Solution · By task

Personal data protection

There are usually two reasons. Either a request has arrived from the authorised body, or a large customer has asked to see how you handle personal data before signing a contract. Neither case is closed with a single piece of paper: you need a full set of documents and technical measures configured to match, otherwise the gap is obvious at a glance.

10 days
the document set
System class
we determine the measures needed
Data inside Kazakhstan
servers inside the country
1-3 mo
for the technical measures

What the work consists of

We work on two planes at once. One is paperwork, which the inspector leafs through. The other is technical, and that is what actually stops the data leaking.

Discuss the timing

Data inventory

We compile a list: what the data is, which applications it lives in, who holds the keys. From that list follow both the data category and the requirements that apply to it.

Threat model

It answers the question of who and what you are defending against in your particular case. This is the document that cuts out unnecessary purchases and noticeably saves money.

The document set

Orders, the processing policy, the access procedure, registers, consent forms. The set an inspector asks to see first.

Technical safeguards

Permissions by role, antivirus with a central console, request logging, channel encryption and security tools chosen for your systems.

Consents and requests

Consent forms on the site and in HR paperwork, the withdrawal procedure and the deadlines for replying to whoever asks.

Staff briefing

Who works with the data and how, what may not be taken outside the perimeter, how access is granted. All of it signed off in a register.

The order we work in

Grabbing everything at once is expensive and pointless. The workable order is: first find out what you have, then the documents, and only at the end buy security tools.

01

What sits where

We look for where the data actually sits: HR records, the customer database, camera footage, forms on the site, rented services and whatever has gone to contractors.

02

Which country the servers are in

We check which servers all this runs on and in which country. Data on Kazakhstani citizens must be held inside the country, and this is usually the most painful point.

03

We prepare the documents

In ten working days we prepare the threat model and the complete set of internal documents. That is enough to answer most of an inspector's questions.

04

We install the safeguards

We install security tools exactly to the threat model we wrote and brief the staff. After that we keep it all in working order.

A fine is far from the worst of it here. A customer database that leaks damages your reputation more than any enforcement notice. And explaining yourself to a partner whose data ended up in the open costs more than the whole document set plus the implementation.

Questions and answers

It does. The law does not sort companies by headcount: if you hold employee forms and customer phone numbers, you are an owner or operator of personal data with all the duties that follow. A small firm objectively has less work to do, but the list of documents is exactly the same.

If that database holds information on Kazakhstani citizens, then almost certainly yes. It has to be stored inside the country; a foreign site can only be an additional copy, never the only location. During the survey we list which systems will have to move and work out in advance what the migration will cost.

To pass an inspection on paper it is sometimes enough. But that protects your wallet, not the data. We always draw an honest line: this part of the set is for the regulator, and this part genuinely reduces the chance of a leak. The choice is then yours.

With two weeks or more in hand we usually make it: both the documents and the basic technical measures. If there is less time we will say so plainly - we will cover part of it and order the work so that whatever gets asked about first is ready.

Documents need upkeep: processes change, new software appears, the law is amended. It makes sense to review the list of processed data annually and always when a new system goes live. That upkeep can be handed to us under contract.

Let us see whether you are ready for an inspection

Опишите, с какими сведениями работаете и что уже успели сделать. Проведём обследование и покажем расстояние между нынешним положением дел и тем, чего требует закон.