Personal data accompanies NPOs at every stage: they register program participants, work with employees and volunteers, report to donors, and publish stories and photographs of beneficiaries.
The handling of such data is regulated by Kazakhstani law, including the Law "On Personal Data and Its Protection" and the Digital Code.
For NPO managers, it's important to see not just a single action—for example, obtaining consent—but the entire path of personal data within the organization.
It all starts with collection. You need to determine what information is truly necessary for a specific purpose. If a name and phone number are sufficient for training, collecting an individual identification number (IIN) is unnecessary. The less unnecessary data an organization stores, the lower the risks.
The next step is use and storage. People must understand who is collecting their data, why it is needed, how it will be used, and with whom it may be shared. Access to information within the organization should also be restricted: for example, employees shouldn't necessarily see data they don't need to perform their job.
Transfer and publication require special attention. Photographs, videos, stories of beneficiaries, information on websites or social media—all of this also involves the processing of personal data and requires compliance with established rules.
If an individual requests that their data be stopped or deleted, the organization must consider such a request in accordance with legal requirements. However, certain information may be retained if there are legal grounds for doing so.
Finally, data should not be stored indefinitely. When it is no longer needed and there is no reason to store it further, it should be deleted or anonymized.
For NGOs, the security of personal data is, first and foremost, a matter of trust from beneficiaries, volunteers, and donors. But it is also a matter of responsibility: in Kazakhstan, data protection requirements are becoming more stringent, with fines for violations, and the organization's director may be held accountable.
Therefore, data protection is more than just signing a consent form. At every stage, it is important to collect only what is necessary, use the information for its intended purpose, protect it from leaks, and promptly delete or anonymize it.