Personal Data Protection in Kazakhstan: New Requirements and a Step-by-Step Plan for Businesses

The protection of personal data is becoming a top priority in both Kazakhstan and Russia. Notably, there is a clear trend toward harmonization of legislation between the two countries. Kazakhstan has recently adopted new amendments to its personal data laws, which largely align with the requirements of Russian legislation. This approach is, without a doubt, a positive development. It fosters a shared understanding in the business community that personal data protection requires not just formal compliance, but a systematic approach, ongoing monitoring, and, most importantly, personal accountability on the part of leadership.

Data protection is an ongoing process that goes beyond IT and sits firmly within the domain of corporate culture. Ultimately, the security of personal data depends on the actions of every employee. Everyone must understand that personal data is not just lines in a system — it represents real individuals, and the company is responsible for their security before the law and society.

Where to start building a data protection system? Full compliance isn’t achieved overnight. However, there is a logical and proven sequence of steps that will help build a working system and reduce business risks.

How to Build a Personal Data Protection System in Practice

Appoint a Data Protection Officer (DPO). The first and most critical step is to designate an employee responsible for information security and data processing. Ideally, this should be a DPO with expertise in relevant legislation. In practice, this role is often filled by legal counsel or heads of IT departments. A significant advantage is providing such a specialist with specialized training or short-term courses on data protection.

Conduct an Internal Audit and Review Documentation. The next stage involves a comprehensive internal audit: identifying information systems, data categories, and processing purposes. This should result in the development of essential internal documentation, including up-to-date consent forms.

Develop Policies and Standards. In parallel, implement internal governance documents such as an Acceptable Use Policy, IT policies aligned with standards like ISO 27001, and other regulations to strengthen information security. Employee training materials should also be created, covering how to identify phishing emails, general information security rules, and proper handling of personal data.

Run Practical Drills. Internal phishing simulations with follow-up training for those who fall for them can deliver significant results. These drills greatly increase employee awareness and reduce risks.

Implement Technical Measures. Don’t forget the technical side: the company must put in place a range of measures to secure information systems, including encryption, password policies, access control, leak prevention, and data backup.

The latest wave of legislative changes in Kazakhstan offers a real opportunity to build a mature data governance framework grounded in best practices.

Author: Andrey Yudkin, Director of Information Security, LavoroSolutions