Jurisdictions
Kazakhstan

Strategic notes on data protection and localisation requirements in Kazakhstan under the Law on Permits and Notifications

Kazakhstan's Law on Permits and Notifications (Zakon o razreshenii i uvedomlenii) does more than regulate licences and notifications in the conventional sense: it intersects with the country's data protection and personal data localisation framework in ways that frequently surprise foreign companies entering the Kazakhstani market. For businesses operating across the Russia–Kazakhstan corridor or within the broader EAEU, understanding where these obligations begin is a practical priority before establishing a commercial or digital presence.

H2: What the Law on Permits and Notifications requires

The Law on Permits and Notifications establishes the general framework through which the Kazakhstani state authorises or registers commercial and operational activities. Certain categories of activity — including those involving the processing of personal data of Kazakhstani residents — require prior notification to or registration with the relevant regulatory authority, primarily the Committee on Information Security within the Ministry of Digital Development, Innovation and Aerospace Industry (MCRIAP).

The intersection with data protection arises because operators of information systems and cross-border data controllers fall within the notification regime. A foreign company that collects, processes, or stores personal data of Kazakhstani individuals — whether through an e-commerce platform, a corporate HR system, a CRM tool, or a client-facing mobile application — may be required to register its information systems and to confirm that personal data of Kazakhstani residents is stored on servers physically located within Kazakhstan.

The localisation requirement is not absolute: certain categories of data processing are exempt, and the law provides a differentiated approach depending on the sensitivity of the data, the volume of processing, and whether the operator qualifies as a "cross-border" processor under Kazakhstani regulatory definitions. However, the default presumption for operators of sizeable databases of Kazakhstani personal data is that local server infrastructure or a certified cloud operator with a Kazakhstan-based node is required.

Note: Failure to comply with the registration and localisation obligations under Kazakhstani data protection legislation may expose a foreign operator to administrative liability, including potential blocking of the operator's website or digital services by order of the regulatory authority. Foreign companies that have not completed the notification filing should treat this as a live compliance gap rather than a deferred matter.

H2: How do data localisation obligations apply to cross-border operators?

For companies already established in Russia and extending operations into Kazakhstan — or those operating through a single legal entity across the EAEU — the localisation requirements in each jurisdiction apply separately and are not satisfied by mutual recognition within the EAEU framework. Russia's own data localisation rules under Federal Law No. 152-FZ do not discharge a company's obligations under Kazakhstani law, and vice versa.

In practice, this means that a company storing personal data of Russian users on a Kazakhstan-based server, or Kazakhstani-user data on a Russian server, satisfies neither jurisdiction's requirement. The common assumption that EAEU membership implies regulatory harmonisation on personal data is incorrect: data protection and localisation remain matters of national competence within the EAEU, and each member state has developed its own regime independently.

For foreign companies entering Kazakhstan from third countries — including those with EU, UK, or US parent entities — the Kazakhstani localisation requirement operates in addition to any home-country obligations. GDPR adequacy considerations do not alter the Kazakhstani obligation, and there is no bilateral arrangement between Kazakhstan and the EU or the UK that provides an equivalent mechanism to an adequacy decision.

H2: What foreign companies should verify before commencing data operations

Practitioners advising foreign clients on Kazakhstani market entry should confirm the following before the client commences any data processing activity directed at Kazakhstani residents:

  • Whether the client's information systems fall within the mandatory notification scope under the Law on Permits and Notifications and the applicable data protection regulations.
  • Whether the data being processed qualifies as personal data under Kazakhstani law and, if so, whether it falls into a special or sensitive category attracting stricter localisation requirements.
  • Whether the client proposes to use a third-party cloud provider, and if so, whether that provider holds a certificate of conformity issued by the Kazakhstani Committee on Information Security for the relevant data category and processing type.
  • Whether any cross-border data transfer arrangement — including transfers to a Russian, EU, or other non-Kazakhstani entity within the same corporate group — requires a separate legal basis or notification filing.
  • Whether the client's operational timeline allows for the notification and registration process to be completed before go-live: in practice, processing timelines vary and should not be assumed to be automatic or immediate.

The Regulatory & Licensing practice page (/jurisdictions/kazakhstan/regulatory-licensing/) sets out the firm's approach to market entry compliance in Kazakhstan, including notification filing support and information system registration.

For companies also considering the broader regional picture, similar — though not identical — data localisation frameworks apply in Uzbekistan (/jurisdictions/uzbekistan/regulatory-licensing/) and in Russia under the 152-FZ regime. Cross-border structures that span two or more of these jurisdictions require jurisdiction-specific analysis rather than a single harmonised compliance approach.

[CTA: For practitioners or in-house counsel advising on Kazakhstani data protection and localisation requirements — make an enquiry: info@vetrovpartners.com | WhatsApp/Telegram: +7 (983) 510-38-76]

H2: Related reading

  • Market entry and company formation in Kazakhstan: a procedural overview (/jurisdictions/kazakhstan/company-formation/)
  • Regulatory and licensing requirements for foreign companies in Kazakhstan (/jurisdictions/kazakhstan/regulatory-licensing/)
  • Cross-border data transfers in the EAEU: comparing Kazakhstan and Russia (/insights/kz-pn-001-cross-border-data-transfers-eaeu-kazakhstan-russia/)

H2: About Vetrov & Partners

Vetrov & Partners is a Russian boutique law firm established in 2009, recognised by Pravo-300 for eight consecutive years. The firm advises foreign companies on regulatory and licensing matters across Russia and, through its regional analyst network, on adjacent EAEU jurisdictions including Kazakhstan. Enquiries relating to Kazakhstan market entry and data compliance are coordinated with qualified Kazakhstani counsel.

Enquiries: info@vetrovpartners.com | WhatsApp / Telegram: +7 (983) 510-38-76 | t.me/vitvetcom

This publication is provided for informational purposes only and does not constitute legal advice under Russian or any other applicable law. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. Vetrov & Partners is a Russian-qualified law firm. For matters governed by foreign law or requiring local admission in another jurisdiction, we collaborate with trusted counsel in the relevant jurisdiction. For advice regarding your particular situation, please contact info@vetrovpartners.com.

— Aigerim Serikbayeva Contributing Regional Analyst — Kazakhstan · EAEU trade, customs and market entry vetrovpartners.com/contributions/