Skip to main content

Only about 1% of personal data protection complaints reach court each year.

Submitted by Gorin_S on
personalnye dannye

It is possible to register an LLC in Kazakhstan in just one day, even on a weekend. But within a few hours, the new phone number provided during registration on eGov starts ringing: first the bank, then its associated insurance company, then organisations claiming to be fire safety bodies warning of inspections by the Ministry of Emergency Situations. A week later, the same number ends up in the call databases of "stockbrokers". When asked where the data comes from, the standard reply is unchanging - "the computer collects it". So where do the personal details of newly registered businesses leak to, and why is essentially no one held accountable for this? 

FACTUAL BASIS

After registering a new limited liability partnership (LLP), entrepreneurs often encounter a wave of intrusive phone calls. Representatives from various organisations offer to arrange accreditation, certificates, or mandatory training, warning that otherwise inspections by state bodies are possible.

One such organisation is, for example, a structure presenting itself as the "Qualification Commission for Fire and Technical Safety under the Centre for Labour Protection and Safety". As it turned out, this name conceals an ordinary LLP. During the conversation, the operator claimed that the details about the new company, whose director received the call, were obtained from the Ministry of Emergency Situations of the Republic of Kazakhstan, and insisted on arranging a certificate, citing possible inspections by the department.

Interestingly, all these dubious manipulations of private business data - data which, as it turns out during the conversation, is obtained from state bodies themselves - occur against the backdrop of claims that leaks from state databases almost never happen. This was stated on 21 July at a briefing in the Central Communications Service (CCS) under the President of the Republic of Kazakhstan by the Vice-Minister for Artificial Intelligence and Digital Development, Doszhan Musaliyev. According to him, the source of leaks is more often private businesses - beauty salons, educational institutions, travel agencies, shops, and online services - rather than state databases. 

INFORMATION SECURITY PROBLEMS IN THE COUNTRY 

At the same briefing, a journalist from FBKK asked representatives of the Committee on Information Security of the Ministry of Artificial Intelligence and Digital Development of the Republic of Kazakhstan (MAIDD RK) where private companies obtain information about a newly registered business. 

The Deputy Chairperson of the Committee, Umizhan Arykbekova, acknowledged that "the internal procedures of some companies allowed for such instances [transfer of personal data - ed. note FBKR]", and suggested filing complaints about these facts through the e-Otinish system.
 


According to her, the committee receives around 9,000 requests annually on issues of information security and personal data protection. When asked by the editorial staff how many such cases reached court, the figure given was 180 cases over two years - and this only covers administrative cases directly related to personal data. In other words, only about 1% of the total number of requests ever reach court each year.

Incidentally, the editorial team of FBKR has itself encountered similar cases where formal mechanisms for protecting personal data and holding violators accountable exist, but the case never actually progresses. In 2025, the editor-in-chief of FBKR filed a complaint regarding the unlawful use of her personal data by a private company - the complaint received from this organisation included her full name, IIN, registered address, and phone number, even though there had been no contact with the company or consent for data processing. After a month and a half, the investigation had effectively made no progress, and the case was plagued by procedural violations and seemingly endless redirection between departments. This directly illustrates what "180 cases over two years" means in practice: even a formal complaint from a specific victim can remain stagnant for years.

On the positive side, from 12 July, a "digital events" service became available on eGov, where citizens can see which state bodies have accessed their information. According to Arykbekova, second-tier banks and organisations integrated with eGov are already connected to the service, and in the future, MAIDD plans to extend it to larger organisations upon request via the Smart Bridge
 


WHAT THE MINISTRY OF EMERGENCY SITUATIONS SAYS 

In parallel, the FBKR editorial team sent an official inquiry to the Ministry of Emergency Situations of the Republic of Kazakhstan, and here the second part of the problem emerges - the quality of departmental communication. When asked directly whether the ministry is aware of cases where commercial organisations, including the aforementioned LLP "Centre for Labour Protection and Safety", cite the Ministry of Emergency Situations as the source of business information, the department essentially evaded the answer. The Ministry of Emergency Situations' response merely states that services under the fire-technical minimum (FTM) programme "operate in a competitive environment" and "can be provided by any training organisation".

It is telling that this same paragraph is almost verbatim repeated in the response to another, substantively different question - whether it is permissible for private organisations to warn entrepreneurs about inspections by civil protection bodies, thereby promoting their own services. Identical wording for two different questions is a clear indication that the department preferred not to provide any substantive assessment of the practice itself, limiting itself to a general reference to the market for training services. Whether they are aware of these issues remains a matter of speculation. 

However, the Ministry of Emergency Situations did answer the legal question substantively. According to paragraphs 9 and 11 of Article 28 of the Entrepreneurial Code of the Republic of Kazakhstan, state bodies are not entitled to transfer information constituting the commercial secret of a business entity to third parties, and liability and compensation for damages are provided for unlawful dissemination. That is, the ministry itself confirms that the law does not allow the transfer of data about registered companies to private entities. But when asked how this protection is ensured technically (if the ministry, by its own account, "can obtain information about the registration of legal entities" through information exchange with state bodies), there was again no answer. It was only stated that "data is provided upon request", without describing the mechanisms for controlling its further use.

WHAT THIS MEANS 

The story of calls to new companies is no longer just about a few pushy certificate sellers. It is a test of how well Kazakhstan's stated personal data protection mechanisms actually work.

The picture is contradictory. On the one hand, the state talks about digitalisation, information security, and data protection, launches new services for controlling access to information, and reminds us of liability for the unlawful dissemination of data. On the other hand, an entrepreneur finds themselves in the sights of dozens of commercial companies almost immediately after registering their business, some of whom do not hesitate to cite possible inspections by the Ministry of Emergency Situations and even claim to have received the information from the ministry itself.

The Ministry of Emergency Situations itself did not confirm such claims, but neither did it refute them substantively. Instead of answering the question, our editorial team received general explanations about the competitive market for educational services. Yet it is precisely the authority of a state body that becomes the main argument in conversations with entrepreneurs.

While departments limit themselves to general statements, and thousands of complaints about personal data violations result in only a handful of court cases, the market continues to operate by its own rules. And no matter how much the state talks about digital security, the main indicator remains practice. Today, practice shows that the data of new businesses ends up with private companies far too quickly, and the origin of this information and accountability for its use continue to lack clear answers.

Наша редакция участвует в партнёрской сети «Все СМИ».