Article 12 of the Kazakhstan PDPL establishes the data localization requirement for biometric personal data of Kazakhstan citizens and residents - a key sovereignty provision strengthened by the 2022 amendment. (1) Article 12 Localization Requirement: (a) Biometric data of Kazakhstan citizens AND residents (residing in Kazakhstan with valid residency) must be stored on servers located in Kazakhstan territory; (b) Data may also be processed (collected + used + analysed + accessed) outside Kazakhstan BUT primary storage location must be in Kazakhstan; (c) Foreign cloud providers must use Kazakhstan-based infrastructure or partner with Kazakhstan data centers; (d) Mirror requirement allowed but Kazakhstan copy must be primary; (e) Data sovereignty enforcement mechanism. (2) Scope of Localized Data: (a) Biometric data per Article 9 - fingerprint + facial recognition + iris + voice + behavioural biometrics; (b) Individual Identification Number (IIN) Kazakhstani; (c) IIN + biometric template combination; (d) Biometric authentication for e-Government + banking + telecom; (e) Smart City surveillance biometric data. (3) Foreign Cloud Provider Implications: (a) AWS + Azure + GCP + Oracle + IBM Cloud must establish Kazakhstan-region presence; (b) Kazakhstan-based data centers operating under foreign cloud brand (similar approach to China-region + Russia-region); (c) Sub-processor chain transparency; (d) Concentration risk monitoring; (e) Sovereignty + Lawful Access by foreign authorities concerns. (4) Kazakhstan Domestic Data Centers: (a) Kazakhtelecom + Beeline + Tele2 + Kcell domestic + foreign joint ventures; (b) Tier III + IV data centers in Almaty + Astana; (c) Government Cloud + Smart Government initiatives; (d) Kazakhstan Cloud + Open Government infrastructure; (e) Astana International Financial Centre data center; (f) State Service for Information Security supervision. (5) State Service for Information Security Oversight: (a) Sub-agency of Ministry of Digital Development; (b) Technical inspection + certification of data centers; (c) Compliance verification; (d) Audit + investigation; (e) Cooperation with KNB Committee for National Security. (6) Mandatory Storage Implementation Mechanisms: (a) Server location verification; (b) Data flow mapping + audit; (c) Cloud Provider contract Kazakhstan region; (d) Sub-processor chain visibility; (e) Periodic technical audit; (f) Public Notice of Localization compliance; (g) Authorized Body inspection cooperation. (7) Exceptions + Edge Cases: (a) Foreign nationals + non-residents in Kazakhstan - biometric data not subject to mandatory localization (foreign visitors); (b) Diplomatic mission processing exempt; (c) International law enforcement cooperation; (d) AIFC zone separate regulatory regime; (e) Emergency cross-border medical care. (8) Compliance Strategies: (a) Multi-cloud + multi-vendor in Kazakhstan region; (b) Domestic provider + foreign cloud partnership; (c) Edge computing for biometric processing; (d) Decentralised biometric template storage; (e) Tokenisation + irreversible templates; (f) Privacy-Enhancing Technologies (PETs); (g) Federated authentication. (9) Penalties for Localization Violations: (a) Article 79 CoAP administrative penalties; (b) Operational suspension for non-compliance; (c) Public naming; (d) Criminal liability for material failures + Article 147-148 Criminal Code; (e) Government contract debarment. (10) Foreign Comparative Data Localization Laws: (a) Russian Federation Personal Data Law 152-FZ + 526-FZ similar localization (2014); (b) China Cyber Security Law + Personal Information Protection Law (PIPL) localization; (c) Vietnam Cybersecurity Law 2018; (d) India Personal Data Protection Bill considerations; (e) Indonesia + Brazil sectoral localization. (11) AIFC Considerations: (a) AIFC Data Protection Regulations may have different localization rules; (b) AIFC + Main Kazakhstan boundary navigation; (c) AIFC fintech + asset management data flows; (d) AIFC + foreign cloud arrangements. Coordinates with Russian Federation Personal Data Law 152-FZ Article 18-1 localization + Decree 526-FZ + China Personal Information Protection Law + Vietnam Cybersecurity Law + Smart City Astana + Almaty + State Service for Information Security + Ministry of Digital Development + Kazakhtelecom + Beeline + Tele2 + Kcell + AIFC Data Protection Regulations + Code of Administrative Offences Article 79 + Criminal Code Articles 147-148 + Government Cloud + Open Government infrastructure + KNB Committee for National Security. Kazakhstan PDPL Biometric Localization + Article 12 applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.