Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
Kazakhstan's Law on Personal Data and Their Protection (No. 94-V, 2013, significantly amended 2023) establishes the data protection framework. The Committee on Information Security of the Ministry of Digital Development oversees enforcement. Key provisions include consent requirements, data subject rights, data localisation for certain categories, cross-border transfer restrictions, and data protection officer requirements. Amendments in 2023 strengthened rights and introduced breach notification obligations.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (22)
Accountability
| Code | Title |
|---|---|
| KZ-PDPL-10 | Designation of Responsible Person |
Breach Management
| Code | Title |
|---|---|
| KZ-PDPL-9 | Data Breach Handling and Notification |
Chapter 1 - General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
Chapter 2 - State Regulation of Personal Data
| Code | Title |
|---|---|
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
| Art. 6 | Writing |
| Art. 8 | Compliance with the Requirements |
Chapter 3 - Collection and Processing of Personal Data
| Code | Title |
|---|---|
| Art. 10 | Data and Data Governance |
| Art. 11 | Technical Documentation |
| Art. 14 | Human Oversight |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
| Art. 17 | Quality Management System |
| Art. 9 | Risk Management System |
Chapter 4 - Rights and Obligations
| Code | Title |
|---|---|
| Art. 18 | Documentation Keeping |
| Art. 19 | Automatically Generated Logs |
| Art. 20 | Corrective Actions and Duty of Information |
| Art. 22 | Authorised Representatives of Providers of High-Risk AI Systems |
| Art. 23 | Transitional Provisions |
Chapter 5 - Liability and Enforcement
| Code | Title |
|---|---|
| Art. 24 | Restrictions on Processing Unique Identification Information |
| Art. 25 | Criminal Penalties |
| Art. 26 | Obligations of Deployers of High-Risk AI Systems |
Cross Border Transfers
| Code | Title |
|---|---|
| KZ-PDPL-5 | Cross Border Data Transfers |
Data Lifecycle
| Code | Title |
|---|---|
| KZ-PDPL-12 | Retention and Destruction |
Data Localization
| Code | Title |
|---|---|
| KZ-PDPL-4 | Biometric Data Localization |
Data Quality
| Code | Title |
|---|---|
| KZ-PDPL-14 | Data Accuracy and Correction |
Data Subject Rights
| Code | Title |
|---|---|
| KZ-PDPL-6 | Data Subject Rights |
Documentation
| Code | Title |
|---|---|
| KZ-PDPL-7 | Personal Data Inventory and Documentation |
Lawful Basis
| Code | Title |
|---|---|
| KZ-PDPL-1 | Lawful Basis and Consent for Personal Data |
Marketing
| Code | Title |
|---|---|
| KZ-PDPL-15 | Marketing and Public Source Data |
Processor Management
| Code | Title |
|---|---|
| KZ-PDPL-11 | Operator Engagement and Oversight |
Regulator Cooperation
| Code | Title |
|---|---|
| KZ-PDPL-16 | Regulator Cooperation and Inspections |
Regulatory Notification
| Code | Title |
|---|---|
| KZ-PDPL-2 | Notification to the Authorized Body |
Security
| Code | Title |
|---|---|
| KZ-PDPL-8 | Security of Personal Data Processing |
Sensitive Data
| Code | Title |
|---|---|
| KZ-PDPL-3 | Sensitive Personal Data Protections |
Training
| Code | Title |
|---|---|
| KZ-PDPL-17 | Training on Personal Data Protection |
Transparency
| Code | Title |
|---|---|
| KZ-PDPL-13 | Privacy Notices and Transparency |
Your Compliance Coverage
If you comply with Kazakhstan Law on Personal Data and Their Protection (No. 94-V), you already cover:
Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data
26%
10 controls mapped
Compare →LGPD
26%
10 controls mapped
Compare →Hungary Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act)
26%
10 controls mapped
Compare →+ 602 more: Zimbabwe Data Protection Act (2021) (26%), EU AI Act (26%)
See all 605 mapped frameworks ↓Maps to 605 other frameworks
Frequently Asked Questions
What is Kazakhstan Law on Personal Data and Their Protection (No. 94-V)?
Kazakhstan Law on Personal Data and Their Protection (No. 94-V) is a compliance framework from Kazakhstan with 22 domains and 40 controls. Kazakhstan's Law on Personal Data and Their Protection (No. 94-V, 2013, significantly amended 2023) establishes the data protection framework. The Committee on Information Security of the Ministry of Digital Development oversees enforcement. Key provisions include consent requirements, data subject rights, data localisation for certain categories, cross-border transfer restrictions, and data protection officer requirements. Amendments in 2023 strengthened rights and introduced breach notification obligations. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Kazakhstan Law on Personal Data and Their Protection (No. 94-V) have?
Kazakhstan Law on Personal Data and Their Protection (No. 94-V) has 40 controls organised across 22 domains. The largest domains are Chapter 3 - Collection and Processing of Personal Data (6 controls), Chapter 1 - General Provisions (5 controls), Chapter 4 - Rights and Obligations (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Kazakhstan Law on Personal Data and Their Protection (No. 94-V) map to?
Kazakhstan Law on Personal Data and Their Protection (No. 94-V) maps to 605 other compliance frameworks. The top mapping partners are Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (26% coverage), LGPD (26% coverage), Hungary Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act) (26% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Kazakhstan Law on Personal Data and Their Protection (No. 94-V) compliance?
Start your Kazakhstan Law on Personal Data and Their Protection (No. 94-V) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Kazakhstan Law on Personal Data and Their Protection (No. 94-V) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 40 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 706 frameworks.
Get Started Free →Free forever — no credit card required