Kazakhstan - Data Management Amendments (90/NQ)

Order of the Minister No. 90/NQ (23 February 2024) — On Amendments and Additions to Order No. 385/NQ (On Amendments and Additions to the Ministerial Order of 14.10.2022 No. 385/NQ)

Приказ Министра № 90/NQ (23 февраля 2024 года) — О внесении изменений и дополнения в приказ № 385/NQ (О внесении изменений и дополнения в приказ Министра от 14.10.2022 №385/НҚ)

Kazakhstan

RAI-KZ-NA-OMN92XX-2024
Repealed(Repealed)
RegulationGovernance and OversightData Protection and PrivacyAccountability and Documentation
Export PDF

Order No. 90/NQ (23 February 2024) amends and supplements Ministerial Order No. 385/NQ (14 October 2022) that establishes the "Requirements for Data Management" for public-sector bodies. The amendments clarify the scope of application, add and revise detailed definitions (including roles such as data steward/CDO and new terms such as SDU and data catalog), prescribe obligations for cataloguing and anonymization, and set operational requirements for interaction with the Smart Data Ukimet (SDU) platform. The order was registered on 26 February 2024 and later repealed by Ministerial Order No. 691/NQ on 11 November 2024.

Overview

Order No. 90/NQ of 23 February 2024 amends and supplements Ministerial Order No. 385/NQ of 14 October 2022 that approves the "Requirements for Data Management" for public-sector organizations in Kazakhstan. The Order was registered with the Ministry of Justice on 26 February 2024 (registration No. 34051) and published in the reference legal database; it clarifies applicability, strengthens governance roles and duties (introducing and elaborating roles such as "data steward" and CDO), prescribes mandatory data cataloguing and passporting processes and formalizes the operational integration of organizational information systems with the national Smart Data Ukimet (SDU) environment. The official consolidated text and appendices are available in the state legal systems: zakon.uchet.kz (consolidated text) and Adilet. The Order was later rescinded by Ministerial Order No. 691/NQ of 11 November 2024 (entered into force ten calendar days after publication), which repealed both the 2022 Requirements and these 2024 amendments.

Definitions

The 90/NQ amendments expand and standardize core terminology used throughout Kazakhstan's public-sector data governance framework. Definitions added or revised include: "data" (information in a formalized form), "data owner", "data steward" (responsible official for compliance and in-organization data management), "officer on data", "CDO" (Chief Data Officer), "data catalog" and "data passport" (standardized metadata/description forms), "Smart Data Ukimet (SDU)" (a unified data repository/analytic environment), "anonymization" and "pseudonymization", "etalon (reference) data", "non-digitized data" and "digitized data", processes ETL and CDC, and clear definitions of data quality and its measurement criteria (uniqueness, accuracy, integrity, timeliness, consistency, completeness). These definitions are intended to align legal wording with technical practice and are published in the consolidated Order text. See the official appendices for the sample passport and non-digitized data description forms in the published Order: Order No. 90/NQ (full text and appendices).

Governance and Institutional Framework

The Order emphasizes a multi-actor governance model. The primary obligations fall on state bodies, state-owned legal entities and quasi-state sector entities (with certain carve-outs, e.g., National Bank and similar organizations). Key roles created or defined include: the data owner (legal title/rights holder), the data steward (responsible official within an organization for policy compliance, catalog completion, internal verification and coordination), the operator (entity tasked with maintaining the "electronic government" information-communication infrastructure), and the service integrator (responsible for architectural and technical support of the government's data catalog and integration). The Order places coordination and cross-sectoral leadership authority on the authorized central executive body (the "authorized organ" for data management) while assigning concrete operational tasks to the operator and service integrator. The ministry and the operator are also required to ensure required security measures, register integration services in service registries, and provide methodological and technical support to organizations. The Ministry of Digital Development, Innovations and Aerospace Industry is the issuing authority; information about the ministry and its responsibilities is available at the government portal: Ministry page (gov.kz). The formal legal texts are published and accessible via national legal information systems: Adilet and zakon.uchet.kz.

Key Focus Areas

The amendments address multiple interlocking subject-matter areas: (1) Scope and Applicability — clarifying which public bodies and quasi-state entities must apply the Requirements (and noting exceptions); (2) Metadata and Cataloguing — mandatory formation and maintenance of a centralized data catalog containing standardized data passports and descriptions for non-digitized data; (3) Data Quality — establishment of criteria and processes for measuring and improving data quality (with concrete indicators such as uniqueness, accuracy, timeliness and consistency); (4) Integration with National Platforms — operational procedures, roles and deadlines for integrating organizational systems with the SDU, including operator-led anonymization where necessary; (5) Roles and Accountability — introduction and detailing of roles (data steward, CDO, officer on data) and their responsibilities (monitoring, internal control, verification with SDU, creation of internal acts and staff training); (6) Reference/Etalon Data — designation and governance of authoritative sources used for cross-system reconciliation; (7) Security and Anonymization — technical and procedural obligations to anonymize or pseudonymize data before inclusion in SDU, and the use of ETL/CDC approaches; and (8) Publication and Transparency — requirements for publishing data passports and statistics of data use on the architectural portal of "electronic government". These changes were supported by the addition of standardized templates (Appendices 1 and 2) for data passports and for describing non-digitized data to ensure uniform implementation across agencies (see published appendices in the official text: Order No. 90/NQ text and appendices).

Implementation Framework

The Order sets a practical implementation framework with assigned short-term deadlines for technical interactions between organizations and the operator/service integrator (for example, the operator must request table and field descriptions within five working days and prepare interaction regulations within five working days; organizations then have five working days to approve). It requires organizations to complete data passports and descriptions prior to placing information systems into production and mandates automated publication of usage statistics on the architectural portal. The operator and service integrator have explicit duties: ensuring the technical ability to form and maintain passports and non-digitized descriptions on the architectural portal; providing technical and methodological support; ensuring access controls and security of catalog content in line with unified ICT and information security requirements; notifying the operator about passports prepared with read-only access on the data catalog; and configuring anonymization via ETL tools when organizations cannot perform anonymization themselves. The Order therefore mixes legal/regulatory obligations with implementation-level timebound technical tasks to accelerate practical operationalization of national data architecture (see the order text and appendices at Adilet and zakon.uchet.kz).

Monitoring and Evaluation

Monitoring provisions require data stewards to oversee compliance, conduct internal verification of SDU entries against local systems and ensure timely submission of indicators to SDU. The Order instructs the collection and publication of automated statistics on dataset access on the architecture portal and assigns the authorized organ and operator specific notification and verification duties. Data quality evaluation may be performed proactively by data users and, for statistics purposes, by the authorized statistical body per referencing rules in the Order. The declared approach intends to enable continuous quality monitoring, identification of inconsistencies against etalon data sources and corrective actions to harmonize conflicting records. The official text provides that non-conformance on core quality indicators is grounds to consider data unreliable and triggers remediation actions (see formal provisions: full text).

Penalties, Liability, and Appeals

The Order principally prescribes obligations, processes and timelines rather than establishing new monetary fines or criminal penalties; enforcement and liability for non-compliance are generally governed by other applicable laws and administrative codes of the Republic of Kazakhstan. Practical enforcement mechanisms visible in the Order include formal duties to complete and maintain passport entries, to comply with operator/service integrator interaction rules and to ensure anonymization where required. Because the Order was administrative and technical in nature, the primary enforcement route was administrative oversight by the authorized organ and potential application of existing administrative procedures or disciplinary measures. The Order itself was later repealed by Ministerial Order No. 691/NQ dated 11 November 2024 (entered into force after publication), which effectively removed these specific 2024 amendments from force; the repeal is recorded in official registries (see repeal notice on Adilet (No. 691/NQ) and registry notes at zakon.uchet.kz).

Relationship to Other Instruments

Order No. 90/NQ amends and operates as a subordinate regulatory act under the framework of the Requirements originally approved by Order No. 385/NQ (14 October 2022). It cross-references other ministerial acts including the 2019 Order No. 193/NQ on formation and monitoring of the "electronic government" architecture and interacts with statutory authorities responsible for national statistics, information security, and regulated sectors (e.g., National Bank carve-out). Subsequently, a Government-level act (November 2024 Governmental documents on Requirements for Data Management) and Ministerial Order No. 691/NQ (11.11.2024) superseded or repealed the ministerial-level acts. Key related instruments and consolidated texts are accessible via national legal information systems: Order No. 385/NQ (Adilet), Order No. 90/NQ (Adilet), and the repeal instrument Order No. 691/NQ (Adilet).

International Alignment

The amendments reflect international data-governance practices: role-based stewardship (CDO/data steward), centralized metadata/cataloguing, data quality metrics and standards for anonymization/pseudonymization. While the text is a domestic ministerial instrument, its approaches mirror OECD and EU trends toward data catalogs, provenance, metadata standards and privacy-preserving analytics. The Order’s focus on etalon/reference data and formalized inter-system reconciliation aligns with international best practices for authoritative registers. For comparative context and the Order’s public publication see: zakon.uchet.kz and Adilet.

Implementation Timeline

EventDate / Notes
Order adopted2024-02-23
Registered with Ministry of Justice2024-02-26 (Reg. No. 34051)
First official publication (reference bank)2024-02-28
Operator/service integrator short operational deadlines (examples)Operator requests table/field descriptions within 5 working days; operator drafts interaction regulation within 5 working days; organization approves within 5 working days (operational requirements set in Order)
Order repealed by Ministerial Order No. 691/NQ2024-11-11 (entered into force 10 calendar days after publication)

Compliance Checklist

ActionResponsibleNotes
Identify whether organization is covered by RequirementsOrganization leadership / legalPublic bodies, state legal entities, quasi-state sector (exclusions apply)
Appoint data steward / officer on dataOrganizationAssign responsibilities per Order (monitoring, passport coordination, training)
Complete data passports and non-digitized descriptionsOrganization / Data stewardUse templates in Appendices 1 & 2
Submit descriptions to Data Catalog and notify operatorOrganization / Service integratorEnsure read-only access on Data Catalog as required
Implement anonymization procedures before SDU uploadOrganization / OperatorOperator to provide algorithms/instructions; may perform anonymization via ETL if org unable
Ensure data quality per metricsOrganization / Data stewardMeasure uniqueness, accuracy, timeliness, consistency, completeness

Sources and References

SourceType
О внесении изменений и дополнения в приказ № 385/НҚ (Consolidated text, Order No. 90/NQ)Primary Source
Adilet: Order No. 90/NQ (registered text and appendices)Primary Source
Adilet: Order No. 385/NQ (original Requirements for Data Management, 14.10.2022)Primary Source
Adilet: Order No. 691/NQ (repeal instrument, 11.11.2024)Primary Source
Plain English

This Kazakhstan regulation, Order No. 90/NQ, updated how public-sector bodies and state-affiliated organizations manage their data, though it was quickly superseded. It applied to government agencies, state-owned legal entities, and quasi-state sector organizations, with some exceptions like the National Bank. The order, which took effect on February 28, 2024, introduced several key requirements aimed at standardizing data practices across the public sector.

Organizations were mandated to: - Create and maintain a centralized data catalog, including standardized "data passports" and descriptions for non-digitized information. - Formally integrate their information systems with the national Smart Data Ukimet (SDU) platform, which involved specific operational procedures and, where necessary, anonymizing or pseudonymizing data before submission. - Establish clear criteria and processes for measuring and improving data quality, focusing on aspects like uniqueness, accuracy, and timeliness. - Define new roles such as "data steward" and Chief Data Officer (CDO) within organizations, assigning them responsibilities for compliance, internal verification, and staff training.

While the regulation prescribed detailed obligations and timelines for technical interactions, it did not introduce new monetary fines or criminal penalties. Instead, enforcement relied on existing administrative oversight and potential disciplinary measures. A significant practical point for any affected entity is that Order No. 90/NQ had a short lifespan; it was repealed on November 11, 2024, by a subsequent Ministerial Order No. 691/NQ, which also rescinded the original 2022 data management requirements it amended. This means its specific provisions were in force for less than nine months.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 11 marked complete

Plain-English obligations under Kazakhstan - Data Management Amendments (90/NQ). Not legal advice — verify against the official text before relying on it.

  1. #1Critical

    Applies to: Public sector organizations in Kazakhstan.

    introduction and detailing of roles (data steward, CDO, officer on data) and their responsibilities
  2. #2Critical

    Applies to: Public sector organizations in Kazakhstan.

    mandatory formation and maintenance of a centralized data catalog
  3. #3CriticalBefore placing information systems into production

    Applies to: Public sector organizations in Kazakhstan.

    mandatory formation and maintenance of a centralized data catalog containing standardized data passports
  4. #4Critical

    Applies to: Public sector organizations in Kazakhstan.

    formalizes the operational integration of organizational information systems with the national Smart Data Ukimet (SDU) environment.
  5. #5CriticalBefore inclusion in SDU

    Applies to: Public sector organizations in Kazakhstan.

    technical and procedural obligations to anonymize or pseudonymize data before inclusion in SDU
  6. #6Critical

    Applies to: Public sector organizations in Kazakhstan.

    ensuring access controls and security of catalog content in line with unified ICT and information security requirements
  7. #7Important

    Applies to: Public sector organizations in Kazakhstan.

    establishment of criteria and processes for measuring and improving data quality
  8. #8Important

    Applies to: Public sector organizations in Kazakhstan.

    Designation and governance of authoritative sources used for cross-system reconciliation
  9. #9Important

    Applies to: Public sector organizations in Kazakhstan.

    requirements for publishing data passports and statistics of data use on the architectural portal
  10. #10Important

    Applies to: Data stewards within public sector organizations.

    data stewards to oversee compliance, conduct internal verification of SDU entries
  11. #11Important

    Applies to: Public sector organizations in Kazakhstan.

    notifying the operator about passports prepared with read-only access on the data catalog

© Regulations.AI — created on 13-Jun-2026