of April 30, 2021 No. 156/Tax Code
About approval of Rules of implementation of inspection of ensuring security of processes of storage, processing and distribution of the personal data of limited access containing in electronic information resources
According to subitem 7-1) of Item 1 of article 27-1 of the Law of the Republic of Kazakhstan of May 21, 2013 "About personal data and their protection" PRIKAZYVAYU:
1. Approve the enclosed Rules of implementation of inspection of ensuring security of processes of storage, processing and distribution of the personal data of limited access containing in electronic information resources.
2. To provide to committee on information security of the Ministry of digital development, innovations and aerospace industry of the Republic of Kazakhstan:
1) state registration of this order in the Ministry of Justice of the Republic of Kazakhstan;
2) placement of this order on Internet resource of the Ministry of digital development, innovations and the aerospace industry of the Republic of Kazakhstan;
3) within ten working days after state registration of this order submission to Legal department of the Ministry of digital development, innovations and the aerospace industry of the Republic of Kazakhstan of data on execution of the actions provided by subitems 1) and 2) of this Item.
3. To impose control of execution of this order on the supervising vice-minister of digital development, innovations and the aerospace industry of the Republic of Kazakhstan.
4. This order becomes effective after ten calendar days after day of its first official publication.
Minister of digital development, innovations and aerospace industry of the Republic of Kazakhstan
B. Musin
It is approved Committee of homeland security of the Republic of Kazakhstan |
|
It is approved Ministry of national economy of the Republic of Kazakhstan |
|
Approved by the Order of the Minister of digital development, innovations and the aerospace industry of the Republic of Kazakhstan of April 30, 2021 No. 156/Tax Code
1. These rules of implementation of inspection of ensuring security of processes of storage, processing and distribution of the personal data of limited access containing in electronic information resources (further – Rules) are developed according to subitem 7-1) of Item 1 of article 27-1 of the Law of the Republic of Kazakhstan of May 21, 2013 "About personal data and their protection" (further – the Law) and determine procedure of inspection of ensuring security of processes of storage, processing and distribution of the personal data of limited access containing in electronic information resources.
2. In these rules the following basic concepts are used:
1) the owner of the base containing personal data (further – the owner) – the state body, the physical and (or) legal entity exercising right of possession, uses and orders of the base containing personal data according to the laws of the Republic of Kazakhstan;
2) the operator of the base containing personal data (further – the operator), – the state body, the physical and (or) legal entity performing collection, processing and personal data protection;
3) personal data protection – package of measures, including legal, organizational and technical, performed for the purpose of, established by the Law;
4) personal data processing – the actions directed to accumulating, storage, change, amendment, use, distribution, depersonalization, blocking and destruction of personal data;
5) distribution of personal data – actions which making is resulted by transfer of personal data, including through mass media or provision of access to personal data any different way;
6) personal data of limited access – personal data, access to which is limited by the legislation of the Republic of Kazakhstan;
7) the public technical service – the joint-stock company created according to the decision of the Government of the Republic of Kazakhstan;
8) the third party – person which is not the subject, the owner and (or) the operator, but related circumstances or legal relationship on collection, processing and personal data protection.
9) inspection of ensuring security of processes of storage, processing and distribution of the personal data of limited access containing in electronic information resources (further – inspection) – assessment of the applied security measures and protective actions when implementing processing, storage, distribution and personal data protection of limited access containing in electronic information resources.
10) subjects of inspection are owners and (or) operators, and also the third parties performing personal data processing of limited access, containing in electronic information resources.
3. For inspection subjects of inspection provide access to the public technical service to the objects of informatization using, storing, processing and extending the personal data of limited access containing in electronic information resources.
4. When carrying out inspection the analysis of the legal, organizational and technical measures established by the Rules of implementation by the owner and (or) operator, and also the third party of measures for personal data protection approved by the order of the Government of the Republic of Kazakhstan of September 3, 2013 No. 909 is carried out.
5. The public technical service by results of the conducted examination of object of informatization creates the report on the conducted examination, and also the recommendation about elimination of the revealed discrepancies (in the presence).
Disclaimer! This text was translated by AI translator and is not a valid juridical document. No warranty. No claim. More info
Database include more 50000 documents. You can find needed documents using search system. For effective work you can mix any on documents parameters: country, documents type, date range, teams or tags.
More about search system
If you cannot find the required document, or you do not know where to begin, go to Help section.
In this section, we’ve tried to describe in detail the features and capabilities of the system, as well as the most effective techniques for working with the database.
You also may open the section Frequently asked questions. This section provides answers to questions set by users.