Kazakhstan - Data Management Requirements (385/NQ)
Order of the Minister No. 385/NQ - On Approval of Requirements for Data Management
Приказ Министра №385/НҚ «Об утверждении Требований по управлению данными»
Kazakhstan
RAI-KZ-NA-OMN3AXX-2022Order No. 385/NQ (14 October 2022) established mandatory requirements for data management in Kazakhstan, setting rules for governance, classification, lifecycle management, access, sharing and security of data processed by public bodies and specified organizations. The Order was amended in February 2024 and formally repealed by a later ministerial order in November 2024.
Summary
Read full text ↗Plain English
Overview
The Order of the Minister No. 385/NQ (14 October 2022) established a unified set of Requirements for Data Management to govern how state bodies and specified organisations in Kazakhstan manage data throughout its lifecycle. The instrument aimed to improve data quality, enable secure cross-agency sharing, and define institutional roles (data owners, data stewards, custodians) and procedural obligations for inventories, classification, metadata, access control and incident response. The Order was published and made available via official legal information systems, including registers hosted at Adilet and announcements on the Ministry portal Ministry press page. The Order underwent amendment in February 2024 and was ultimately revoked by a later ministerial order in November 2024.
Definitions
The Order defined core terms to standardize understanding across entities: "data asset" (a dataset or collection managed as a unit), "data owner" (official accountable for data value and classification), "data steward" (operational manager responsible for quality and metadata), "data custodian" (technical manager responsible for storage and security), "metadata" (descriptive information to support findability and governance), "data lifecycle" (phases from creation to disposal), and "sensitive/personal data" (categories subject to heightened protections under national law). The definitions aligned these roles to existing public-sector organisational structures to enable assignment of responsibilities and accountability for data governance and security.
Governance and Institutional Framework
The instrument required each ministry, agency and specified organisation to establish a data governance structure composed of appointed data owners and stewards, supported by IT and security units. Entities were directed to maintain a centralized inventory/catalog of datasets and publish metadata to facilitate discovery and authorized reuse. Oversight responsibilities were assigned to the Ministry of Digital Development, Innovations and Aerospace Industry for coordination, methodological support and monitoring. The Order also envisaged interagency coordination mechanisms for data exchange and for establishing common technical standards and interfaces. The Ministry provided explanatory materials and public notices via its website and the national legal portal to guide implementation; see the Ministry’s announcement at Ministry press page and the consolidated text at Adilet.
Key Focus Areas
The Requirements addressed multiple technical, organisational and procedural areas. Data inventory and classification rules required entities to catalogue datasets and label them by sensitivity, criticality and retention. Metadata standards and cataloguing rules supported discoverability and reuse while preserving privacy and security constraints. Lifecycle management provisions established retention schedules, legal basis checks, secure archival and disposal procedures. Data quality and validation rules required entities to set quality metrics, monitor completeness and correctness, and document provenance. Access management provisions mandated role-based access controls, authentication and authorization mechanisms, and logging and auditing of data access. Data-sharing provisions required formal agreements, purpose limitation clauses, and safeguards for transfers, including cross-border considerations. Security controls required technical measures (encryption at rest/in transit, network segmentation, secure backups) and organisational measures (incident response plans, staff training). The Order also required reporting of breaches and incidents to designated supervisory authorities and coordination for remediation.
Implementation Framework
The Order set an implementation sequence: initial inventory and classification; appointment of roles; deployment of metadata catalogues; establishment of sharing agreements; adoption of technical security controls; and continuous quality monitoring. Entities were required to prepare internal regulations and schedules aligned to the Order and to report progress to the Ministry within prescribed timeframes. The instrument envisaged methodical support and templates to be issued by the Ministry for inventories, agreements and security baselines. The February 2024 amendment updated certain operational deadlines and clarified procedural steps; those amendments are recorded in the legal information systems (see Amendment text).
Monitoring and Evaluation
Monitoring obligations included periodic reporting to the Ministry, scheduled audits of data inventories and data quality metrics, and compliance checks focusing on access controls and incident handling. The Ministry was authorised to conduct methodological reviews and to issue corrective recommendations. Performance indicators included completeness of inventories, percentage of datasets classified, number of data-sharing agreements in force, and incident response times. The Order anticipated that monitoring outputs would inform revisions to methodology and technical standards over time.
Penalties, Liability, and Appeals
The Order itself specified administrative and procedural measures for non-compliance, including directives to remedy deficiencies, temporary suspension of data exchanges, and referral to competent agencies for administrative sanctions where statutory breaches occurred (for example, violations of data protection or information security legislation). Entities retained the right to appeal ministerial decisions through administrative and judicial channels under Kazakh law. The February 2024 amendment adjusted enforcement modalities; both the original and the amendment were later revoked by Order No. 691/NQ (11 November 2024), which removed these specific obligations from force and transferred any outstanding enforcement to successor acts.
Relationship to Other Instruments
The Requirements were explicitly linked to existing national frameworks: Kazakhstan's Law on Personal Data, laws on informatization and public information systems, and sectoral regulations for health, finance and other sensitive domains. Where personal data or sector-specific rules applied, those instruments retained primacy and the Requirements were to be read as complementary for data governance rather than as a substitute for sectoral legal obligations. The Order referenced methodological documents and standards to ensure interoperability with state information systems and to align with other ministerial acts; see consolidated references at Adilet record.
International Alignment
The Order reflected an effort to align Kazakhstan’s public-sector data management practice with international best practices in data governance, privacy-by-design, and information security. While not a direct transposition of any single foreign regime, its structure mirrors OECD and EU-inspired approaches to data stewardship, role-based accountability, lifecycle management, and risk-based security measures. The instrument paid particular attention to cross-border data exchange rules and encouraged safeguards consistent with international norms, yet transfers and processing remained subject to national law and sectoral restrictions.
Implementation Timeline
| Event | Date | Notes |
|---|---|---|
| Order issued | 2022-10-14 | Order No. 385/NQ signed by Minister. |
| Registered with Ministry of Justice | 2022-10-17 | Registration No. 30186 (official registration of the normative act). |
| Amendment issued (No. 90/NQ) | 2024-02-23 | Amendments and additions; registered 2024-02-26 (Reg. No. 34051). |
| Order revoked | 2024-11-11 | Order No. 691/NQ revoked Order No. 385/NQ and related amendments; registered 2024-11-12. |
Compliance Checklist
| Requirement | Compliant (Yes/No) | Notes |
|---|---|---|
| Appoint data owners and stewards | Yes | Mandatory assignment for state bodies. |
| Create data inventory and metadata catalogue | Yes | Required for all covered entities. |
| Classify data by sensitivity and retention | Yes | Classification required, with sectoral nuances for personal/sensitive data. |
| Implement role-based access controls and logging | Yes | Technical control requirement; must be auditable. |
| Execute formal data-sharing agreements | Yes | Purpose limitation and safeguards required. |
| Report incidents to designated authority | Yes | Incident reporting and response obligations apply. |
Sources and References
| Source | Type |
|---|---|
| Об утверждении Требований по управлению данными (Order No. 385/NQ) — Adilet | Primary Source |
| Amendment: Order No. 90/NQ (23 Feb 2024) — Adilet | Primary Source |
| Revocation: Order No. 691/NQ (11 Nov 2024) — Adilet | Primary Source |
| Ministry announcement and project materials — Ministry of Digital Development | Primary Source |
Kazakhstan's Order No. 385/NQ, which took effect on October 17, 2022, established mandatory data management requirements for all state bodies and specified organizations across the country. This regulation aimed to standardize how these entities handled data throughout its entire lifecycle, from creation to disposal.
The Order placed several key obligations on ministries, government agencies, and other designated organizations. They were required to: - Establish a clear data governance structure, appointing officials like "data owners" accountable for data value and "data stewards" responsible for quality. - Create and maintain a central inventory or catalog of all datasets, along with descriptive "metadata" to make data discoverable and reusable. - Classify data based on its sensitivity, importance, and required retention periods. - Implement robust access controls, ensuring only authorized personnel could view or use data, and logging all access for auditing purposes. - Formalize data sharing through agreements that specified the purpose of sharing and included necessary safeguards. - Report any data breaches or security incidents to the relevant authorities.
Initially, non-compliance could lead to directives to fix issues, temporary suspension of data exchanges, and potential administrative sanctions under other data protection or information security laws. However, the specific enforcement measures outlined in this Order were later removed. The most critical point for anyone reviewing this regulation is its short lifespan: despite being amended in February 2024, Order No. 385/NQ was formally revoked by a new ministerial order in November 2024. This means its specific provisions are no longer in force, and any ongoing data management requirements would now fall under successor regulations.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 15 marked completePlain-English obligations under Kazakhstan - Data Management Requirements (385/NQ). Not legal advice — verify against the official text before relying on it.
- #1CriticalGovernance and Institutional Framework
Applies to: State bodies and specified organizations in Kazakhstan.
“required each ministry, agency and specified organisation to establish a data governance structure”
- #2CriticalDefinitions
Applies to: State bodies and specified organizations in Kazakhstan.
“The definitions aligned these roles to existing public-sector organisational structures to enable assignment of responsibilities”
- #3CriticalGovernance and Institutional Framework
Applies to: State bodies and specified organizations in Kazakhstan.
“Entities were directed to maintain a centralized inventory/catalog of datasets”
- #4CriticalKey Focus Areas
Applies to: State bodies and specified organizations in Kazakhstan.
“Data inventory and classification rules required entities to catalogue datasets and label them by sensitivity, criticality and retention.”
- #5CriticalKey Focus Areas
Applies to: State bodies and specified organizations in Kazakhstan.
“Access management provisions mandated role-based access controls, authentication and authorization mechanisms”
- #6CriticalKey Focus Areas
Applies to: State bodies and specified organizations in Kazakhstan.
“Access management provisions mandated... logging and auditing of data access.”
- #7CriticalKey Focus Areas
Applies to: State bodies and specified organizations in Kazakhstan.
“Data-sharing provisions required formal agreements, purpose limitation clauses, and safeguards for transfers”
- #8CriticalKey Focus Areas
Applies to: State bodies and specified organizations in Kazakhstan.
“Security controls required technical measures (encryption at rest/in transit, network segmentation, secure backups)”
- #9CriticalKey Focus Areas
Applies to: State bodies and specified organizations in Kazakhstan.
“organisational measures (incident response plans, staff training).”
- #10CriticalKey Focus Areas
Applies to: State bodies and specified organizations in Kazakhstan.
“The Order also required reporting of breaches and incidents to designated supervisory authorities”
- #11CriticalRelationship to Other Instruments
Applies to: State bodies and specified organizations in Kazakhstan.
“Where personal data or sector-specific rules applied, those instruments retained primacy”
- #12ImportantGovernance and Institutional Framework
Applies to: State bodies and specified organizations in Kazakhstan.
“Entities were directed to... publish metadata to facilitate discovery and authorized reuse.”
- #13ImportantKey Focus Areas
Applies to: State bodies and specified organizations in Kazakhstan.
“organisational measures (incident response plans, staff training).”
- #14ImportantImplementation Framework
Applies to: State bodies and specified organizations in Kazakhstan.
“Entities were required to prepare internal regulations and schedules aligned to the Order”
- #15ImportantKey Focus Areas
Applies to: State bodies and specified organizations in Kazakhstan.
“Data quality and validation rules required entities to set quality metrics, monitor completeness and correctness”
Related Regulations
Order of the Minister No. 90/NQ (23 February 2024) — On Amendments and Additions to Order No. 385/NQ (О внесении изменений и дополнения в приказ Министра от 14.10.2022 №385/НҚ)
Kazakhstan94% similar
Order of the Minister No. 691/NQ (11 November 2024) — On Recognition as Having Lost Force of Prior Orders No.385/NQ and No.90/NQ
Kazakhstan92% similar
Закон Республики Казахстан от 24 ноября 2015 года № 418-V «Об информатизации»
Kazakhstan87% similar
Қазақстан Республикасының «Дербес деректер және оларды қорғау туралы» Заңы
Republic of Kazakhstan85% similar
Цифровой кодекс Республики Казахстан
Kazakhstan84% similar
© Regulations.AI — created on 13-Jun-2026