How to store personal data in Kazakhstan
A practical guide to storing personal data in Kazakhstan: where databases and backups belong, how to assess cloud services, and what proves compliance.

The localization requirement does not force every organization to build its own server room. It does require the organization to know the precise physical location of the database containing personal data, where copies appear, and under what conditions other parties can access them.
The most common mistake starts with the statement, "Our primary database is in Almaty." Ten minutes later, it turns out that nightly snapshots go to a foreign region, the support team exports tables to a global service, and the test environment receives a production copy once a month. The address of the primary server proves nothing in that situation. Compliance depends on the entire chain of storage and processing.
This guide covers the general infrastructure logic and does not replace legal advice for a specific industry. Government systems, financial organizations, critical infrastructure facilities, and certain categories of information may be subject to extra rules.
The law requires a local database, not your own room
Article 12 of the Law of the Republic of Kazakhstan "On Personal Data and Their Protection" states the basic rule directly: the owner, operator, or third party must store personal data in a database located in the Republic of Kazakhstan. The text does not require ownership of the building, rack, or server. An in-house server room, rented rack space in a data center, and cloud infrastructure can therefore meet the rule if the database is physically located in Kazakhstan and the other obligations are met.
The Rules for Implementing Measures to Protect Personal Data add detail to this provision. Paragraph 9 refers to an electronic database in a server room or data center located in Kazakhstan. Paragraph 8 requires restricted-access personal data to be collected and processed through information systems located in the country. For a normal corporate system, this means a local disk copy is not enough when the working application and the actual processing are abroad.
The law distinguishes the database owner, the operator, and a third party, but localization does not disappear when work is outsourced. If a provider operates the HR system, the organization cannot rely on a general promise to "comply with applicable law." It needs the physical addresses of the facilities, a description of replication, a list of subcontractors, and a contractual right to obtain evidence.
Another distinction often gets lost during procurement. A "Kazakhstani provider" and "infrastructure in Kazakhstan" are not the same thing. A local legal entity may use a foreign region of a global cloud, while a foreign provider may place equipment in a Kazakhstani data center. Check the data path and equipment location, not the brand's country of registration.
Personal data exists far beyond the primary table
The localization scope includes all stored information that can identify a person, not just columns containing an individual identification number and full name. A passport copy in file storage, a phone number in a support log, a customer address in a message queue, and an employee identifier in an export may all remain personal data. Encryption reduces the risk of access, but it does not make the information anonymous by itself.
When I assess infrastructure, I trace one record from the input form through final deletion. That path usually reveals the primary database, a synchronous replica, search index, cache, attachment storage, queue, application log, virtual machine snapshots, backups, and analyst exports. I check test environments, administrator laptops, email attachments, and diagnostic bundles sent to support separately.
A typical failure unfolds like this. A company chooses a local server for its CRM and produces a rack rental agreement. Under the provider's default settings, the backup agent stores encrypted snapshots in a default region outside Kazakhstan. A developer copies part of the database into a foreign error analysis service, while support receives a full dump through a file-sharing service. A local CRM formally exists, but the actual storage design no longer matches the company's policy or consent wording.
Technical values do not all require the same treatment. Truly aggregated statistics that cannot isolate a person differ from a pseudonymized table where a code can be linked through a separate lookup table. The field customer_8472 has not become anonymous if the same team holds the mapping. Getting this boundary wrong leads organizations to send a dataset abroad that they call anonymized even though reidentification remains a normal working operation.
A backup is also a storage location
A backup contains the same personal data, so the defensible working position is simple: keep backups containing that data in Kazakhstan. The law does not grant backups a separate privileged category. If a copy is retained and can restore records about people, the organization should include it in its database map and location evidence.
A local backup beside the primary server answers the geography question but does little for resilience. A fire, flood, storage failure, or administrator account can damage both copies. A practical design keeps an operational replica and a backup at separate facilities within the country, sets retention according to the purposes of processing, and tests restoration regularly. Geographic separation does not have to cross a national border.
The Protection Rules require cryptographic protection when storing and transferring restricted-access personal data, with parameters that meet the level of ST RK 1073-2007 specified in the Rules. A checkbox that says "encryption enabled" is not enough. Documentation should identify the product, mode, key location, administrator group, rotation procedure, and behavior during restoration.
Testing a backup without restoring it creates false confidence. A successful job status confirms that the program wrote some volume of data, but it does not confirm completeness, readable keys, or a usable application. A restore test record should show the date, selected restore point, facility, duration, data verification result, and deletion of the temporary restored copy. That record proves that the procedure works and that the test did not create another forgotten store.
Retention matters too. Article 12 ties the storage period to achievement of the purposes of collection and processing unless another period is set by law. A policy that deletes a record from the working database but retains it indefinitely in daily copies contradicts itself. Backups need a clear expiration cycle and a way to carry out blocking or deletion that accounts for the restore architecture.
Cloud use neither removes nor automatically violates localization
The choice between an in-house server room and cloud infrastructure affects control, cost, and the speed of change, but it does not alter the territorial requirement. Cloud compliance depends on the physical location of resources, the actual processing, redundancy, and the evidence the provider will supply.
- An in-house server room gives direct control over equipment and access. Its weaknesses often involve a single site, power, cooling, and unrecorded remote copies. Before procurement, request a room plan, equipment inventory, redundancy design, and the access logging procedure.
- A private rack in a Kazakhstani data center provides facility systems and the option to separate sites. The provider handles the building, but the customer remains responsible for configuration and backups. Record the physical address, division of responsibility, access process, and incident reports.
- A cloud with resources in Kazakhstan can allocate capacity and managed services quickly. Risk appears when service data or copies enter the provider's global systems. Clarify the region for every service, the location of replicas and backups, the subcontractor list, and deletion terms.
- A foreign cloud offers a broad selection of ready-made services, but the working database and processing may end up outside the country. Using it requires a separate legal analysis of cross-border transfer and a local architecture that fulfills Article 12.
A region name in the management console is useful, but it does not finish the assessment. The provider should explain whether the selected region covers the database, object storage, backups, logs, key management service, and diagnostics. The phrase "customer data remains in the region" may exclude account metadata and material that a support engineer creates while investigating a ticket.
Contracts need specific restrictions: storage of named categories at specified facilities in Kazakhstan, no unilateral relocation, approval of subcontractors, an incident notification period, return and deletion after service termination, and access to evidence. A provider's information security management certificate is useful, but it does not prove the address of a particular database instance.
When comparing costs, include more than servers and the monthly cloud bill. An in-house facility needs power, cooling, fire protection, physical access controls, spare parts, and on-call coverage. Cloud infrastructure needs configuration discipline, spending controls, contract review, and an exit plan. A poor server room and an opaque cloud are equally awkward during an inspection.
Cross-border transfer remains a separate decision
Localization and cross-border transfer answer different questions. Article 12 determines where the database is stored, while Article 16 regulates the transfer of personal data to the territory of a foreign state. The possibility of a lawful transfer does not erase the duty to maintain storage in Kazakhstan.
Article 16 permits transfers to states that provide personal data protection in accordance with Kazakhstani law. For a state that does not provide such protection, the law lists grounds that include the data subject's consent, a ratified international treaty, and specific cases provided by law. A single checkbox cannot settle the issue: consent must comply with the collection and processing rules, and sector restrictions or prohibitions still apply.
Remote access by foreign support requires separate analysis. If an engineer views a customer record from another country, receives a dump, or downloads a diagnostic file, the company can no longer describe the process as purely local merely because the disks are in Astana. It must determine whether a transfer occurs, which data is available, the legal ground, how actions are logged, and whether a local team can solve the problem using anonymized material.
A sensible technical boundary sits earlier than the legal dispute. Do not send full records when an external service only needs an aggregate. Keep names, phone numbers, and tokens out of telemetry. Prepare a reproducible test dataset without real people for foreign support, and grant access to production only through an approved procedure for a limited period.
Global SaaS systems need special attention. The provider's office address in Kazakhstan does not reveal the database location, and a contract with a local partner does not change the service architecture. Get a written answer for every data layer before procurement. If the provider will not disclose facilities and copy movement, the organization has nothing it can use to prove compliance.
Architecture starts with a data flow register
A workable design places the system of record for personal data, its applications, replicas, and backups at facilities in Kazakhstan. External services receive only information with a defined purpose, legal ground, and permitted transfer. Administrators connect through a controlled access point, and the system records database events and the actions of users as required by the Protection Rules.
Create one machine-readable record for each dataset. It does not replace legal documents, but it prevents the architecture diagram and the live configuration from drifting apart:
asset: hr_employee_records
owner: HR
purpose: payroll_and_employment
classification: restricted_personal_data
system_of_record:
country: KZ
facility: AST-DC-02
replicas:
- facility: ALA-DC-01
country: KZ
backups:
- facility: ALA-VAULT-01
country: KZ
retention_days: 35
processors:
- role: local_datacenter_operator
cross_border_transfer: false
restore_test: quarterly
last_evidence_review: 2026-06-30
The fields should point to actual agreement, acceptance record, configuration, and responsible person identifiers in your recordkeeping system. Do not copy the example blindly: retention_days, the test interval, and the set of roles must reflect the organization's purposes, risks, and mandatory retention periods.
This record exposes gaps quickly. If an asset lists a primary facility but no replicas, the system owner must prove that replication is disabled rather than assume it. If cross_border_transfer is false, support exports, email, and analytics must also match that statement.
Logs need the same discipline. The Rules require a database management system event log and an activity log for users who can access restricted data. Record enough for an investigation without turning the log into a duplicate of the database. An individual identification number and the full text of a request are rarely necessary to answer who acted, when, and what they did.
Choose a server facility for failures and evidence
A physical address in Kazakhstan answers only the first question. A server facility must survive real failures and preserve a verifiable history of access. Assess backup power, cooling, fire detection and suppression, entry control, video monitoring, maintenance, spare parts, and the ability to remove a failed storage device under an approved procedure.
At an in-house site, boundaries of responsibility look simple only on a diagram. The business owns the room, the IT team handles the equipment, security manages admission, and a contractor may service air conditioning beside an open rack. Record the responsible people, permitted actions, and rules for escorting visitors. A paper log that no one reconciles against service requests adds little.
Responsibility is divided differently in a data center or cloud. The provider protects the building and base infrastructure within the contract, while the customer configures accounts, networks, encryption, databases, copy retention, and employee access. The responsibility matrix should reach each operation: who replaces a disk, who destroys media, who authorizes a remote session, and who produces a log after an incident.
A server specification does not prove localization, but precise inventory links the logical asset to its physical host. Serial number, rack, facility, hypervisor, volume, database instance, and backup job should form one consistent chain. In virtual infrastructure, replace the fiction that "our server is in rack 14" with a virtual machine placement export and controls that stop the scheduler from moving it to an unsuitable facility.
GSE can supply Kazakhstan-made S200 servers and integrate data center infrastructure with subsequent 24/7 support across the country. Even local equipment, however, cannot fix a process in which an administrator sends database dumps through a foreign file service.
Compliance is proven by documents tied to records
A policy stating that "data is stored in the Republic of Kazakhstan" is not enough for an inspector. Evidence must connect the legal ground, declared architecture, physical placement, and current technical records.
- Prove the primary database location with an architecture diagram, an agreement naming the data center address, and a placement acceptance record. An inventory export and the mapping of the database instance to its node and facility should match them.
- Prove backup placement with the backup policy and an annex to the provider agreement. The job configuration, execution log, and copy catalog by facility show the current state.
- Prove access restrictions with an access authorization order, role matrix, and access procedure. Compare them with account lists, requests, login logs, and activity logs.
- Put the restriction on unilateral relocation by a contractor in the contract and subcontractor list. Change notices and a periodic provider report show how the term is followed.
- Describe deletion after the purpose has been achieved in the retention schedule and deletion procedure. Keep requests, purge logs, copy expiration records, and media destruction certificates as evidence.
The Protection Rules expressly require organizations to identify processes containing personal data, separate publicly available and restricted data, determine who has access, approve a policy, and appoint a responsible person for a legal entity. They also require notice to the authorized body within one business day after discovering a personal data security breach. The appointment order and incident response plan belong in the working evidence set, not in a folder opened only for rare inspections.
Not every item of evidence above appears in the law under that exact name. An organization selects some of it to demonstrate that a mandatory measure works in practice. This distinction matters: a contract may be required for the provider relationship, while the law does not specifically demand a screenshot of a console. Together, they support the same statement from legal and technical sides.
Run a sample check from a person to the storage medium. Select one employee or customer record, locate every system and copy, and show the access grounds, facilities, deletion period, and latest logs. If the team points to different versions of the diagram or cannot identify the owner of an export, the documents still do not describe the live environment.
Migration ends when the old copies are gone
A move to Kazakhstan is not complete when the application switches to a new address. Old disks, snapshots, cloud storage recycle bins, replicas, and accounts continue to exist until their deletion is confirmed.
First, record the full flow register and prevent new untracked exports during the move. Then deploy the target environment in Kazakhstan, configure protection and logging, transfer data through a protected channel, compare record counts and control totals, test the application, and perform a trial restoration. After cutover, watch queues and integrations so an automatic retry does not reactivate the old route.
Close the former environment as a separate stage. Disable copy jobs, revoke access, wait for backup expiration or obtain deletion through the contractual process, collect confirmation from the provider, and update the register. If the organization owns the medium, record sanitization or destruction so its serial number matches the inventory.
Do not accept a deletion certificate without checking its scope. It may cover the active volume but exclude disaster recovery copies, logs, or a subcontractor's data. A request to the provider should name every layer and the final deletion date.
After migration, treat localization as a configuration that can change. A new integration, region change, support connection, or backup policy update can recreate a foreign copy in one business day. Periodically reconciling the data records with the configuration is more useful than rewriting a general policy once a year because it reveals drift before an incident or inspection does.
FAQ
Must a company have its own server room in Kazakhstan?
No. The database can run on owned equipment, in a rented rack, or in cloud infrastructure if the physical facility is in Kazakhstan and the protection requirements are met. The company remains responsible for selecting the provider and proving the location.
Can the primary database be in a foreign cloud with a copy in Kazakhstan?
A local copy alone does not make that design compliant with Article 12. The working database and actual storage remain abroad, while the Rules also address the place where restricted-access data is collected and processed. Redesign the system and assess cross-border transfer separately.
Must backups of personal data remain in Kazakhstan?
The defensible approach is to keep those copies inside the country. A backup stores restorable personal data, and the law does not create a separate exception for it. Record backup facilities in the contract, configuration, and restore test reports.
Can cloud services hold personal data in Kazakhstan?
Yes, if the necessary services, databases, replicas, and copies are physically located in Kazakhstan and the contract and configuration prove it. Check each layer separately because a local region name does not always cover logs, support material, and service data.
Is cross-border transfer of personal data allowed?
The law permits it under the conditions of Article 16 and may require consent or another ground depending on the state and circumstances. It is a separate regime that does not cancel the requirement to store the database in Kazakhstan. Sector restrictions require their own analysis.
Do logs and test databases count as personal data?
Yes, when they retain information about an identified or identifiable person. Masking a name or using an internal identifier does not help if the team can restore the link. Remove unnecessary fields from logs and build test datasets without real records.
Which documents prove personal data localization?
The normal set includes a data flow diagram, database register, agreement naming physical facility addresses, placement records, backup policy, and access matrix. Configurations, inventory exports, job logs, and restoration reports prove the technical side. One contract or provider certificate cannot prove the whole chain.
Is encryption enough to store data abroad?
No. Encryption protects content, but it does not change the physical location of a database or automatically anonymize the data. It complements localization, access management, logging, and a legal ground for transfer.
Who is responsible when a contractor processes the data?
Outsourcing processing does not remove the duties of the owner or operator. The contract should cover facilities, subcontractors, incident notices, deletion, and the delivery of evidence. The parties divide operational duties, but an unassigned gap remains the customer's risk.
How often should data and backup locations be checked?
Check after every change to the architecture, provider, region, integration, or backup policy. Also schedule a regular reconciliation between the register and configuration, plus a restore test. The interval depends on risk, but an annual declaration is not enough for an environment that changes every week.