
Published
09/28/2026, 16:10Kyrgyz citizens will be able to find out who accessed their personal data, when and why, and, if they suspect a breach, lodge a complaint directly via the ‘Tündük’ app. It is proposed that this service be established as part of the personal data protection strategy for 2026–2030.
The draft has been prepared by the State Agency for Personal Data Protection. Alongside the strategy, a roadmap and performance indicators for assessing its implementation have been put forward for public consultation, which will run until 13 October.
The new service is intended to show not only that a request for information about an individual has been made, but also the purpose and legal basis for such a request. Its development and integration into the ‘Tündük’ mobile app are set out in the roadmap, with a deadline of ‘by the fourth quarter of 2026’.
However, not all requests will be visible. An exception is made for requests from law enforcement and judicial authorities, as well as national security bodies, made within the scope of their lawful powers.
The developers explain the need for these changes by pointing out that the state and the business sector are processing ever-increasing amounts of data on citizens: from education and health to financial transactions. The development of e-services, artificial intelligence and data sharing requires more reliable protection of this information.
In addition to the history of enquiries in ‘Tündük’, it is proposed to create a register of data controllers. The plan is for this register to record information on personal data incidents, audits, mandatory directives and the prosecution of offenders. There are also plans to link the register to government information systems via ‘Tündük’.
A separate area of focus is the response to data breaches and other security incidents. By the fourth quarter of 2027, the roadmap provides for the creation of a national system for recording such incidents and a mechanism for mandatory notification of the relevant agency. This should help to identify breaches more quickly and minimise their consequences.
There are plans to audit government information systems that store personal data for compliance with security requirements. By 2030, 50 systems are due to undergo this assessment. The developers aim to increase the proportion of identified breaches that are rectified to 70 per cent.
By 2030, all government bodies must appoint individuals responsible for the protection of personal data. Training and professional development are provided for these individuals. Educational programmes are also planned for members of the public – covering protection against online fraud, cyberbullying and the unlawful distribution of personal images.
For organisations handling personal data, it is proposed to develop electronic interaction with the regulator. Through a digital portal, it will be possible to submit notifications and reports, receive instructions and advice, pay fines and track inspections.
To ensure the roadmap is implemented, it is proposed that the heads of the relevant government bodies be held personally accountable. They will be required to report on progress every six months.



