Personal Data Protection Rules Updated: What Has Actually Changed


On 22 June 2026, the Deputy Prime Minister — Minister of Artificial Intelligence and Digital Development of the Republic of Kazakhstan (“RK”) issued Order No. 338/NK “On Amending Order No. 179/NK of the Minister of Digital Development, Innovation and the Aerospace Industry of the Republic of Kazakhstan dated 12 June 2023 “On the Approval of the Rules for the Implementation of Personal Data Protection Measures by Data Controllers and/or Data Processors, as well as Third Parties” (the “Order”). The Order came into force on 12 July 2026.

The new Rules on the implementation of personal data protection measures by data controllers and/or data processors, as well as by third parties (the “Rules”) have been set out in an entirely new version, replacing the previously applicable procedure.

This overview covers only those provisions that are new or amended compared with the previous version of the Rules and does not duplicate the provisions expressly set out in the Law of the Republic of Kazakhstan “On Personal Data and Its Protection” No. 94-V dated 21 May 2013 (the “Personal Data Law”).

I. New Definition of Personal Data

The Rules introduce a new definition of personal data, which differs fundamentally from the definition previously in force under the Personal Data Law. Accordingly, the Law of the Republic of Kazakhstan “On Amendments and Additions to Certain Legislative Acts of the Republic of Kazakhstan on Digitalisation, Transport and Entrepreneurship” No. 256-VIII dated 9 January 2026 (which came into force on 11 July 2026) introduces a corresponding new definition into the Personal Data Law:

  • The previous versions of the Rules and the Personal Data Law defined personal data as “data, including biometric data, relating to an identified or identifiable data subject, recorded on an electronic, paper and/or other physical medium”.
  • The new versions of the Rules and the Personal Data Law introduce the following definition: personal data means information or a set of information about a data subject, supplemented by one or more personal data identifiers”. The new defining criterion — the presence of a “personal data identifier” — removes the link to a physical medium and biometric data.

The concept of “personal data identifier” is not defined in the Rules themselves. The new definition may be broader or narrower, depending on how the term “identifier” is interpreted.

This means that companies need to monitor the emerging enforcement practices of government bodies and assess the risk of the data they process being reclassified.

II. Blocking of Personal Data: A New Rule on the Timing of Application

The new Rules, for the first time, expressly establish the point at which personal data with restricted access (“PDRA”) must be blocked upon a data subject’s request: the blocking must be carried out before a decision on the request is taken. Previously, no such specification existed in the legislation.

This means that personal data must be blocked immediately upon receipt of a data subject’s request. Moreover, the blocking must take place before any decision is made as to whether to grant or refuse the request.

III. Biometric Authentication: Clarification of the Scope of Obligated Persons

The previous version of the Rules required the use of authentication measures, including biometric authentication, for databases containing more than 100,000 records, without specifying the persons to whom these requirements applied. The new Rules add an important clarification: this obligation applies exclusively to people who have access to the personal data database.

IV. Practical Steps for Business

In light of the updated Rules, companies should consider taking the following steps:

Note:

Should you require expert assistance in the area of personal data protection, including an audit of processing procedures and ensuring compliance with the updated Rules, we are prepared to provide qualified support and legal advisory services.