On July 12, 2026, the Digital Code of the Republic of Kazakhstan (No. 255-VIII) — the first comprehensive piece of digital law — entered into force. The main objective of the Code is to consolidate fragmented digital regulations into a single system, establish the fundamental principles of digital law, and set general rules that will apply to all digital relationships.
It does not replace sector-specific regulations (the Law “On Personal Data,” the Law “On Cybersecurity,” the Law “On Digital Assets,” and the Law “On Artificial Intelligence”), but rather establishes a unified conceptual framework and a systematic hierarchy above them. In the event of a conflict with other laws of the Republic of Kazakhstan regarding the digital environment, the Code takes precedence; however, international treaties ratified by the Republic of Kazakhstan take precedence over the Code itself.
What does this mean for businesses?
For businesses, adopting the code means they must:
- review internal processes related to the use of electronic digital signatures and employee authorizations;
- update local data processing policies;
- take new requirements into account when developing digital services, AI solutions, and decision-making algorithms;
- review contractual structures that involve the use of smart contracts.
The Code applies to virtually all organizations that use digital technologies, specifically:
- companies that use electronic digital signatures;
- banks and financial institutions;
- IT companies;
- marketplaces;
- information system operators;
- employers that use digital HR document management;
- organizations that process personal data;
- developers of artificial intelligence-based solutions.
A set of principles for digital legislation is being established, including the following:
- human-centered approach;
- legality;
- technological neutrality;
- security;
- trust;
- digital ethics;
- accountability of digital environment participants;
- ensuring competition;
- balance between public and private interests.
Key aspects of the code:
- The Digital Code repeals the law on electronic digital signatures (EDS)
Upon the entry into force of the Digital Code, the Law “On Electronic Documents and Electronic Digital Signatures” of January 7, 2003, is repealed; while retaining the basic legal framework, the Digital Code introduces updated concepts, clarified wording, and more detailed regulations on specific issues.
An electronic digital signature is equivalent to a handwritten signature — but only if all four conditions are met simultaneously (Article 49, paragraph 2):
- authenticity has been verified using a public key with a valid certificate;
- the individual is the rightful owner of the private key;
- the signature is used in accordance with the information in the certificate;
- the certificate was issued by a certification authority (CA) accredited in Kazakhstan or by a foreign CA registered with a trusted third party in Kazakhstan.
The requirements for electronic signature software have become more detailed (Article 50)
The Code explicitly stipulates that electronic signature software must:
- allow the signer to review the content before signing;
- create the signature only after the signer has explicitly confirmed the action;
- send a notification confirming that the signature has been created and applied;
- provide evidence of the signature’s existence at a specific point in time (a requirement for a timestamping service);
- allow the signed document to be saved.
The private key is the property of the owner; transfer is prohibited
The private key is the property of the individual; transfer to or use by third parties is not permitted.
CA Accreditation: Issued free of charge for a period of 3 years
Accreditation is mandatory (except for root CAs) and is issued free of charge by the authorized cybersecurity authority for a period of 3 years. For individuals planning to establish a private CA, this is a key practical consideration.
Recognition of Foreign Digital Signatures — Through a “Trusted Third Party of the Republic of Kazakhstan” (Article 57)
This is a separate digital system that, within the framework of cross-border cooperation, verifies the authenticity of foreign digital signatures and Kazakhstani digital signatures abroad. The rules for registering certification authorities and trusted third parties of foreign states are approved by the authorized body; that is, the mechanism is a framework, and the specifics (which countries/certification authorities are already recognized) are not included in the code but are left to subordinate legislation. At present, the mechanism is of a framework nature; its practical implementation will depend on the adoption of subordinate legislation and international cooperation.
A physical signature and “company seal” are no longer required
The head of a legal entity has the right to authorize an employee to sign electronic documents; each employee uses their own personal certificate, meaning there should be no practice of “a single director’s signature on all company documents” in the digital environment.
In practice, this means that the use by one employee of another employee’s certificate — even at the direction of a supervisor — violates the requirements of the Code and may call into question the legal validity of the signed electronic document.
- Data now enjoys a “presumption of innocence,” but that presumption vanishes if there’s a leak
The Code defines open data as data that has been voluntarily and lawfully made publicly available. However, if data becomes available to the public due to a leak, error, or hack, it automatically ceases to be considered “open” and must be deleted immediately.
- A “digital condominium” has emerged
Perhaps the most unusual innovation in the code is the digital condominium (Article 35): a form of ownership in which participants jointly own distributed digital assets (both individual and shared), and their rights are established by an agreement or a smart contract.
- Smart contracts must give humans the final say
A smart contract is an agreement that provides for the automatic execution of terms agreed upon in advance by the parties upon the occurrence of certain circumstances through the use of digital technologies. A smart contract can be written entirely in the form of program code, provided that it is unambiguously readable and reproducible by a human. However, the code sets a clear condition: the final decision on any dispute arising from a smart contract must be made by a natural person, not by an algorithm.
- Algorithms have a responsibility to explain themselves, but not to disclose their source code
An algorithmic system is a digital system that makes decisions or influences decision-making based on automated data processing, including artificial intelligence systems. If a decision regarding human rights is made by a fully automated system, the individual has the right to request an explanation of the key factors that influenced the outcome and to seek a review of the decision with the involvement of a specialist. At the same time, the code expressly permits the source code or algorithm to remain undisclosed (Art. 43).
- Digital identification cannot be mandated unless expressly permitted by law
The Code establishes the right not to identify oneself in the digital environment as a general rule: it is permissible to engage in relationships without identification if this does not give rise to rights or obligations (Article 40).
- An official category called “digital ethics” has been established
The list of nine basic principles of digital legislation includes “digital ethics and social responsibility” (Article 4, elaborated upon in Article 13) — a phrase not previously found in Kazakhstan’s codified law, aimed at preventing discrimination, manipulation, abuse of digital technologies, and other violations of the rights, freedoms, and legitimate interests of individuals, society, and the state.
- AI systems will check not only for quality but also for “prohibited functions”
A quality audit of artificial intelligence systems must include an assessment of the legitimacy of the use of training datasets and a verification that the systems do not contain any prohibited functionalities, in accordance with the relevant law “On Artificial Intelligence.”
- Digital human rights are now subject to their own regulations
The Code enshrines the right of individuals to protect their digital data, transparency in the use of digital technologies, protection against unlawful automated decision-making, and other safeguards that serve as the general principles of digital legislation.
The Digital Code should not be viewed as just another technical law in the IT sector. It establishes uniform rules for the functioning of the digital environment and will gradually become the foundation for the application of all specialized digital laws. For businesses, this means not only taking these new requirements into account when developing digital products, but also reviewing internal procedures for electronic document management, data processing, the use of artificial intelligence, and the use of digital services.
The provisions of the Code will be applied in conjunction with sector-specific laws and subordinate regulatory legal acts; therefore, the development of legal enforcement practices is still pending.
This article is based on the “Digital Code of the Republic of Kazakhstan” No. 255-VIII dated January 9, 2026.
Author
Dildara Dzhapieva
- Lawуer

Send message
Please describe your situation and we will find an optimal solution for your business.
info@konsugroup.com