PDF (Russian)

Keywords

personal data, Republic of Kazakhstan, artificial intelligence, legislation, cross-border data transfer, data protection impact assessment (DPIA), biometrics

How to Cite

PROBLEMS OF LEGAL REGULATION AND PROSPECTS FOR IMPROVING THE LEGISLATION OF THE REPUBLIC OF KAZAKHSTAN IN THE FIELD OF PERSONAL DATA PROTECTION. (2026). VERITAS LEGIS JOURNAL, 2(2). https://doi.org/10.62687/VLJ.2.2.2026.50

Abstract

The implementation of artificial intelligence, the advancement of digital technologies, and the systematic analysis of big data have significantly increased the importance of personal data protection and the improvement of legal regulation in this field. This study examines the challenges associated with the application of personal data protection legislation and evaluates its compliance with international legal standards.

The primary objective of this research is to identify legal inconsistencies and gaps that hinder the effective realization of citizens’ constitutional rights and the protection of their privacy, as well as to develop proposals for improving the existing legal framework. To achieve this objective, the following tasks were undertaken:

– conducting a comparative analysis of domestic and foreign legal practices;

– examining the regulation of automated data processing, the use of biometric data, and the cross-border transfer of personal data.

The findings indicate that the current legislation does not fully ensure the protection of citizens’ rights and fails to adequately address the challenges posed by modern digital technologies. The study revealed the absence of data protection impact assessment mechanisms, as well as insufficient regulation of biometric and behavioral data processing. These shortcomings are largely attributable to the existence of referral provisions that lack effective implementation mechanisms, as well as legislative gaps in this area.

The study concludes that improving the personal data protection framework requires the development of a comprehensive risk-based model of legal regulation. Key recommendations include the introduction of Data Protection Impact Assessment (DPIA) procedures, the establishment of clear rules governing cross-border data transfers, and the strengthening of the institutional role of the authorized state body responsible for personal data protection.

PDF (Russian)

References