{"id":53455,"date":"2026-09-24T08:01:54","date_gmt":"2026-09-24T05:01:54","guid":{"rendered":"https:\/\/kz.f-chain.com\/?p=53455"},"modified":"2026-09-24T08:23:45","modified_gmt":"2026-09-24T05:23:45","slug":"digital-code-personal-data-2026","status":"publish","type":"post","link":"https:\/\/kz.f-chain.com\/en\/feautured-post\/digital-code-personal-data-2026\/","title":{"rendered":"Kazakhstan\u2019s Digital Code: New Personal Data Protection Requirements in 2026"},"content":{"rendered":"<h2><strong>Kazakhstan\u2019s Digital Code: New Personal Data Protection Requirements in 2026<\/strong><\/h2>\n<p>In 2026, Kazakhstan substantially updated its approach to personal data regulation: the Digital Code came into effect, certain requirements relating to the processing and protection of personal data were revised, new obligations for businesses were introduced, and liability for violations was strengthened.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>In short, the key changes are as follows:<\/strong><\/h3>\n<ol>\n<li>the Digital Code came into effect, introducing additional rights for individuals in relation to their personal data, including the right to request deletion, anonymisation or restriction of processing in cases provided by law;<\/li>\n<li>personal data protection requirements were updated: companies must identify the processes involving personal data processing, determine the persons having access to such data, appoint a responsible person and implement the necessary organisational and technical protection measures;<\/li>\n<li>a classification of personal data owners and operators was introduced depending on the number of data subjects, together with new rules for notifying the authorised body of the commencement and termination of personal data processing;<\/li>\n<li>administrative liability was significantly increased: in certain cases, the fine for large business entities may reach 2,000 MCI, or KZT 8,650,000 in 2026.<\/li>\n<\/ol>\n<p>Below, we take a closer look at what exactly has changed and what practical implications the new requirements may have for businesses. In 2026, regulation of the digital environment and personal data protection in Kazakhstan entered a new stage. The Digital Code of the Republic of Kazakhstan came into effect, certain requirements of personal data legislation were updated, and administrative liability for violations in this area was significantly increased. For businesses, this means that personal data issues can no longer be treated solely as a technical task for the IT department. The collection, storage, use, transfer and protection of personal data require proper legal documentation, effective internal procedures and demonstrable compliance with the applicable protection measures.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>What has changed?<\/strong><\/h3>\n<p>The Digital Code of the Republic of Kazakhstan was adopted on 9 January 2026 and came into effect in July 2026. The Code established a unified legal framework for the digital environment and, among other matters, introduced additional rights for data subjects in relation to data placed or processed in the digital environment. In particular, a personal data subject may require the deletion, anonymisation or restriction of processing of his or her personal data in the cases provided by law. At the same time, the Law of the Republic of Kazakhstan \u201cOn Personal Data and Their Protection\u201d remains in force and continues to be one of the key legal acts in this area. The Law establishes requirements for obtaining consent, determining the purposes and scope of processing, ensuring confidentiality and security, and sets out the obligations of personal data owners and operators. Updated Rules on measures for the protection of personal data have applied since 12 July 2026. Among other things, the Rules require the identification of business processes involving the collection and processing of personal data, identification of persons having access to such data, approval of internal documents, appointment by legal entities of a person responsible for organising personal data processing, and implementation of the necessary organisational and technical protection measures. If a personal data security breach is detected, the owner, operator or third party must notify the authorised body within one business day from the moment the breach is detected. Further material amendments were introduced by Law of the Republic of Kazakhstan No. 326-VIII dated 24 June 2026 and took effect on 25 August 2026. In particular, owners and operators, as well as third parties collecting and processing personal data, are now classified according to the number of unique data subjects: small entities process data of no more than 10,000 unique subjects; medium entities process data of 10,000 to 500,000 unique subjects; and large entities process data of 500,000 or more unique subjects. Where restricted-access personal data are collected and processed, the category of the owner and\/or operator is increased by one level. A register of persons collecting and\/or processing personal data has also been introduced. As a general rule, the owner, operator and third party must notify the authorised body before starting personal data processing and upon termination of such processing. An exception applies to persons classified as small and medium. Companies should therefore determine their category and assess whether the relevant notification obligation applies to them. As a result, the regulatory framework is moving from the general requirement to \u201censure data protection\u201d towards a more detailed system of duties and procedures that a company must be able to demonstrate in practice.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Liability has increased significantly<\/strong><\/h3>\n<p>At the same time, the state has substantially increased liability for violations of personal data legislation.<\/p>\n<p>Article 79 of the Code of the Republic of Kazakhstan on Administrative Offences provides for liability, among other things, for unlawful collection and processing of personal data, failure to comply with personal data protection measures, and violations resulting in loss or unlawful collection or processing of data. The amount of the penalty depends on the offence and the category of the business entity. In particular, where failure to comply with personal data protection measures results in loss, unlawful collection and\/or processing of personal data, the fine for a large business entity may reach 2,000 MCI. With the monthly calculation index (MCI) set at KZT 4,325 in 2026, this equals KZT 8,650,000. The increase in liability has also been accompanied by more active enforcement. According to information from the Prosecutor General\u2019s Office, during the first seven months of 2026 the number of persons brought to administrative liability for violations of personal data and data protection legislation increased more than fourfold. Accordingly, the absence of the required internal documents, or the existence of a purely formal policy that does not reflect the company\u2019s actual processes, creates a concrete legal and financial risk rather than a merely theoretical one.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>What documents should a company have?<\/strong><\/h3>\n<p>It is important to note that the obligation to regulate personal data processing through internal documentation is not new. The Law of the Republic of Kazakhstan \u201cOn Personal Data and Their Protection\u201d requires the owner and\/or operator to approve a list of personal data that is necessary and sufficient for the relevant tasks, as well as documents governing the procedure and policy for the collection, processing and protection of personal data. A legal entity must also appoint a person responsible for organising personal data processing. However, in light of the new requirements and the substantial increase in liability, the formal existence of a single document entitled \u201cPrivacy Policy\u201d may be insufficient.<\/p>\n<p>A company should analyse what personal data it actually receives, for what purposes and on what legal basis, where the data are stored, who has access to them, to whom they are transferred and how they are protected. Depending on the organisation\u2019s activities, the relevant set of documents may include:<\/p>\n<ol>\n<li>a policy on the collection, processing and protection of personal data;<\/li>\n<li>a list of personal data necessary and sufficient for the company\u2019s activities;<\/li>\n<li>consent forms for the collection and processing of personal data, addressing, where applicable, transfers to third parties, cross-border transfers and other relevant forms of processing;<\/li>\n<li>an order appointing the person responsible for organising personal data processing;<\/li>\n<li>internal rules governing employee access to personal data;<\/li>\n<li>rules on storage, blocking, deletion, depersonalisation and destruction of personal data;<\/li>\n<li>procedures for responding to incidents and personal data security breaches, including mandatory notification procedures;<\/li>\n<li>provisions governing transfers of personal data to contractors and other third parties;<\/li>\n<li>appropriate clauses in employment agreements and contracts with clients, suppliers and other counterparties;<\/li>\n<li>documents and notices placed on corporate websites and other digital resources;<\/li>\n<li>where the relevant obligation applies, a notification to the authorised body on the commencement and termination of personal data processing.<\/li>\n<\/ol>\n<p>The specific set of documents should be determined individually, taking into account the company\u2019s structure and activities, the categories and volume of personal data processed, the number of data subjects, the digital systems used and the company\u2019s interaction with third parties.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>What should businesses do now?<\/strong><\/h3>\n<p>Companies that process data relating to employees, candidates, clients, representatives of counterparties, website users or other individuals should conduct an internal review of their existing processes.<\/p>\n<p>The first step should be an audit: identify all processes in which personal data are collected or processed, verify that an appropriate legal basis exists, assess the existing documentation, determine the company\u2019s category under the new criteria, and check whether there is an obligation to notify the authorised body.<\/p>\n<p>Internal documents should then be aligned not only with the law but also with the company\u2019s actual business processes. A policy that exists only formally and does not reflect how data are handled in practice does not, by itself, ensure proper legal compliance.<\/p>\n<p>Particular attention should be paid by companies using foreign IT services, cloud systems, CRM systems, HR platforms and other solutions involving the transfer or storage of information with the participation of third parties. In such cases, the requirements concerning the location of data storage, the legal grounds for transfers to third parties and the conditions for cross-border transfers should be assessed separately.<\/p>\n<p>&nbsp;<\/p>\n<h3>Professional Services by FChain<\/h3>\n<p>FChain provides comprehensive legal support on personal data protection matters and assists companies in aligning their internal processes with the legislation of the Republic of Kazakhstan. As part of this work, we conduct legal audits of a company\u2019s existing processes and documentation, identify applicable requirements and potential risks, determine the category of the personal data owner or operator under the new criteria, assess whether notification of the authorized body is required, and develop the necessary set of internal documents tailored to the specific nature of the company\u2019s business.<\/p>\n<p>In particular, our support may include the development and updating of policies governing the collection, processing, and protection of personal data; lists of personal data necessary for the company\u2019s activities; consent forms; internal orders and procedures; provisions governing access to and transfer of personal data; procedures for responding to personal data security breaches; as well as relevant contractual provisions for employees, clients, and counterparties.<\/p>\n<ul>\n<li><a href=\"https:\/\/kz.f-chain.com\/en\/legal-support-for-business\/\"><strong>Legal support for business<\/strong><\/a> \u2014 comprehensive legal support for companies, including compliance with personal data processing and protection requirements.<\/li>\n<li><a href=\"https:\/\/kz.f-chain.com\/en\/legal-audit\/\"><strong>Legal audit<\/strong><\/a> \u2014 review of a company\u2019s internal processes and documentation to identify legal risks and determine whether updates are required.<\/li>\n<li><a href=\"https:\/\/kz.f-chain.com\/en\/drafting-contracts\/\"><strong>Drafting contracts<\/strong><\/a> \u2014 preparation and review of contractual provisions governing the processing, transfer, and protection of personal data in relationships with employees, clients, and counterparties.<\/li>\n<\/ul>\n<p>The changes introduced in 2026 require businesses to adopt a more systematic approach to personal data management. Companies should not only update their internal documentation but also ensure that their actual processes for collecting, processing, storing, and transferring personal data comply with the new legal requirements. Given the strengthened regulatory oversight and increased liability, a timely review of existing processes can help reduce legal and financial risks.<\/p>\n<p>&nbsp;<\/p>\n<p><strong><a href=\"https:\/\/kz.f-chain.com\/en\/feautured-post\/cash-register-receipts-kazakhstan-26\/\">Cash Register Receipts: New Requirements from September 2026<\/a><\/strong><\/p>\n<p style=\"text-align: right;\"><em>Prepared by: Sergey Gaidarov<\/em><\/p>\n<p style=\"text-align: right;\"><em>Senior Legal Adviser<\/em><\/p>\n<p style=\"text-align: right;\"><em>FChain Kazakhstan<\/em><\/p>\n<p style=\"text-align: center;\"><strong>\ud83d\udce9<\/strong><strong>almaty@f-chain.com<\/strong><br \/>\n<strong>WhatsApp: +7 771 214 1820<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kazakhstan\u2019s Digital Code: New Personal Data Protection Requirements in 2026 In 2026, Kazakhstan substantially updated its approach to personal data regulation: the Digital Code came into effect, certain requirements relating to the processing and protection of personal data were revised, new obligations for businesses were introduced, and liability for violations was strengthened. &nbsp; In short,<\/p>\n","protected":false},"author":6,"featured_media":53456,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[23,24],"tags":[],"class_list":["post-53455","post","type-post","status-publish","format-standard","hentry","category-feautured-post","category-news-ribbon"],"acf":[],"_links":{"self":[{"href":"https:\/\/kz.f-chain.com\/en\/wp-json\/wp\/v2\/posts\/53455","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kz.f-chain.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kz.f-chain.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kz.f-chain.com\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/kz.f-chain.com\/en\/wp-json\/wp\/v2\/comments?post=53455"}],"version-history":[{"count":3,"href":"https:\/\/kz.f-chain.com\/en\/wp-json\/wp\/v2\/posts\/53455\/revisions"}],"predecessor-version":[{"id":53461,"href":"https:\/\/kz.f-chain.com\/en\/wp-json\/wp\/v2\/posts\/53455\/revisions\/53461"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/kz.f-chain.com\/en\/wp-json\/wp\/v2\/media\/53456"}],"wp:attachment":[{"href":"https:\/\/kz.f-chain.com\/en\/wp-json\/wp\/v2\/media?parent=53455"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kz.f-chain.com\/en\/wp-json\/wp\/v2\/categories?post=53455"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kz.f-chain.com\/en\/wp-json\/wp\/v2\/tags?post=53455"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}