The Agency for Regulation and Development of the Financial Market of the Republic of Kazakhstan has advised users to review mobile app permissions and grant access only when required for an app’s core functions. Unnecessary access to location data, cameras, microphones, contacts, files, text messages and notifications increases the risk of personal data leaks, misuse and fraud, particularly if an app or its developer’s infrastructure is compromised. Users should limit location access to periods when an app is in use and deny camera, microphone, contact or file access where it is not functionally necessary. The agency advised heightened caution when apps request unrelated permissions, lack reliable developer information, come from unofficial sources or seek access to text messages, payment information or other confidential data without a clear need.