#
A comprehensive statute and designated enforcer exist and are operative, but the enforcer lacks independence/resources and the substantive law is materially outdated relative to GDPR.
Sub-modules (5)
Regulator And AuthorityAmber
The Ombudsman is a Parliamentary commissioner, not a standalone DPA, and has historically been under-resourced.
Claims (2):
- Data protection supervision and enforcement in Ukraine is carried out by the Verkhovna Rada Commissioner for Human Rights (Ombudsman), which functions as a Parliamentary human-rights body rather than a standalone, independent data protection authority.
- The Ombudsman's Department for Personal Data Protection has historically operated with a small staff (reported at 13 personnel) and a limited budget, raising concerns about its capacity to supervise data protection across Ukraine's population.
Act And InstrumentsAmber
Law No. 2297-VI is the primary in-force instrument; a GDPR-aligned successor remains a draft.
Claims (1):
- The primary data protection statute currently in force in Ukraine is the Law of 1 June 2010 No. 2297-VI on Personal Data Protection (as amended), which entered into force on 1 January 2011.
Material ScopeAmber
The Law covers automated and structured (catalogued) personal data processing, rooted in Convention 108 and Directive 95/46/EC concepts.
Claims (1):
- The Personal Data Protection Law was originally modelled on Council of Europe Convention 108 and the EU's Data Protection Directive 95/46/EC, and governs automated and structured (catalogued) processing of personal data by controllers in Ukraine.
Territorial ScopeAmber
No explicit extraterritorial-effect clause exists under current law; the pending draft law is also not expected to adopt one explicitly.
Claims (2):
- Under the current 2010 Law, Ukraine's data protection regime does not have an explicit extraterritorial-effect provision, though Ukrainian controllers should still consider the GDPR's own extraterritorial reach where relevant.
- The pending draft data protection law is not expected to include an explicit extraterritorial-effect clause, but non-resident controllers that collect and process personal data in Ukraine will likely still need to comply with the new law once enacted.
Regulator Registration And FilingAmber
Historic database-registration formalities were abolished; current notification duties attach to high-risk data processing and DPO appointments.
Claims (2):
- Under early implementation of the 2010 Law, the State Service of Ukraine for Personal Data Protection required companies to register their personal-data databases, a formality later abolished after the Service's functions were transferred to the Ombudsman in 2014.
- Controllers processing 'data constituting a high risk to individuals' rights and freedoms' must notify the Ombudsman of such processing and of the related DPO appointment, except where the data is processed solely to fulfil the controller's employment obligations.
Regulator & Framework
Ukraine's data-protection framework rests on two layers that are moving at different speeds. The governing statute, the Law on Personal Data Protection No. 2297-VI, has been in force since 1 January 2011, predating the GDPR and tracking the earlier EU Directive 95/46 in its structure and terminology. Supervisory authority sits with the Ukrainian Parliament Commissioner for Human Rights, the Ombudsman, an institution embedded within the broader human-rights ombudsman function rather than constituted as a standalone, independent data-protection authority of the kind now standard across the EU.
The more consequential development, and the reason this module carries material change this cycle, is Draft Law No. 8153, a comprehensive GDPR-alignment reform that would create an independent supervisory authority separate from the Ombudsman's office and expand the data-subject rights available under current law. The draft passed its first reading in the Verkhovna Rada on 20 November 2024 and, as at mid-2026, remained in preparation for a second reading, not yet enacted or in force. This first-reading passage represents genuine legislative movement, but the reform's ultimate shape and timeline through second reading and beyond were not confirmed against a primary Verkhovna Rada bill-tracker page this cycle, and the precise committee status was not resolved from the sources available.
The practical reality for any entity processing personal data in Ukraine today is that the 2011-vintage statute, not the pending reform, remains the operative law. Compliance obligations should be assessed against the current statute's structure, not against Draft Law No. 8153's proposed independent-authority and expanded-rights provisions, which carry no present legal force.
Outlook
The second-reading timeline for Draft Law No. 8153 is the single most consequential forward marker for this module, currently estimated at a 2027 Q2 horizon under a multi-year uncertainty band, though this estimate was not corroborated against a primary legislative-tracker source this cycle. Should the draft advance to enactment, Ukraine would gain, for the first time, an independent data-protection supervisory authority distinct from the Ombudsman's office, a structural shift that would also determine how the enforcement powers described below in Enforcement & Redress ultimately take shape.
1 earlier distinct update(s)
Regulator & Framework
Ukraine's data-protection supervisory model remains structurally distinct from most EU peers. The Ukrainian Parliament Commissioner for Human Rights, commonly referred to as the Ombudsman, functions as the country's data-protection supervisory authority, with confirmed statutory power to receive complaints, conduct inspections, and issue binding orders and administrative sanctions. This is a probable finding sourced to Linklaters' comparative data-protection guide, though the underlying institutional arrangement — supervision embedded within an ombudsman institution rather than a standalone independent data-protection authority — is a well-established structural feature of the Ukrainian regime rather than a new development this cycle.
The core statute, the Law of Ukraine "On Personal Data Protection" No. 2297-VI, was adopted 1 June 2010 and has been in force since 1 January 2011, with its current consolidated text as amended on 14 June 2025, confirmed directly via the Verkhovna Rada's own legal database. This is the durable statutory backbone of the regime.
The principal reform effort, Draft Law No. 8153, aims to align Ukraine's data-protection regime with the GDPR and with Council of Europe Convention 108+, and passed its first reading in the Verkhovna Rada on 20 November 2024. As of a December 2025 legislative-tracker entry, it remains pending second-reading preparation — confirmed evidence that the reform, while advancing, has not yet been enacted. A related, probable development is that the mandatory Ombudsman database-registration requirement has reportedly been removed for most processing categories by amendment, while sensitive-data processing continues to require notification to the Ombudsman; this rests on secondary legal-firm commentary rather than a directly identified amending instrument this cycle.
Taken together, the framework this cycle presents a structural continuity rather than a discrete change: an Ombudsman-embedded supervisory model, a durable 2010/2011 core statute, and a GDPR-alignment reform that continues to advance through the legislative process without having yet closed the structural gap between Ukraine's current regime and the EU model it is designed to approach.
Outlook
The regulatory horizon places Draft Law No. 8153's second-reading preparation around 2026 Q4 at Confirmed confidence, sourced to the Verkhovna Rada's own bill tracker. If enacted, it would introduce a formal data-protection-officer institution, a breach-notification procedure, expanded data-subject rights, and cross-border-transfer rules — but the Ombudsman-embedded supervisory structure itself is expected to persist unchanged, per this cycle's key judgment, meaning the reform closes specific compliance gaps without altering Ukraine's foundational institutional choice.
Sources and claims (8)
- ProbableIAPP — Data protection supervision and enforcement in Ukraine is carried out by the Verkhovna Rada Commissioner for Human Rights (Ombudsman), which functions as a Parliamentary human-rights body rather than a standalone, independent data protection authority.observed
- ProbableIAPP — The Ombudsman's Department for Personal Data Protection has historically operated with a small staff (reported at 13 personnel) and a limited budget, raising concerns about its capacity to supervise data protection across Ukraine's population.observed
- ProbableDataGuidance — The primary data protection statute currently in force in Ukraine is the Law of 1 June 2010 No. 2297-VI on Personal Data Protection (as amended), which entered into force on 1 January 2011.observed
- ProbableDataGuidance — The Personal Data Protection Law was originally modelled on Council of Europe Convention 108 and the EU's Data Protection Directive 95/46/EC, and governs automated and structured (catalogued) processing of personal data by controllers in Ukraine.observed
- ProbableDataGuidance — Under the current 2010 Law, Ukraine's data protection regime does not have an explicit extraterritorial-effect provision, though Ukrainian controllers should still consider the GDPR's own extraterritorial reach where relevant.observed
- UncertainDataGuidance — The pending draft data protection law is not expected to include an explicit extraterritorial-effect clause, but non-resident controllers that collect and process personal data in Ukraine will likely still need to comply with the new law once enacted.observed
- ProbableDataGuidance — Under early implementation of the 2010 Law, the State Service of Ukraine for Personal Data Protection required companies to register their personal-data databases, a formality later abolished after the Service's functions were transferred to the Ombudsman in 2014.observed
- ProbableIAPP — Controllers processing 'data constituting a high risk to individuals' rights and freedoms' must notify the Ombudsman of such processing and of the related DPO appointment, except where the data is processed solely to fulfil the controller's employment obligations.observed