The aim of this study is to analyze the legal regulation of citizens' digital profiles in the context of the digital transformation of public authorities in Kazakhstan, and to compare it with the regulatory approaches of the EU and OECD countries. The study is based on comparative legal analysis, the normative-dogmatic method, an institutional approach, legal modeling, and a qualitative synthesis of legislative, judicial, and supervisory materials. The theoretical contribution of the study lies in conceptualizing citizens' digital profiles not as technical administrative tools but as legally regulated governance infrastructures that mediate relations between the state and the individual within centralized digital systems. The study identified three key legal risks of centralized digital governance in Kazakhstan: unlawful processing of personal data due to broad inter-agency access without differentiated regimes and procedural restrictions; the secondary use of personal data beyond the original administrative purpose due to the absence of clear prohibitions; systemic data breaches caused by fragmented cybersecurity regulation and the predominantly reactive nature of accountability mechanisms. In contrast, the EU and OECD approaches are based on convergent, rights-based governance models featuring independent institutional oversight, mandatory data protection impact assessments, and differentiated access regimes. The study substantiates the need for three priority areas of legal modernization in Kazakhstan: the introduction of mandatory preventive legal risk assessment procedures, the establishment of independent institutional oversight, and the implementation of differentiated access regimes for personal data.