Payment for services is made exclusively to the company's account. For your convenience, we have launched Kaspi RED 😎

Home / Laws / Article 1. The basic concepts used in this Law are the Law on Personal Data and Their Protection

Article 1. The basic concepts used in this Law are the Law on Personal Data and Their Protection

АMANAT партиясы және Заң және Құқық адвокаттық кеңсесінің серіктестігі аясында елге тегін заң көмегі көрсетілді

Article 1. The basic concepts used in this Law are the Law on Personal Data and Their Protection

The following basic concepts are used in this Law:

     1) biometric data – personal data that characterizes the physiological and biological characteristics of the personal data subject, on the basis of which his identity can be established; - Excluded by the Law of the Republic of Kazakhstan dated January 9, 2026 No. 256-VIII SAM

2) personal data – information or a set of information about the subject of personal data supplemented by one or more personal data identifiers;

     2-1) the state service for access control to personal data (hereinafter referred to as the state service) is a service that provides information interaction between owners and (or) operators, third parties with the personal data subject and the authorized body when accessing personal data contained in digital objects of state bodies and (or) state legal entities, including obtaining information from personal data subject's consent to the collection, processing of personal data or their transfer to third parties;

     2-2) a non–governmental personal data access control service (hereinafter referred to as a non–governmental service) is a service that provides information interaction between owners and (or) operators, third parties, and a personal data subject when accessing personal data contained in non-governmental digital objects, including obtaining consent from the personal data subject to collect, process personal data, or their transfer to third parties;

  2-3) automated personal data processing – processing of personal data to digital objects, excluding the participation of the owner and (or) operator, as well as a third party in the processing process;

2-4) deletion of personal data – actions aimed at excluding personal data from a digital object, as a result of which it is impossible to restore personal data.; 

     2-5) anonymization of personal data – actions aimed at the irreversible transformation of personal data identifiers, as a result of which it is impossible to determine the identity of personal data to the personal data subject.;

     3) blocking of personal data – actions to temporarily stop the collection, accumulation, modification, addition, use, dissemination, depersonalization and destruction, destruction and deletion of personal data;

3-1) masking of personal data is the process of protecting information by replacing part of the real personal data with invalid and (or) depersonalized ones.; 

     3-2) dissemination of personal data in publicly available sources – actions, as a result of which access to personal data is provided to an unlimited number of persons;

     4) accumulation of personal data – actions to systematize personal data by entering them into a database containing personal data and (or) a digital object containing personal data;

     5) collection of personal data – actions aimed at obtaining personal data;

5-1) register of persons who collect and (or) process personal data – a list of owners and (or) operators, as well as third parties who collect and (or) process personal data;

     6) destruction of personal data – actions, as a result of which it is impossible to restore personal data;

     7) depersonalization of personal data – actions, as a result of which it is impossible to determine the identity of personal data to the subject of personal data;

     8) the database containing personal data (hereinafter referred to as the database) is a set of ordered personal data on paper;

     9) the owner of a database and (or) a digital object containing personal data (hereinafter referred to as the owner) is a government agency, an individual and (or) a legal entity exercising, in accordance with the laws of the Republic of Kazakhstan, the right to own, use and dispose of a hard copy database and (or) a digital object containing personal data; 

     10) the operator of a database and (or) a digital object containing personal data (hereinafter referred to as the operator) is a government agency, an individual and (or) a legal entity that collects, processes and protects personal data;

10-1) a digital object containing personal data is a digital object containing a set of ordered personal data;

     11) personal data protection – a set of measures, including legal, organizational and technical, carried out for the purposes established by this Law;

     11-1) the authorized body in the field of personal data protection (hereinafter referred to as the authorized body) is the central executive body responsible for managing personal data protection.;

     11-2) Excluded by the Law of the Republic of Kazakhstan dated 12/30/2021 No. 96-VII (effective sixty calendar days after the date of its first official publication).  

     12) personal data processing – actions aimed at accumulation, storage, modification, addition, use, dissemination, depersonalization, anonymization, blocking, destruction and deletion of personal data;

     13) use of personal data – actions with personal data aimed at achieving the goals of the owner, operator and a third party;

     14) personal data storage – actions to ensure the integrity, confidentiality and accessibility of personal data;

14-1) personal data identifier – information that makes it possible to identify the subject of personal data or to link individual sets of data about him into a set of information that makes it possible to identify this subject.;

     15) dissemination of personal data – actions that result in the transfer of personal data, including through mass media, or the provision of access to personal data to a specific person or a certain circle of people in a predetermined manner;

15-1) register of personal data security violations – a list of personal data whose security has been violated;

15-2) violation of personal data security – violation of personal data protection, resulting in illegal dissemination, modification, destruction and deletion, unauthorized dissemination of transmitted, stored or otherwise processed personal data or unauthorized access to them;

     16) the subject of personal data (hereinafter referred to as the subject) is an individual to whom personal data relate;

     17) a third party is a person who is not a subject, owner and (or) operator, but is related to them (him) by circumstances or legal relations related to the collection, processing and protection of personal data.

18) Digital data hashing is the process of converting digital data of any size into a fixed–length string in order to protect it.

 

 

The Law of the Republic of Kazakhstan dated May 21, 2013 No. 94-V. 

The article was amended and supplemented by the Law of the Republic of Kazakhstan dated June 24, 2026, No. 326-VIII SAM 

     This Law regulates public relations in the field of personal data, as well as defines the purpose, principles and legal basis of activities related to the collection, processing and protection of personal data.

  

President    

Republic of Kazakhstan     

© 2012. RSE na PHB "Institute of Legislation and Legal Information of the Republic of Kazakhstan" of the Ministry of Justice of the Republic of Kazakhstan  

 Constitution Law Code Standard Decree Order Decision Resolution Lawyer Almaty Lawyer Legal service Legal advice Civil Criminal Administrative cases Disputes Defense Arbitration Law Company Kazakhstan Law Firm Court Cases