to affect 16 million people. It referred material for criminal proceedings. Official figures reported in August 2024 recorded 65 administrative personal-data cases in seven months. It replaced the Ministry of Digital Development, Innovations and Aerospace Industry. We did not verify the exact page address for the renamed ministry.

  • Data protection supervision for firms registered in the Astana International Financial Centre

    The office works. It issues transfer permits, keeps a register of participant notifications and reviews complaints. But no serving commissioner is named publicly, and we found no published decisions or enforcement notices. Treat it as working but quiet.

  • Қазақстан Республикасының Ұлттық Банкі

    Payments, payment systems and monetary policy; publishes information security acts for the financial sector

    An active regulator with a published set of information security legal acts. We could not read those acts, so this record does not state any banking rule about where data must sit.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The official consolidated text, number and commencement schedule of the Digital Code of the Republic of Kazakhstan

    State media report that the Code was signed on 9 January 2026 and came into force on 12 July 2026. The government's own site confirms the Code was adopted. We could not confirm the text itself on the official legal database. So its effect on the 2013 personal data law, including on where data must sit and on sending data abroad, is unconfirmed.

  • The current maximum fine for personal data violations

    The official English text of Article 79 of the Code on Administrative Offences still shows 10 to 200 monthly calculation index units. Press reporting of amendments effective 13 March 2025 gives a range of roughly 117,960 to 7,900,000 tenge. The English translations on the state database lag the Russian originals, and we could not confirm the Russian version. Price your risk from the higher figure.

  • Whether any specific storage-location rule applies to banks, insurers, securities firms or health providers

    We found no dedicated rule on a government website on 18 August 2026. We could not confirm the National Bank's information security legal acts. Finding no rule does not prove there is none. The general local-storage duty applies to these industries in any case.

  • Whether Kazakhstan publishes an official list of countries assessed as providing adequate protection for personal data

    The transfer article requires the destination state to protect data in line with Kazakh law. We found no published list of assessed countries on a government site. We rate the model as an approved-country list with no visible entries. A list may exist in a ministerial order we could not confirm.

  • The exact deadline for notifying the authority of a personal data breach

    The law requires you to notify from the moment you detect the breach. The official English text states no fixed number of hours. We could not confirm whether a separate order sets one. Plan for one working day.

  • Criminal liability for personal data offences

    Kazakhstan's Criminal Code is widely reported to punish breaches of privacy and personal data law. We could not confirm the relevant article, so this record states no criminal exposure. If this matters to you, take local advice.

  • The date on which the storage-in-Kazakhstan requirement was inserted into the 2013 personal data law

    The requirement is in the current official text. We could not confirm which law added it, or the date that law took effect. So the rule records only the parent law's adoption date.

  • Retention periods for telecoms service information, and general tax and accounting record periods

    The telecoms law leaves the period to the authorised body, and we could not find that order. We also could not confirm tax and accounting periods from a government source, so we do not state them. Check both before you set your deletion schedule.

  • Whether firms in the Astana International Financial Centre are fully exempt from the national local-storage duty

    The centre's rules set no storage-location duty and work as a separate legal system. We could not confirm from an official source that the national requirement does not apply inside the centre. If you are based there, take local advice before you assume the exemption.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.