Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
KZ PDPL Authorized Body + Notification

Kazakhstan Law on Personal Data and Their Protection (No. 94-V) KZ-PDPL-Authorized-Body-Notification-Article27-29-Ministry-Digital-Development-State-Service-Information-Security: Kazakhstan PDPL Authorized Body Notification + Articles 27-29 + Ministry of Digital Development + State Service for Information Security + Breach Notification 72-Hour + Operational Notification + AIFC Coordination + KNB Committee Coordination

Articles 27-29 of the Kazakhstan PDPL establish the Authorized Body framework and notification obligations. (1) Authorized Body Structure: (a) Ministry of Digital Development Innovation and Aerospace Industry (MDDIAI) primary regulator; (b) State Service for Information Security technical compliance + inspection; (c) State Technical Service technical implementation; (d) KNB Committee for National Security coordination for state secrets + national security; (e) Inter-Ministerial Coordination via Cabinet of Ministers. (2) Article 27 Notification of Processing: (a) Owner of personal data database notify Authorized Body before commencement of processing for certain categories; (b) Notification content - identity + purposes + categories + recipients + retention + security measures; (c) Exemptions - small-scale processing (under 1000 subjects + not sensitive) + personal household + journalism public interest; (d) Public register of notified owners + operators (selectively published). (3) Article 27-Bis Breach Notification (added by recent amendments): (a) Notification required to Authorized Body without undue delay; (b) Where feasible within 72 HOURS of becoming aware; (c) If delayed beyond 72 hours - reasons must accompany notification; (d) Phased notification allowed if full information not available; (e) Ongoing updates as investigation progresses. (4) Notification to Affected Subjects per Article 27-Bis: (a) Where breach likely to result in HIGH RISK to subject rights and freedoms; (b) Without undue delay; (c) In clear and plain Russian + Kazakh language; (d) Information - nature of breach + Responsible Person contact + consequences + measures; (e) Exemptions - encryption rendering data unintelligible + subsequent risk mitigation + disproportionate effort + public communication instead; (f) Authorized Body may require notification if not done. (5) Article 28 Powers of Authorized Body: (a) Investigate complaints + on own motion; (b) Access controllers/processors information + premises; (c) Require production of documents + records; (d) Interview personnel; (e) On-site inspection + technical audit; (f) Forensic examination; (g) Witness statements under oath; (h) Subpoena power; (i) Cooperation requirement of controllers + processors. (6) Article 29 Administrative Penalties: (a) Coordination with Code of Administrative Offences (CoAP) Article 79; (b) Issuance of Compliance Notice; (c) Cessation Orders for ongoing violations; (d) Penalty Notice imposing administrative fine; (e) Public Naming for serious violations; (f) Operational suspension for material non-compliance; (g) License Revocation for licensed processing activities. (7) Documentation Requirement: (a) ALL breaches documented regardless of notification threshold; (b) Facts + effects + remedial action; (c) Enables Authorized Body compliance verification; (d) Supports trend analysis + organisational learning. (8) Cross-Border Breach Notification: (a) If affected data subjects in multiple jurisdictions - notify each Supervisory Authority; (b) Lead Supervisory Authority concept where applicable (EAEU coordination); (c) Authorized Body liaison with foreign DPAs; (d) CIS + EAEU coordination. (9) Sectoral Notification: (a) Banking + National Bank of Kazakhstan; (b) Telecom + Telecommunications Regulator; (c) Health + Ministry of Health; (d) Securities + Securities Commission; (e) Cybersecurity + KNB Committee; (f) AML + State Tax Service + Anti-Money Laundering. (10) AIFC Coordination: (a) AIFC Court jurisdiction for AIFC-based entities; (b) AIFC Data Protection Regulations separate from main law; (c) Inter-AIFC + main Kazakhstan boundary navigation; (d) AIFC fintech sandbox processing. (11) Penalties for Notification Failures: (a) Article 79 CoAP administrative penalties; (b) Operational suspension; (c) Public naming; (d) Criminal liability for material failures + Articles 147-148 Criminal Code; (e) Government contract debarment. Coordinates with Russian Personal Data Law 152-FZ + Roskomnadzor + EU GDPR Articles 33 + 34 + 51-59 + Convention 108+ + AIFC Data Protection Regulations + AIFC Court + KNB Committee for National Security + Ministry of Internal Affairs + Ministry of Justice + National Bank of Kazakhstan + Telecommunications Regulator + Ministry of Health + EAEU + CIS coordination + State Service for Information Security + State Technical Service + Code of Administrative Offences Article 79 + Criminal Code Articles 147-148. Kazakhstan PDPL Authorized Body + Articles 27-29 apply.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.