Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
KZ PDPL Data Subject Rights

Kazakhstan Law on Personal Data and Their Protection (No. 94-V) KZ-PDPL-Data-Subject-Rights-Articles24-26-Access-Correction-Erasure-Object-Portability-30-Days-Free: Kazakhstan PDPL Data Subject Rights + Articles 24-26 + Right to Information + Access + Correction + Erasure + Restriction + Object + Portability (Recent Amendments) + 30-Day Response Timeline + Free of Charge + Refusal Grounds Limited

Articles 24-26 of the Kazakhstan PDPL establish comprehensive data subject rights + significantly aligned with Russian Federation Personal Data Law 152-FZ + emerging convergence with GDPR-style rights through recent amendments. (1) Article 24 Right to Information + Access: (a) Right to confirmation whether personal data being processed; (b) Right to copy of personal data; (c) Right to supplementary information (purposes + categories + recipients + retention + sources + automated decision-making); (d) Response within 30 calendar days from receipt of request; (e) Extension possible for complex requests with notification; (f) Free of charge for reasonable requests; (g) Refusal grounds limited - state secrets + criminal investigation + national security + third party rights + manifestly unfounded. (2) Article 25 Right of Correction: (a) Right to correct inaccurate data; (b) Right to complete incomplete data; (c) 30-day response timeline; (d) Notification to recipients of correction; (e) Reasoned refusal + appealable. (3) Right of Erasure (Right to be Forgotten - emerging through recent amendments): (a) Right to erasure on grounds of (i) no longer necessary; (ii) consent withdrawn; (iii) objection upheld; (iv) unlawful processing; (v) statutory obligation; (b) 30-day response timeline; (c) Notification to recipients; (d) Restrictions per legal preservation + state interests + freedom of expression. (4) Right of Restriction (emerging): (a) Right to restrict processing where accuracy contested + processing unlawful but subject opposes erasure + controller no longer needs but subject requires for legal claims + objection pending review; (b) Restricted data can only be stored + other processing requires consent or legal claim. (5) Article 26 Right to Object (Right to Withdraw Consent): (a) Right to object to processing including profiling for legitimate interests + public interest task; (b) Owner/Operator MUST stop unless compelling legitimate grounds OR for establishment/defence of legal claims; (c) Absolute right to object to direct marketing including profiling; (d) Withdrawal of consent absolute for consent-based processing. (6) Right to Data Portability (emerging through recent amendments): (a) Right to receive personal data in structured + commonly used + machine-readable format; (b) Right to transmit to another controller; (c) Applies where processing based on consent or contract + carried out by automated means; (d) Does NOT apply to processing for public interest task; (e) Not to the right or freedoms of others. (7) Right Not to Be Subject to Automated Decision-Making: (a) Emerging right through recent amendments; (b) Right not to be subject to decision based solely on automated processing including profiling which produces legal effects or significantly affects; (c) Exceptions - explicit consent + contract performance + legal authorisation with safeguards; (d) Mandatory safeguards including human intervention + ability to express views + ability to contest decision. (8) Subject Rights Mechanism Requirements: (a) DSAR portal + identity verification proportionate to risk; (b) Workflow + ticketing + SLA tracking; (c) Audit trail of requests + decisions + actions; (d) Downstream propagation to recipients + sub-processors; (e) Responsible Person oversight + escalation; (f) Authorized Body appeal; (g) Court action for compensation per Civil Code. (9) Refusal Grounds + Limitations: (a) National security + KNB Committee operations; (b) Crime prevention + investigation + prosecution + Ministry of Internal Affairs; (c) Public economic + financial interests; (d) Judicial independence + proceedings; (e) Defence of legal claims; (f) Manifestly unfounded + excessive frequency; (g) State secrets + classified information. (10) Practical Implementation: (a) DSAR portal in Russian + Kazakh languages; (b) Identity verification - National IIN + biometric option (subject to localization) + Government ID; (c) 30-day response SLA tracking; (d) Responsible Person oversight + escalation; (e) Customer service surge handling; (f) Authorized Body reporting + transparency report; (g) e-Government Portal integration for individual data subject access. (11) Penalties for Rights Violations: (a) Article 79 CoAP administrative penalties for failure to enable rights; (b) Authorized Body escalation; (c) Civil compensation per Civil Code; (d) Reputational + customer trust damage. Coordinates with EU GDPR Articles 12-22 + Russian Personal Data Law 152-FZ Articles 14-20 + Convention 108+ Article 9 + Kazakhstan Constitution + Civil Code + e-Government Portal egov.kz + National IIN + Ministry of Digital Development + Code of Administrative Offences + Court of Civil Procedure + AIFC Court for AIFC subjects. Kazakhstan PDPL Data Subject Rights + Articles 24-26 apply.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.