Kazakhstan Informatization Law
Law of the Republic of Kazakhstan dated November 24, 2015, No. 418-V 'On Informatization'
Закон Республики Казахстан от 24 ноября 2015 года № 418-V «Об информатизации»
Kazakhstan
RAI-KZ-NA-NO418V0-2015No. 418-V
Kazakhstan Informatization Law is In Force (Amended) in Kazakhstan as of 7 Sep 2026, according to adilet.zan.kz.
ActGovernance and OversightData Protection and PrivacyLaw No. 418-V, enacted by the Parliament of Kazakhstan in 2015, establishes the legal framework for cybersecurity and AI integration binding public and private digital operators. The statute took effect on January 1, 2016, and is In Force (Amended). Compliance is supervised by the Ministry of Artificial Intelligence and Digital Development.
Summary
Law No. 418-V of November 24, 2015 is currently In Force (Amended). Its most recent major modification entered into force on July 12, 2026, pursuant to Law No. 256-VIII of January 9, 2026, which officially renamed the statute from the Law 'On Informatization' to the Law 'On Cybersecurity' and restructured its scope.
The law establishes the primary legal and organizational framework for cybersecurity across the Republic of Kazakhstan. It aims to achieve and maintain the security of digital objects and critical digital infrastructure, ensuring the stable functioning of state bodies, businesses, and society against cyber threats and security incidents.
Enforcement and regulatory oversight are led by the Authorized Body in the Field of Cybersecurity (the central executive ministry) alongside the State Technical Service and the National Coordination Center for Cybersecurity. These entities are empowered to supervise compliance, conduct continuous monitoring of cybersecurity events, perform mandatory cybersecurity audits of critical digital objects, manage the National Repository of Source Codes, and enforce technical protection standards.
The law establishes binding obligations for public and private operators of digital infrastructure, including mandatory event logging, vulnerability remediation, implementation of security protection profiles, and immediate reporting and response to cybersecurity incidents.
Full article
Read full text ↗Overview
The Law of the Republic of Kazakhstan of November 24, 2015 No. 418-V was originally enacted as the Law 'On Informatization'. Following legislative reforms under Law No. 256-VIII of January 9, 2026 (which entered into force on July 12, 2026), the statute was officially renamed to the Law 'On Cybersecurity'. This reform shifted the primary focus of Law No. 418-V from general informatization to cybersecurity, the protection of digital objects, and defense of critical digital infrastructure across Kazakhstan.
Definitions
Article 1 of the Law, as amended by Law No. 256-VIII, provides a comprehensive glossary of cybersecurity terminology. It defines 'cybersecurity' as the state of protection of digital objects from violations of their confidentiality, integrity, or availability. Key statutory definitions include 'critical digital objects', 'cybersecurity threat', 'cybersecurity event', 'cybersecurity incident', 'cybersecurity audit', and 'cybersecurity incident response service'. It also defines technical mechanisms such as the National Repository of Source Codes, single Internet access gateways, event logging, and security protection profiles.
Governance and Institutional Framework
The governance structure is led by the Authorized Body in the field of cybersecurity (the central executive body), which oversees state policy and cross-sectoral coordination. Key operational functions are assigned to the State Technical Service—a state entity created by decision of the Government of Kazakhstan—and the National Coordination Center for Cybersecurity. The framework also includes sectoral cybersecurity centers, specialized cybersecurity centers, and cybersecurity incident response services responsible for local monitoring, vulnerability discovery, and incident handling.
Key Focus Areas
One of the primary focus areas of the Law is the continuous development and refinement of the 'Electronic Government.' The law mandates that state bodies must provide services in electronic form, prioritizing the 'proactive' and 'one-stop-shop' principles. This involves the integration of various departmental systems through the 'Smart Bridge' platform, which facilitates secure data exchange between the public and private sectors. The law also emphasizes the 'Open Data' initiative, requiring state bodies to publish non-confidential datasets in machine-readable formats to encourage commercial innovation and public transparency. By centralizing these resources, the government aims to reduce administrative barriers and eliminate the need for citizens to provide paper documents that are already available in state databases. Another significant focus area is the regulation of the National Artificial Intelligence Platform. This platform serves as a unified infrastructure for the development, training, and pilot operation of AI models using state-held data. The law establishes strict rules for accessing this data, ensuring that personal information is anonymized before being used for AI training. Furthermore, the law introduces mandatory labeling for synthetic content generated by AI systems, particularly in the context of mass media and public communications, to prevent the spread of misinformation. The 2025 updates also prioritize 'Digital Sovereignty,' encouraging the use of domestic software and hardware in state informatization projects to reduce dependency on foreign technology providers and mitigate cyber risks.
Implementation Framework
The implementation of informatization projects in Kazakhstan follows a rigorous lifecycle defined by the Law and its subordinate regulations. For state agencies, every project must begin with the development of an 'Architecture of the State Body,' which aligns its IT needs with its functional tasks. This is followed by the creation of investment proposals and technical specifications, which must be approved by the Authorized Body and the State Technical Service. The law promotes the 'Service Model,' where agencies are encouraged to lease infrastructure and software from the National Operator or private providers rather than investing in their own hardware, thereby optimizing budget expenditures and ensuring technical standardization. For AI systems, the implementation framework includes a mandatory risk-based assessment. Before deployment, AI systems are classified into risk categories: low, medium, or high. High-risk systems, especially those used in healthcare, transport, or law enforcement, must undergo a 'Conformity Assessment' to ensure they do not exhibit bias or pose a threat to public safety. The law also requires the appointment of a 'Responsible Person' for the operation of AI systems within an organization. Furthermore, the National AI Platform provides a 'Sandbox' environment where developers can test their solutions under regulatory supervision before full-scale commercial or state deployment, ensuring that innovation does not bypass legal and ethical safeguards.
Data Protection and Localization
A critical pillar of the Informatization Law is the protection of electronic information resources and the enforcement of data sovereignty. The law mandates that all information systems processing the personal data of citizens of the Republic of Kazakhstan must be physically located on servers within the national territory. This localization requirement is designed to ensure that the state can exercise legal jurisdiction over the data and protect it from unauthorized access by foreign entities. Furthermore, the law establishes strict protocols for the classification of information resources into 'state' and 'non-state' categories, with state resources being subject to the highest levels of security and encryption standards. In the context of the 2025 AI amendments, these data protection rules have been extended to the training sets used for machine learning. Developers utilizing the National AI Platform must adhere to 'Privacy by Design' principles, ensuring that data is stripped of identifying characteristics before it enters the training pipeline. The law also grants the State Technical Service the authority to inspect the data centers of private operators to ensure compliance with these localization and security mandates. Failure to comply can lead to the immediate suspension of the information system's operation and significant administrative fines, reflecting the government's view that data security is a fundamental component of national security.
Monitoring and Evaluation
Monitoring and evaluation are critical components of the Law to ensure the efficiency and security of the digital landscape. The Authorized Body conducts annual monitoring of the 'Architecture of the Electronic Government' to identify redundancies and ensure that all state systems are functioning as intended. This includes evaluating the quality of electronic services provided to the public and the level of integration between different state databases. For local executive bodies, the law establishes a 'Digital Maturity' index, which ranks regions based on their success in implementing digital initiatives and providing e-services to their populations. In terms of technical oversight, the State Technical Service (STS) performs mandatory periodic audits of all state-owned information systems and objects of critical information infrastructure. These audits check for vulnerabilities, compliance with encryption standards, and the integrity of data protection mechanisms. With the integration of AI, the monitoring framework now includes 'Algorithmic Audits' for high-risk AI systems. These audits are designed to detect 'black box' issues, where the decision-making process of an AI becomes opaque or discriminatory. The results of these evaluations are used to update the 'National Register of Informatization Objects,' and systems that fail to meet security or performance standards can be ordered to suspend operations until the deficiencies are rectified.
Penalties, Liability, and Appeals
The Law on Informatization establishes a comprehensive liability framework for violations of its provisions. Subjects of informatization—including system owners, operators, and users—bear civil, administrative, or criminal liability depending on the severity of the infraction. Administrative penalties are primarily governed by the Code of the Republic of Kazakhstan on Administrative Offenses (KAP). Common violations include the failure to ensure the security of information systems, the illegal collection or processing of electronic information resources, and the non-fulfillment of requirements regarding the localization of data on servers within Kazakhstan. For AI systems, specific penalties have been introduced for the failure to label synthetic content or for deploying high-risk systems without the required safety certifications. Liability for harm caused by automated systems, including AI, follows the principle of 'Responsibility by Role.' This means that the owner or operator of the system is generally liable for damages caused by the system's output unless they can prove that the harm resulted from unauthorized interference or a failure by the user to follow instructions. The law also provides a robust appeals process. Citizens and legal entities have the right to challenge the decisions of state bodies or the outcomes of automated processes through the Administrative Procedural and Process-Related Code (APPC). In the case of AI-driven decisions, individuals have the specific right to request a human review and a detailed explanation of how the automated decision was reached, ensuring that technology does not undermine the right to due process.
Relationship to Other Instruments
The Law on Informatization does not operate in isolation but is part of a broader legal ecosystem. Its most significant relationship is with the Law 'On Personal Data and its Protection' (No. 94-V). While the Informatization Law provides the technical framework for data systems, the Personal Data Law provides the rights-based framework for how that data is handled. Any object of informatization that processes personal data must comply with both statutes, including requirements for explicit consent and data localization. The law also intersects with the Law 'On Communications,' which regulates the physical networks and telecommunications infrastructure that transport the data generated by informatization objects. Furthermore, the law is closely linked to the Law 'On Digital Assets,' which regulates the mining and circulation of cryptocurrencies and other digital tokens. The 2025 amendments ensured that the National AI Platform and digital asset infrastructures are interoperable, particularly concerning the use of high-performance computing resources. In the realm of intellectual property, the Informatization Law works alongside the Patent Law and the Law on Copyright to determine the ownership of software codes and AI-generated content. Specifically, the law now clarifies that works created solely by AI without human creative input do not receive copyright protection, whereas the 'prompts' and creative requests of users may be protected as intellectual property.
International Alignment
Kazakhstan has designed the Law on Informatization to align with international standards and regional agreements. As a member of the Eurasian Economic Union (EAEU), Kazakhstan harmonizes its digital regulations with the EAEU Digital Agenda, which focuses on cross-border data exchange, digital trade, and unified technical standards for information systems. This alignment ensures that Kazakhstani IT companies can operate more easily within the EAEU market and that state systems are compatible with those of neighboring member states. The law also references international technical standards, such as ISO/IEC for information security management, which are mandatory for critical infrastructure operators. In the context of AI and emerging technologies, Kazakhstan has looked toward the OECD Principles on Artificial Intelligence and the European Union's AI Act for regulatory inspiration. While the Kazakhstani law is less prescriptive than the EU's framework, it adopts a similar risk-based approach and emphasizes transparency, safety, and human-centricity. The law also supports international cooperation in the field of cybersecurity, mandating that the State Technical Service collaborate with international computer emergency response teams (CERTs). By maintaining this international alignment, Kazakhstan aims to improve its standing in global rankings, such as the UN E-Government Development Index, and to attract foreign investment in its growing technology and AI sectors.
Implementation Timeline
The statutory implementation timeline includes the following milestones:
| Date | Event |
|---|---|
| 2015-11-24 | Original enactment of Law No. 418-V ('On Informatization'). |
| 2016-01-01 | Official entry into force of Law No. 418-V. |
| 2023-12-11 | Adoption of information security amendments. |
| 2026-01-09 | Adoption of Law No. 256-VIII renaming the act to the Law 'On Cybersecurity'. |
| 2026-07-12 | Entry into force of Law No. 256-VIII amendments. |
Sources and References
The official text of Law No. 418-V is published and maintained on the Adilet Information and Legal System of the Ministry of Justice of the Republic of Kazakhstan. The statutory framework rests on the Constitution of the Republic of Kazakhstan, federal statutes, and international treaties ratified by Kazakhstan. The law has been modified through major amending statutes, including Law No. 256-VIII of January 9, 2026, which changed the title of the act to 'On Cybersecurity' and updated its provisions regarding digital objects and cybersecurity supervision.
Requirements for a company
What an organisation has to do under Kazakhstan Informatization Law, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
6- Locate all information systems processing personal data of citizens of Kazakhstan on physical servers within the national territory.Operators of information systems processing Kazakh citizens' personal data
- Label synthetic content generated by AI systems, particularly when distributed in mass media and public communications.Deployers and publishers of AI-generated synthetic content
- Subject high-risk AI systems in healthcare, transport, or law enforcement to a conformity assessment prior to deployment.Providers of high-risk AI systems
- Anonymize personal data and apply Privacy by Design principles before utilizing datasets for training AI models.AI developers utilizing state data or National AI Platform
- Appoint a designated responsible person to manage and oversee the operation of AI systems within the organization.Organizations operating AI systems
- Provide individuals upon request with human review and a detailed explanation of automated AI-driven decisions affecting them.Entities utilizing automated AI decision-making systems
Must not do
2- Do not deploy high-risk AI systems without obtaining mandatory safety certifications and completing a conformity assessment.Developers and deployers of high-risk AI systems
- Do not input non-anonymized personal data into AI model training pipelines on the National AI Platform.AI developers using the National AI Platform
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Kazakhstan Informatization Law, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Operators of information systems processing Kazakh citizens' personal data | Locate all information systems processing personal data of citizens of Kazakhstan on physical servers within the national territory. “all information systems processing the personal data of citizens of the Republic of Kazakhstan must be physically located on servers within the national territory.” | Before operating system | — | Critical |
| 2 | Deployers and publishers of AI-generated synthetic content | Label synthetic content generated by AI systems, particularly when distributed in mass media and public communications. “the law introduces mandatory labeling for synthetic content generated by AI systems, particularly in the context of mass media and public communications” | Upon publication or distribution | — | Critical |
| 3 | Developers and deployers of high-risk AI systems | Do not deploy high-risk AI systems without obtaining mandatory safety certifications and completing a conformity assessment. “High-risk systems, especially those used in healthcare, transport, or law enforcement, must undergo a 'Conformity Assessment'” | Before deployment | — | Critical |
| 4 | Providers of high-risk AI systems | Subject high-risk AI systems in healthcare, transport, or law enforcement to a conformity assessment prior to deployment. “High-risk systems, especially those used in healthcare, transport, or law enforcement, must undergo a 'Conformity Assessment'” | Before deployment | — | Critical |
| 5 | AI developers utilizing state data or National AI Platform | Anonymize personal data and apply Privacy by Design principles before utilizing datasets for training AI models. “ensuring that personal information is anonymized before being used for AI training.” | Before model training | — | Critical |
| 6 | AI developers using the National AI Platform | Do not input non-anonymized personal data into AI model training pipelines on the National AI Platform. “Developers utilizing the National AI Platform must adhere to 'Privacy by Design' principles, ensuring that data is stripped of identifying characteristics” | At all times | — | Critical |
| 7 | Organizations operating AI systems | Appoint a designated responsible person to manage and oversee the operation of AI systems within the organization. “The law also requires the appointment of a 'Responsible Person' for the operation of AI systems within an organization.” | Before operating AI systems | — | Important |
| 8 | Entities utilizing automated AI decision-making systems | Provide individuals upon request with human review and a detailed explanation of automated AI-driven decisions affecting them. “individuals have the specific right to request a human review and a detailed explanation of how the automated decision was reached” | Upon individual request | — | Important |
Related Regulations
More AI regulation in Kazakhstan
© Regulations.AI using Gemini 3 Flash Preview · reviewed against official sources on 7 Sep 2026 using Gemini 3.6 Flash