An enquiry form, a customer account and an ‘I agree to data processing’ checkbox can seem like formalities until a company faces an inspection or customer complaint. Handling personal data on a website is regulated by law. The requirements affect not just banks and medical centres, but almost any business whose website asks visitors for a name, phone number or email address.
This guide is for business owners and non-lawyers: what counts as personal data, what the law requires of a website, which technical and organisational measures to plan during development, and which mistakes are common.
What counts as personal data
Personal data is any information relating to an identified or identifiable individual. For a business website, this commonly includes a visitor’s or customer’s name; a phone number or email submitted in an enquiry; a delivery address; account login information and sometimes stored payment details; and an IP address or behavioural information when linked to a specific person, for example through sign-in.
Even a simple enquiry form with name and phone fields means the website collects and processes personal data and is therefore subject to legal requirements.
Which websites fall within the requirements
The requirements apply regardless of business size to websites that collect visitor data: enquiry, feedback and newsletter forms; online stores with accounts and checkout; appointment-booking sites for clinics, salons and education centres; CRM and internal systems holding customer or employee information; and sites using analytics or advertising pixels that collect visitor behaviour data.
Purely informational sites with no data-collection forms are the category to which these requirements do not directly apply in this account. In practice, such sites are rare for active businesses: even a newsletter sign-up banner changes the situation.
How to obtain data-processing consent on a website
Before a user submits a form containing personal information, the website must obtain their consent to process it.
The usual technical implementation includes:
- An ‘I agree to the processing of my personal data’ checkbox beside the submit button that the user actively selects; a preselected box is not treated as valid consent;
- A privacy-policy link beside the checkbox so the user can read the terms before submitting data;
- Validation that prevents submission without consent, rather than leaving the step optional;
- A server-side record of consent, including the date, time and privacy-policy version accepted, which may be needed as evidence during an inspection.
What a privacy policy should contain
A privacy policy is a required document for a website collecting personal data. It is usually published on a separate page linked from the footer and from forms.
| Section | Contents |
|---|---|
| Introduction | Commitment to data privacy |
| Data collection | Information collected and types of personal data |
| Purposes of use | Why and how data is used: analytics, personalisation and service delivery |
| User rights | Access, correction, deletion and opting out |
| Data protection | Encryption, access control, firewall and monitoring |
| Compliance | Security and protection protocols |
| Updates and contacts | Change notifications and support contact details |
Publishing an online privacy-policy template unchanged is risky: it may describe another jurisdiction’s rules or fail to match how the website actually processes data. Adapt the document to the business, preferably with a lawyer’s involvement.
Personal-data storage and security
Information hosting and protection deserve particular attention. A Kazakhstani business serving citizens of Kazakhstan should clarify with a lawyer the requirements for the physical location of servers holding customer databases. This directly affects hosting selection. Database access should be limited to designated employees rather than the entire development or marketing team.
Data should not be retained indefinitely without a lawful basis. If someone submits an enquiry but never becomes a customer, set a defined period after which their record is deleted or anonymised. The same requirements extend to backups, whose access must be protected as carefully as the primary database.
Ask a question or leave a request
Have questions about this topic? Tell the Qazaqsoft team what you need.
By submitting the form, you agree to the processing of personal data.
Technical safeguards during website development
Plan basic safeguards when preparing the technical specification. All pages with personal-information forms should use an encrypted HTTPS connection; otherwise data travels in clear text. Customer account passwords must be stored only as hashes.
Discuss protection against common vulnerabilities such as SQL injection and cross-site scripting explicitly with the contractor before development. Configure admin roles so only authorised personnel can export the full customer database. Log database access to support investigations into possible incidents.
What to do after a leak or incident
First record the incident and assess its scope: identify which data and how many users were affected. Then promptly address the technical vulnerability or incorrect access settings that caused it.
In parallel, consult a lawyer about the procedure and deadlines for notifying the relevant authority and affected individuals, as these processes are regulated by law. Document every response action carefully for subsequent review. Finally, reassess internal processes, update access rules and conduct a security audit to prevent a repeat.
Common business mistakes
Companies often make serious mistakes in handling personal information. The most obvious is having enquiry forms but no privacy policy. Preselected consent boxes that require no active action, or copying a competitor’s document without adapting it to actual company processes, are also significant problems.
Common technical mistakes include storing passwords in plain text and granting every employee unrestricted database access. Companies also forget retention periods, leaving inactive customer records in systems for years, or collect excessive information unrelated to the purpose of the enquiry.




