On 25 June 2026, the Acting Minister of Artificial Intelligence and Digital Development of the Republic of Kazakhstan (the “RK”) signed Order No. 352/НҚ “On the Approval of the Rules on Third-Party Access to Digital Records via the Digital Documents Service with Mandatory Personal Data Protection” (the “Order”). The Order came into force on 12 July 2026.
Legal basis: The Order was adopted in implementation of Article 64(4) of the Digital Code of the Republic of Kazakhstan dated 9 January 2026, No. 255-VIII (the “Digital Code”), pursuant to which third-party access to digital records via the digital documents service is carried out with the consent of the user in the manner prescribed by the authorised body, with mandatory personal data protection.
This overview covers the key provisions of the Rules on Third-Party Access to Digital Records via the Digital Documents Service with Mandatory Personal Data Protection (the “Rules”) that have a practical impact on business operations.
I. Legal Context and Scope of Application
The Rules set out the procedure under which private companies (“third parties” as defined in the Rules) may obtain access to the digital records of individuals (data held in national registers and state digital resources) through the "digital government" mobile application.
New definitions introduced by the Rules:
- A third party — a person who is not a data subject, data owner or data operator, but who is connected to them by circumstances or legal relationships involving the collection, processing and protection of personal data;
- The digital documents service — a “digital government” digital infrastructure facility designed for the display and use of documents in digital form.
II. Conditions for Third-Party Access to Digital Records
The Rules establish an exhaustive list of conditions, all of which must be satisfied simultaneously for third parties to be granted access to the digital records or digital documents of a data subject:
- the data subject’s duly obtained consent to the collection and processing of their personal data, containing the information specified in Article 8(4) of the RK Law “On Personal Data and Their Protection” dated 21 May 2013, No. 94-V;
- integration of the third party’s digital facility with the “digital government” mobile application in accordance with Article 83(3) of the Digital Code;
- implementation of a comprehensive set of personal data protection measures in accordance with the RK legislation on personal data and their protection.
III. Access Mechanism: Two Scenarios
The Rules contemplate two technical scenarios under which a third party may obtain access to a data subject’s records.
Scenario 1: Initiation by the Data Subject (QR Code / Short Code)
- The data subject independently generates a short code (six-digit) or a QR code in the "digital government" mobile application and provides it to the third party.
- The code remains valid for no longer than one minute from the moment of its generation.
- The third party enters the short code or scans the QR code via its digital facility and submits a request to the "digital government" mobile application.
- If the verification is successful, the digital records are transmitted to the third party’s digital facility.
- Regardless of the outcome, the data subject receives an SMS notification to their registered mobile number confirming that access to their data has been requested.
Scenario 2: Initiation by the Third Party (One-Time Password)
- The third party, through its digital facility, submits a request to the "digital government" mobile application to obtain the data subject’s consent.
- Following the verification of the third party’s login credentials and the existence of the data subject’s profile, if the verification is successful, a one-time password (One-Time Password – “OTP”) is sent to the data subject’s registered mobile number or to their personal account on the "digital government" web portal.
- The data subject provides the OTP to the third party for the submission of a request to access the digital records.
- Following the verification of the OTP, the records are transmitted to the third party’s digital facility.
A one-off consent stored in the company’s database is not sufficient — each request requires fresh confirmation from the data subject.
IV. Personal Data Protection Requirements
The Rules expressly link the granting of access to digital records with mandatory compliance with the RK legislation on personal data and their protection as a standalone access condition. This means that any breach of personal data legislation automatically precludes the lawful use of the digital documents service.
In addition, the Rules establish a data subject notification mechanism: an SMS notification is sent to the data subject’s registered mobile number each time their records are accessed. This enables the data subject to exercise real-time oversight of the use of their data by third parties.
V. Practical Steps for Businesses
Companies planning to use, or already using, the digital documents service are advised to consider the following steps: