Law / Kyrgyzstan

Kyrgyzstan

11 of 18 named instruments researched to a stage, across all six areas of law we track: 11 in force. As of 20 September 2026.

When they take effect10 of 11 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 1 instrument (1 in force) 2024: 0 instruments 2025: 0 instruments 2026: 8 instruments (8 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 4
  3. Scraping law 1
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 in force

Research summary (198 words)

Kyrgyzstan's first AI-specific statutory regime is Chapter 23 (Arts. 191-197) of the Digital Code, Law No. 178, adopted 18 June 2025 and in force since 6 February 2026 alongside the Code's personal-data chapter.

Arts. 191-196 set design principles for AI systems generally and turn them into binding risk-management, documentation, logging and conformity-declaration duties once an owner's own hazard assessment finds a system poses increased danger to a protected interest (life, health, rights, the environment, defense, national security or public order); Art. 197 requires disclosure that a person is interacting with an AI system, that a biometric-classification or emotion-recognition system is being applied to them, and that a deepfake is artificially produced or altered.

The Code's own official portal, cbd.minjust.gov.kg, serves Chapter 23 only through a script-rendered viewer returning no text on repeated checks, so every citation below rests on continent-online.com, a commercial CIS legal-database mirror serving the same statute, corroborated by its table of contents on a second, independent mirror, base.spinform.ru. No penalty, private-right-of-action or enforcement-body provision specific to Chapter 23 was located in the articles read; the Cabinet of Ministers requirements Arts. 194 and 195 delegate to had not been separately located as of the date below.

AI risk obligations

Digital Code, Chapter 23: AI system design and risk-management obligations

Digital Code, Law No. 178 (18 June 2025), in force 6 February 2026, Chapter 23, Arts. 191-196text of Chapter 23 (Systems of Artificial Intelligence)

In force 8 months, effective 6 February 2026. Binds public and private bodies.

What this law does

Arts. 191-196, read in full, establish Kyrgyzstan's AI governance framework: Art. 191 sets non-binding design principles (risk reduction, openness, explainability, human oversight, accuracy, reliability, security) that any later binding requirement must implement, and Arts. 192-196 attach binding duties once an owner's own hazard assessment finds a system poses increased danger to a protected interest.

An owner of such a system must reassess and republish the hazard assessment at each life-cycle stage, meet Cabinet of Ministers risk-management and documentation requirements, keep operating logs, and declare conformity by a published, digitally signed document before deployment.

A user of such a system must operate it per its instructions, maintain effective human oversight, immediately suspend use and notify the owner once it has grounds to believe use could cause harm, keep logs, comply with a suspension or final court order, and, where the system's output feeds a rights-affecting decision, explain that result to an affected person on request free of charge; a person using the system solely for personal or family needs is excused most of these duties.

Chapter 23 states no duty for an owner or a user to notify the authorized state body of a suspension or of grounds to believe a system may cause harm: that body's role under Arts. 194(5)(7) and 196(1)(7) is to demand a suspension the owner or user must then carry out, enforceable by a final court act ordering the system's use to stop.

What it requires

AI transparency

Digital Code, Chapter 23: AI interaction and deepfake disclosure duties

Digital Code, Law No. 178 (18 June 2025), in force 6 February 2026, Chapter 23, Art. 197text of Chapter 23 (Systems of Artificial Intelligence)

In force 8 months, effective 6 February 2026. Binds public and private bodies.

What this law does

Art. 197, read in full, requires an owner or user of an AI system who applies it to interact with natural-person consumers to inform them they are dealing with an AI system, unless that is obvious from context; a user of a system that recognizes emotion or classifies a person by biometric characteristics must inform that person the system is being applied to them; and a user who applies such a system to create deepfakes must disclose that the material's origin or content was artificially produced or altered.

The consumer-interaction and biometric-classification duties are excused where disclosure would defeat a lawful defense, national-security, or crime-prevention purpose, and the deepfake duty is separately excused for lawful use protecting those same interests or exercising freedom of scientific, technical, artistic or educational creation, each excused case still conditioned on measures protecting the rights the disclosure would otherwise serve.

What it requires

Privacy law4 instruments, 4 in force

Research summary (242 words)

Kyrgyzstan's personal-data law has recently changed regimes: the Digital Code (Law No. 178, adopted 18 June 2025) entered into force 6 February 2026 and recodifies personal-data law into a dedicated Chapter 11 (Arts. 77-91). Every citation below rests on the Code's own official text at https://cbd.minjust.gov.kg/3-48/edition/35412/ru rather than on the third-party mirrors that also carry it, with Arts. 48(3), 63, 77, 78, 80, 88, 89, and 90 matching those mirrors word for word.

Law No. 58's own official page (https://cbd.minjust.gov.kg/4-3703/edition/1239270/ru) is marked "УТРАТИЛ СИЛУ в соответствии с Законом КР от 31 июля 2025 года № 179" (repealed pursuant to Law of the Kyrgyz Republic dated 31 July 2025 No. 179), which is the Digital Code's own introducing law, so Law No. 58 is repealed as of the Code's 6 February 2026 commencement. No instrument for Law No. 58 is authored here since it no longer states current law.

Chapter 11's read provisions closely track General Data Protection Regulation (GDPR): Art. 78 states lawfulness, purpose limitation, minimization, accuracy, and storage-limitation principles in near-verbatim GDPR Art. 5 form, and Art. 80 prohibits processing five special categories, including biometric data for digital identification, by default, subject to a GDPR Art. 9 style conditions list.

Art. 89 establishes a published adequacy-list mechanism for cross-border transfer with no localization or in-country-storage mandate found, a real jurisdictional difference from the rest of this batch. Data-subject rights at Arts. 81-87 and the processing-grounds list at Art. 79 are outside the provisions described below.

Comprehensive regime

Digital Code, comprehensive personal data regime

Digital Code, Law No. 178 (18 June 2025), in force 6 February 2026, Chapter 11, Arts. 78, 88official government portal

In force 8 months, effective 6 February 2026. Binds public and private bodies.

What this law does

Art. 78, read in full, states lawfulness/fairness/transparency, purpose limitation, data minimization, accuracy, and storage-limitation principles in a structure closely tracking General Data Protection Regulation (GDPR) Art. 5. Art. 88, also read in full, requires privacy-by-design measures, an operations log kept per regulator guidance, a personal-data-responsible person for organizations with more than ten employees, and staff training, with the Cabinet of Ministers setting protection-level requirements by regulation.

Art. 77, read in full, confirms the chapter applies to any personal-data processing including within digital records and resources, exempts a natural person's purely personal or family processing, and voids any conflicting or unpublished regulation. Art. 79 (the general processing-grounds list) is outside the provisions described here.

The official government portal, cbd.minjust.gov.kg, serves the Digital Code's own page in full (81,674 characters), matching the third-party mirrors word for word, but returns only a client-rendered JavaScript shell without a full browser render; the citations here rest on that official page.

What it requires

Cross border transfer

Digital Code, cross-border transfer of personal data

Digital Code, Law No. 178, Art. 89official government portal

In force 8 months, effective 6 February 2026. Binds public and private bodies.

What this law does

Art. 89, read in full and confirmed word for word against the official portal, has the sectoral personal-data regulator approve and publish a list of foreign states ensuring adequate protection; transfer to a listed state is carried out under the Code and may not be prohibited or restricted, a notably strong free-flow guarantee once a state is listed, and the record-owner must verify a destination's listing before transferring.

Transfer to a non-listed state may still occur on subject consent, an international treaty, statutory necessity for the constitutional order, national defense, or state security, or contract necessity, with the article's remaining grounds past a fourth not extracted here. No localization or in-country-storage mandate was found anywhere in Art. 89 or elsewhere in what was read, a real jurisdictional contrast with Kazakhstan, Uzbekistan, Tajikistan, and Turkmenistan in this batch.

What it requires

Enforcement supervision

Digital Code, sectoral regulator for personal data

Digital Code, Law No. 178, Art. 90 (State Agency for Protection of Personal Data)official government portal

In force 8 months, effective 6 February 2026. Binds public and private bodies.

What this law does

Art. 90, read at the official source, requires the sectoral personal-data regulator to be created under Art. 9 of the Code and to be independent of the persons it oversees, with a head who must hold qualifications and experience in personal-data protection.

Art. 90(3) gives it real powers: applying and overseeing the Code; raising subject and controller awareness; advising state bodies; accrediting inspection bodies under Cabinet of Ministers procedure; hearing complaints and conducting inspections, including on its own initiative; taking preventive, corrective, and enforcement measures for violations; and publishing guidance. Art. 90(4) has it maintain a registry of record-owners recording incidents, inspection results, and binding decisions.

No fine schedule or private-right-of-action provision appears within Art. 90 or in the other provisions of the Code described here.

The Code's own text never names the regulator (it uses only "отраслевой регулятор в сфере персональных данных," sectoral regulator in the field of personal data, throughout, confirmed by a search finding zero occurrences of "Агентство" (Agency) anywhere in the Code); its identity as the State Agency for Protection of Personal Data (DPA) rests on the DPA's own official site, which describes itself in exactly these Digital-Code terms and institutionally predates the Code, having been established by a 2021 amendment to the now-repealed Law No. 58.

What it requires

Sensitive categories

Digital Code, special categories of personal data

Digital Code, Law No. 178, Art. 80official government portal

In force 8 months, effective 6 February 2026. Binds public and private bodies.

What this law does

Art. 80(1), read in full and confirmed word for word against the official portal, prohibits processing by default: data revealing racial or ethnic origin, political views, religious or philosophical beliefs, or trade-union membership; genetic information; biometric data for the digital identification of a natural person; and data concerning health, sex life, or sexual orientation.

Art. 80(2) lifts the prohibition for contract necessity, explicit statutory authorization, vital-interest necessity, data the subject has explicitly made public, medical or public-health purposes, and (in part) membership processing by an association or religious organization.

No definition of biometric data as a general term was found anywhere in the official Code text (confirmed by a search for the root "биометрич" (biometric) across the whole document, which surfaces only Art. 48's state-system provisions and Art. 80(1)(3)'s bare category name); the only enumerated biometric-modality list in the Code is Art. 48(3)'s narrower, government-identification-system-specific list, confirmed at the official source to read exactly: digital facial image, papillary-pattern fingerprints of both hands, and handwritten signature, naming no voice modality, which should not be read as governing this general provision.

What it requires

Scraping law1 instrument, 1 in force

Research summary (303 words)

Kyrgyzstan has no scraping-specific statute, so general law governs each dimension separately.

Chapter 40 of the Criminal Code of the Kyrgyz Republic, No. 127 of 28 October 2021 (Cyber Security Crimes, Arts. 319-322), criminalizes unauthorized access to a computer system that infringes a security measure, with escalating tiers for intentional destruction, group commission, or critical infrastructure; Art. 319, read in full, requires unauthorized access that results in destruction, blocking, or modification of information, so a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision, and no reported Kyrgyz case has tested the point.

No Kyrgyz statute or reported decision addresses the enforceability of a browsewrap or clickwrap terms of service against a scraper.

The Law of the Kyrgyz Republic No. 6 of 14 January 1998 on Copyright and Related Rights, as amended to Law No. 62 of 17 March 2023, permits quotation for scientific, critical, or informational purposes and reproduction of newspaper extracts in press reviews (Art. 19(1)(1)), but carries no text-and-data-mining exception, so reproducing Kyrgyz-hosted copyrighted text at scale for AI training rests only on this same narrow quotation ground, subject to the general exceptions; Art. 8 excludes daily news and current-events press information from copyright protection altogether, a partial carve-out for scraping bare factual news items.

The Copyright Law treats a database only as an object of ordinary copyright protection and confers no sui generis database right. Personal data scraped from a Kyrgyz-hosted system is governed by the Digital Code, Law No. 178 (2025), Chapter 11, researched under this corpus's privacy topic; no scraping-specific carve-out for publicly available personal data is described here.

No Kyrgyz statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Criminal Code, unauthorized access to computer information

Criminal Code of the Kyrgyz Republic, No. 127 (28 October 2021), Chapter 40, Art. 319Criminal Code of the Kyrgyz Republic

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2025. Publisher's page: https://legislationline.org/sites/default/files/2025-03/KG_Criminal%20Code%202021_EN.pdf

In force. Binds public and private bodies.

What this law does

Art. 319(1), read in full, prohibits unauthorized access to someone else's protected computer information, electronic documents, an information system, or a telecommunications network, where the access results in destruction, blocking, or modification of information, or in disruption of processing devices, causing significant harm intentionally or through negligence; the base tier is community service, deprivation of the right to hold certain positions, correctional labor, or a fine of 200 to 500 calculated units.

Art. 319(2) raises the penalty to a fine of 500 to 1000 calculated units or imprisonment of up to five years where the act is committed by a group by prior agreement, causes major damage through negligence, or reaches critical information infrastructure.

Art. 319(3) sets the same 500-to-1000-unit or five-year tier for the same base conduct committed with intent to destroy, alter, block, or render unusable the information or to disable the system, and Art. 319(4) applies that tier's aggravating circumstances to the intentional form as well.

The same Chapter 40 separately criminalizes creating malicious software (Art. 320), cyber-sabotage (Art. 321), and unsolicited mass distribution of electronic messages that disrupts a system's operation (Art. 322), each read at the same source.

Because Art. 319's trigger is unauthorized access resulting in one of the listed harms, a scraper reading a public, unauthenticated page without defeating any access control, and without destroying, blocking, or modifying the page's information, falls outside a plain reading of the provision.

The Code's own text, as archived, carries no commencement clause; it was enacted by a separate introducing law (Law of the Kyrgyz Republic of 28 October 2021 No. 126) whose commencement date is not confirmed in the primary text, so the Code's own in-force status rests on its own extensive amendment history running from January 2022 through January 2024.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (446 words)

Kyrgyzstan's product-security and cyber-resilience law rests on the Digital Code (Law No. 178, adopted 18 June 2025, in force 6 February 2026), Art. 63, "Digital Resilience," a general chapter positioned outside the Code's dedicated personal-data chapter (Arts. 77-91) rather than a provision inside it.

Art. 63(5) and (6), read in full at the official source and confirmed word for word, require a record owner or digital service provider to notify its sectoral regulator of any incident affecting digital resilience or the rights and legitimate interests of a digital-environment participant within 72 hours of discovery, and a processor to notify the record owner within 48 hours; the trigger is not limited to a personal-data exposure, and Chapter 11, the Code's own comprehensive personal-data regime, states no separate breach-notification article of its own, so this is Kyrgyzstan's only incident-notification duty located and it is analyzed here rather than as personal-data law.

Art. 63(1), (2) and (4) impose a further, general duty on every subject of a digital-environment legal relationship to maintain the integrity, availability and confidentiality of what it operates and processes, monitor for and help prevent incidents, manage risk under a risk-management system, manage the resources continuity of operation requires, and follow a sectoral regulator's binding instructions, with no gate limiting the duty to a particular sector or company size.

No instrument was found setting security requirements a software product or connected device must meet before it reaches the Kyrgyzstan market.

Art. 63(3) reserves the detailed procedure governing critical information infrastructure specifically to a separate body of cybersecurity legislation whose citation is not confirmed in the primary text read here, and whether the National Bank of the Kyrgyz Republic has issued its own binding cybersecurity or IT-risk directive for a licensed financial institution is likewise not confirmed; both are recorded here as open questions rather than as a confirmed absence.

No single authority, penalty amount, or published enforcement record specific to Art. 63 was located. The Digital Code's own personal-data security duty, Art. 88, which requires privacy-by-design measures, an operations log, and a designated personal-data-responsible person, is already analyzed as this jurisdiction's personal-data row rather than repeated here, because it is a security-of-processing provision inside the comprehensive personal-data regime itself.

The Code's Chapter 23 AI system-design, risk-management, and deepfake-disclosure duties are, for the same reason in reverse, already analyzed as this jurisdiction's AI-system row rather than repeated here, because their duty attaches to a system for being an AI system rather than to a product's or service's general security posture.

As the Digital Code entered into force only on 6 February 2026, the sectoral-regulator instructions and cybersecurity legislation Art. 63(3) and (4) contemplate may still be forthcoming.

Security baseline statutes

Digital Code, digital resilience baseline security measures

Digital Code, Law No. 178, Art. 63(1)-(4)Official government portal

In force 8 months, effective 6 February 2026. Binds public and private bodies.

What this law does

Article 63(1) states that state regulation of digital resilience exists to ensure the continuity of operation of the subjects and objects of the digital environment and their recovery after an incident there, expressly recognizing the practical impossibility of fully protecting against one.

Article 63(2) requires every subject of a digital-environment legal relationship to achieve digital resilience by ensuring the integrity and availability of the objects of that relationship and the confidentiality of the digital data it processes. The same provision also requires monitoring for and helping prevent incidents in the digital environment and exchanging data about them, managing risk under a risk-management system, and managing the resources continuity of operation requires.

Article 63(3) reserves the specific procedure for integrity, availability, and confidentiality measures over critical information infrastructure, and for monitoring and exchanging data about incidents affecting it, to Kyrgyzstan's cybersecurity legislation, a body of law not described here. Article 63(4) lets a sectoral regulator direct measures a digital-environment participant must implement to prevent an incident or reduce its negative consequences, and binds the participant to follow them.

What it requires

Vulnerability and incident reporting

Digital Code, digital resilience incident notification

Digital Code, Law No. 178, Art. 63Official government portal

In force 8 months, effective 6 February 2026. Binds public and private bodies.

What this law does

Article 63, positioned in the Digital Code's general chapter on digital resilience outside its dedicated personal-data chapter, requires a record owner or digital service provider to notify the sectoral regulator of any incident in the digital environment affecting digital resilience or the rights and legitimate interests of a subject of a digital-environment legal relationship.

That notice is due no later than 72 hours after the record owner or digital service provider discovers the incident, and a notice given after that clock must explain the reason for the delay. A processor must separately notify the record owner of an incident within whatever period their contract or an applicable legal act sets, and in any event no later than 48 hours after discovering it.

The notification itself must describe the incident, estimate the number of affected users, name a contact responsible for the incident or for personal-data processing, describe the incident's consequences, and describe the remedial measures already taken. The record owner or digital service provider must update that notification as new facts about the incident or its consequences emerge.

The duty is triggered by an incident affecting digital resilience broadly, not only one exposing personal data, and Kyrgyzstan's dedicated personal-data chapter states no separate breach-notification article of its own.

What it requires

Age gating law1 instrument, 1 in force

Research summary (233 words)

Kyrgyzstan bars distributing to children information that harms their health or development, with an aggravated administrative fine specifically where the distribution uses mass media or an information-telecommunications network including the Internet, under Art. 74(2)-(3) of the Code on Offenses, Law No. 128 (28 October 2021), as introduced by the amending Law No. 176 of 9 August 2023.

The regulatory statute that defines the categories of harmful information and sets additional requirements for its online distribution, the Law on Measures to Prevent Harm to Children's Health, their Physical, Intellectual, Mental, Spiritual and Moral Development, Law No. 185 (21 July 2015), was amended by that same 2023 law to add Art. 2-1 (types of information harmful to children) and Art. 3-1 (additional requirements for distributing such information via information-telecommunications networks and for the circulation of information products prohibited for children); beyond Art. 1's definitions, the two articles' own text is not reproduced in the copy consulted, so they are described here only by their titles.

The Children's Code, Law No. 100 (10 July 2012), read in full, carries no chapter or provision addressing media, information distribution, or an online service; its child-victim-protection chapter (Arts. 98-102) concerns detection and state assistance for children who have already suffered violence or crime, not a duty on a distributor. A Law on Mass Media was named in the same 2023 amending package; its own provisions are not described here.

Adult content age verification (AV)

Code on Offenses, Art. 74(2)-(3): distributing information harmful to children, aggravated for online and mass-media distribution

Code of the Kyrgyz Republic on Offenses, Law No. 128 (28 October 2021), Art. 74(2)-(3), as introduced by Law No. 176 (9 August 2023)text of Art. 74 of the Code of the Kyrgyz Republic on Offenses

In force since 30 August 2023. Binds public and private bodies.

What this law does

Art. 74(2), read in full, fines distributing to children information that causes harm to their health or development and is prohibited for distribution among children, where the conduct does not amount to a criminal offense, at 20 calculation indicators for a natural person and 100 for a legal person.

Art. 74(3) raises that fine to 50 and 250 calculation indicators, respectively, where the same conduct is carried out using mass media or an information-telecommunications network, including the Internet. Contemporaneous press coverage of the amending law's signing reported the resulting fines as 2,000 som for a natural person and 10,000 som for a legal person, rising to 25,000 som for a legal person where the information was published in mass media or on the Internet.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (268 words)

Kyrgyzstan has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the copyright framework of Law No. 6 of 14 January 1998 on Copyright and Related Rights, as amended to Law No. 62 of 17 March 2023, is the only law reaching an aggregator's reproduction of news content.

Article 8 excludes 'daily news or information on current events that constitute regular press information' from copyright altogether, so a bare news item carries no copyright to begin with.

Where an article does carry copyright, Article 19(1)(1) permits, without the author's consent or payment of remuneration, quotation for scientific research, polemic, critical, or informational purposes to the extent justified by the intended purpose, including reproduction of extracts from newspaper and magazine articles in press reviews, and Article 19(1)(3) separately permits reproducing in newspapers, broadcast, or cable the general information newspapers or periodicals publish on current economic, political, social, and religious issues, unless the author has specifically prohibited it.

Neither provision carries a headline-length or short-extract cap distinct from the source-and-author-name and fair-practice conditions, and no reported Kyrgyz decision applies either to a systematic news aggregator rather than an individual quoting a published work. Neighbouring rights under the Law cover performers, phonogram producers, and broadcasting organizations, not a print or online news publisher's own reporting.

No statute or case law addresses whether a hyperlink is a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law was found. The Law predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.