Kazakhstan proposes raising maximum data breach fine to 5,000 MCI

This digest was compiled by AI from multiple sources — links to the originals are below.
Kazakhstan's vice minister of AI and digital development, Doszhan Mussaliyev, announced on September 29 that the government is considering raising the maximum fine for repeat personal data breaches by large companies from 2,000 to 5,000 MCI. The proposal has been prepared and will now be discussed with state bodies and business before submission to the Kurultai.
Key Facts
- The current maximum fine for personal data breaches is 2,000 MCI, equivalent to 8.65 million tenge in 2026.
- The proposed increase would raise the maximum fine for repeat violations by large legal entities to 5,000 MCI, or 21.625 million tenge.
- Vice Minister Doszhan Mussaliyev announced the proposal on September 29, 2026, at the KazHackStan cybersecurity conference in Astana.
- The draft proposals have been prepared and will be discussed with state bodies and business before submission to the Kurultai.
- In 2025, Kazakhstan significantly tightened administrative liability for cybersecurity and personal data protection violations.
Proposed Fine Increase
Vice Minister of AI and Digital Development Doszhan Mussaliyev announced the proposal on September 29, 2026, at the KazHackStan conference in Astana. The current maximum fine for personal data breaches is 2,000 MCI, which equals 8.65 million tenge in 2026. The ministry is considering raising the maximum fine for repeat violations by large legal entities to 5,000 MCI, or 21.625 million tenge. Mussaliyev stated that existing fines do not always have a significant impact on large companies.
Legislative Process
The ministry has already prepared draft proposals and amendments. The proposals will be discussed with state bodies and business representatives. After agreement, the amendments will be submitted to the Kurultai for consideration. Mussaliyev expressed hope that the proposals will receive support and lead to corresponding decisions.