Business & Technology 22.09.2026 ~10 min read

Digital Code of the Republic of Kazakhstan 2026: What Changes for Businesses

Since July 11, 2026, companies in Kazakhstan operate under the new Digital Code. This is not just a formality, but a significant change for everyone dealing with data and technology. How is business adapting to the new rules?

Digital Code of the Republic of Kazakhstan 2026: What Changes for Businesses

Digital Code of the Republic of Kazakhstan 2026: What Changes for Businesses

On January 9, 2026, the President signed the Digital Code of the Republic of Kazakhstan (No. 255-VIII), and on July 11, 2026, the document came into force. It is the first collection in the CIS that consolidates the regulation of data, artificial intelligence, digital rights, and cybersecurity — areas that were previously scattered across dozens of separate laws. For businesses, this is not an abstract reform happening "somewhere up there": since this summer, any company with a website, CRM, customer database, or cloud service falls under the new rules. And most are finding out about this post factum.

At West Star Ltd, we work with client data every day — 1C integrations, CRM, AI services, cloud deployments — and our practice shows that digital regulation almost always outpaces companies' readiness for it. Therefore, let's analyze specifically and without legal fog: what the Digital Code of the Republic of Kazakhstan really changes, what obligations businesses have acquired, and what should be done first to avoid a directive or service blockage.

What is the Digital Code of the Republic of Kazakhstan and Why Does Business Need It

Until 2026, the digital sphere in Kazakhstan was regulated by a mosaic: the law on personal data, the law on informatization, separate acts on electronic documents, communications, and public services. Norms were duplicated, sometimes contradicted each other, and businesses had to piece together requirements. The Digital Code consolidated this into a single logic: digital data, digital objects, rights, and obligations of participants in the digital environment are described in one document with common principles.

The key idea of the code is the transition from point solutions to systemic digital transformation built on security, responsibility, and protection of citizens' rights. Detailed regulation of artificial intelligence is allocated to a separate AI Law, to which the code directly refers. Thus, we now have a bundle of several acts that need to be read together — and it is precisely at the intersections that most practical questions arise.

For a company owner, it is important to understand one thing: the code is not only addressed to IT giants. It applies to an online store with an order form, a dental clinic with online booking, a recruitment agency with a resume database, any SaaS. If you collect, store, or process people's data — you are subject to this regulation. And the sooner a business realizes this, the cheaper it is to bring processes in order: reforming calmly is always easier than putting out a fire after a directive.

Localization, AI, and Cybersecurity: Three Main Requirements

Data localization is the most expensive in practice. Personal data of Kazakhstan citizens must be stored on the territory of the Republic of Kazakhstan (or in countries with an adequate level of protection). The requirement applies to everything at once: websites, CRM, client databases, email newsletters, cloud solutions. And — critically — even an international company falls under it if it serves clients in Kazakhstan. "We just keep the database on a European cloud" no longer works by default.

In practice, you will have to answer uncomfortable questions: where are client data physically located, where is the CRM deployed, where does the feedback form on the website write to, which third-party services (analytics, newsletters, chatbots) export personal data outside the country. The consequences of non-compliance are tangible. Violations in handling personal data are classified as administrative (Article 79 of the Code of Administrative Offenses of the Republic of Kazakhstan), and for violation of localization, directives from the authorized body and — in extreme cases — blocking of the site or service on the territory of Kazakhstan are possible. For a business whose website is the main sales channel, this is a direct hit to revenue.

This is where the main work lies: conducting a data inventory, determining what falls under localization, and transferring storage to the Kazakhstan circuit without losing business processes. This is exactly what we do within the framework of automation and integration of 1C — moving data is rarely "copy and forget", especially when CRM, accounting system, and website are interconnected by a single exchange chain.

How this looks in practice is easier to show with a typical example. Let's take a regular online store in Kazakhstan: applications from the site fall into CRM, from there they go to 1C, receipts are sent to clients by email through a foreign newsletter service, and web analytics is collected by a third-party script with servers abroad. Formally, client data in this chain crosses the border at least twice — on the newsletter and analytics. Bringing such a bundle in order does not mean rewriting everything from scratch, but precisely replacing or fine-tuning links: transferring the database and accounting system to a Kazakhstan cloud, selecting a local newsletter service, or leaving only anonymized data where permissible. Most often, processes for the user do not change at all — what changes is where data physically resides and how it is transmitted between systems.

Artificial intelligence is now under rules. The code and the accompanying AI Law establish basic principles for working with AI: ethics, transparency, non-discrimination, and human control over decisions. The right to deletion is separately prescribed: if a user demands to delete their data, the AI model cannot be further trained on this data. For businesses, this is not philosophy but specific obligations. If you have a chatbot on the first line of support, AI scoring of applications, a recommendation system, or a voice assistant — you must ensure transparency (a person should understand that they are interacting with an algorithm), the ability to appeal an automatic decision, and correct processing of data deletion requests.

We take this into account when implementing AI solutions: any automatic scenario must have a "handle" for the operator and a clear logic. The code essentially enshrined what is already good engineering practice — but now for the absence of human control, you can receive a complaint not from a client, but from the regulator. How to build AI solutions so that they are both useful and compliant with requirements is a topic we have covered in detail in materials on data security when working with artificial intelligence.

Cybersecurity and data turnover. The code establishes framework requirements for information protection and incident notification. An important nuance: specific deadlines and notification procedures are set by subordinate acts, and from the wording, it is clear that the windows will be tight — industry experts are oriented towards a daily order. The company must have a pre-written regulation: who records the incident, who and within what timeframes notifies, how logs are stored. Simultaneously, the code opens new opportunities — for the first time, a platform for the exchange of digital data products is introduced, a legal mechanism to formalize and implement anonymized analytics. For a company with accumulated data arrays, this is a chance to monetize them correctly, not in a gray zone. And from July 12, 2026, the rules for digital condominiums came into effect — the digitalization of property management received its own legal framework.

It is also worth remembering the broader context: 2026 is a year of regulatory reboot in general. Alongside the digital reform, a new Tax Code with a VAT rate of 16% and a registration threshold of 10,000 MRP came into effect. Companies that are already restructuring accounting and processes for tax changes logically close digital compliance with the same approach, rather than two separate emergencies — data, accounting, and integrations usually live in the same systems.

Limitations and Pitfalls

An honest conversation about the code cannot be only enthusiastic. There are several areas where practice will be painful, and it is better to know about them in advance.

  • Much is delegated to subordinate acts. The code sets the framework, but exact notification deadlines, formats, and some requirements will appear in subordinate documents after coming into force. Until they are adopted, part of the obligations has to be interpreted "in advance", with a margin.

  • Collisions between acts. The Digital Code, the AI Law, the current law on personal data, and the Tax Code coexist and sometimes overlap. "Digital compliance" is reading several documents together, and there is no unequivocal answer to every question yet.

  • Cost of localization for small businesses. Transferring data to the Kazakhstan circuit, changing the cloud, reworking integrations — this is money and time. For a large company, this is a budget item, for a small one — a noticeable burden, which not everyone is ready for.

  • Practice of law enforcement is not yet formed. The code is new, there is almost no judicial and supervisory practice. How exactly the regulator will measure "adequate protection" in another country or interpret AI transparency will be shown by the first cases, not the text of the law.

  • Risk of a formal approach. It's easy to hire a responsible person "for show", write a policy, and forget about it. The code requires not papers, but actually working processes — and it is the live processes that the regulator will ultimately check.

  • Gray areas with foreign services. Analytics, newsletters, payment, and cloud services that export data abroad will have to be reviewed one by one. Not all popular tools have a Kazakhstan circuit, and here businesses face a choice between convenient and legal.

What to do with all this depends on the role. A technical specialist should start with an inventory: create a map of where personal data is stored, which integrations export it outside, where AI operates without human control in the product. A manager should appoint a responsible person for data not formally, but with authority, and budget for storage transfer and incident response regulation. An owner should perceive this not as another bureaucracy, but as risk reduction: a blocked site or leak costs more than careful preparation. The Digital Code did not make business life more complicated — it made transparent the risks that were already there, just previously unspoken. Those who treat it not as a threat but as a checklist that has long been overdue to pass win.

Frequently Asked Questions

When did the Digital Code of the Republic of Kazakhstan come into force?

The code was signed on January 9, 2026 (No. 255-VIII) and came into effect on July 11, 2026 — six months after publication. Some related norms, such as the rules for digital condominiums, came into effect on July 12, 2026. However, a number of detailed requirements will be clarified by subordinate acts after the code comes into force.

Do I need to transfer CRM and client databases to Kazakhstan?

If they store personal data of citizens of the Republic of Kazakhstan — in most cases, yes. The localization requirement applies to websites, CRM, client databases, newsletters, and cloud services. Start with an inventory: understand where data is physically located and which third-party services export it outside the country, and only then plan the transfer to the Kazakhstan circuit.

How does the Digital Code regulate artificial intelligence?

The code, along with a separate AI Law, establishes principles of ethics, transparency, non-discrimination, and human control over decisions. In practice, this means that automatic systems must be explainable, AI decisions appealable by a human, and user data that demanded deletion cannot be further used for model retraining.

What are the consequences of violating data localization?

Violations in handling personal data are classified as administrative (Article 79 of the Code of Administrative Offenses of the Republic of Kazakhstan). For non-compliance with localization, directives from the authorized body are possible, and in extreme cases — blocking of the site or service on the territory of Kazakhstan. For companies whose website is the main sales channel, this is a direct financial risk, so preparation is better not postponed.

Business & Technology цифровой кодекс РК
Share Article

Comments (0)

No comments yet. Be the first!

Need 1C Integration?

We implement integration using Django + 1C OData API. Contact us for a free consultation.

Discuss Project