Data inventory
We compile a list: what the data is, which applications it lives in, who holds the keys. From that list follow both the data category and the requirements that apply to it.
We work on two planes at once. One is paperwork, which the inspector leafs through. The other is technical, and that is what actually stops the data leaking.
We compile a list: what the data is, which applications it lives in, who holds the keys. From that list follow both the data category and the requirements that apply to it.
It answers the question of who and what you are defending against in your particular case. This is the document that cuts out unnecessary purchases and noticeably saves money.
Orders, the processing policy, the access procedure, registers, consent forms. The set an inspector asks to see first.
Permissions by role, antivirus with a central console, request logging, channel encryption and security tools chosen for your systems.
Consent forms on the site and in HR paperwork, the withdrawal procedure and the deadlines for replying to whoever asks.
Who works with the data and how, what may not be taken outside the perimeter, how access is granted. All of it signed off in a register.
Grabbing everything at once is expensive and pointless. The workable order is: first find out what you have, then the documents, and only at the end buy security tools.
We look for where the data actually sits: HR records, the customer database, camera footage, forms on the site, rented services and whatever has gone to contractors.
We check which servers all this runs on and in which country. Data on Kazakhstani citizens must be held inside the country, and this is usually the most painful point.
In ten working days we prepare the threat model and the complete set of internal documents. That is enough to answer most of an inspector's questions.
We install security tools exactly to the threat model we wrote and brief the staff. After that we keep it all in working order.
A fine is far from the worst of it here. A customer database that leaks damages your reputation more than any enforcement notice. And explaining yourself to a partner whose data ended up in the open costs more than the whole document set plus the implementation.
It does. The law does not sort companies by headcount: if you hold employee forms and customer phone numbers, you are an owner or operator of personal data with all the duties that follow. A small firm objectively has less work to do, but the list of documents is exactly the same.
If that database holds information on Kazakhstani citizens, then almost certainly yes. It has to be stored inside the country; a foreign site can only be an additional copy, never the only location. During the survey we list which systems will have to move and work out in advance what the migration will cost.
To pass an inspection on paper it is sometimes enough. But that protects your wallet, not the data. We always draw an honest line: this part of the set is for the regulator, and this part genuinely reduces the chance of a leak. The choice is then yours.
With two weeks or more in hand we usually make it: both the documents and the basic technical measures. If there is less time we will say so plainly - we will cover part of it and order the work so that whatever gets asked about first is ready.
Documents need upkeep: processes change, new software appears, the law is amended. It makes sense to review the list of processed data annually and always when a new system goes live. That upkeep can be handed to us under contract.
Опишите, с какими сведениями работаете и что уже успели сделать. Проведём обследование и покажем расстояние между нынешним положением дел и тем, чего требует закон.
Request received
It is already with a manager. You will get an answer within the working day, and urgent requests go to the duty engineer immediately.
There is no such city in the list. Check the spelling.