Kazakhstan fines Daryn.online for data protection failures, finds no leak of 4.2 million records
This digest was compiled by AI from multiple sources — links to the originals are below.

Kazakhstan's Information Security Committee conducted an unscheduled inspection of Daryn.online following reports of an alleged leak of 4.2 million user personal data records, the ministry said on July 31. The inspection confirmed no data breach — the platform's actual database holds over 90,000 records, making a leak of that scale impossible — but found violations of mandatory data protection measures. The company was fined under Article 79 of the Administrative Offences Code.
Inspection Findings
The unscheduled inspection was launched after open-source reports claimed a leak of 4.2 million user records from the educational platform Daryn.online. Inspectors from the Information Security Committee examined compliance with the Law on Personal Data and Their Protection, including organizational and technical safeguards. The ministry confirmed that no such leak occurred — the system actually contains just over 90,000 personal data records, making a breach of the alleged size impossible. Nevertheless, the audit uncovered gaps in the company's implementation of mandatory data security measures.
Administrative Penalty
For the identified violations, Daryn.online was held administratively liable under Article 79 of Kazakhstan's Administrative Offences Code, which addresses failure to comply with personal data protection requirements. The company was ordered to pay a fine, though the exact amount was not disclosed. The ministry noted that such lapses are common in the private sector, including excessive collection of data, absence of consent, lack of internal procedures, and insufficient security of information systems.
Regulatory Reminder
The ministry reminded all database owners and operators of their legal obligations: collect personal data only with subject consent and in the minimum required volume, appoint responsible officers, implement access controls, encrypt data, use secure communication channels, store databases within Kazakhstan, and report security incidents within one business day. Non-compliance carries liability under Kazakhstani law.
What's Next
Daryn.online is now required to rectify the identified deficiencies and pay the administrative fine. Whether the regulator will launch broader audits of private-sector data handlers in Kazakhstan remains unclear.
5 sources
Kazakhstan fines Daryn.online for data protection failures, finds no leak of 4.2 million records


