🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
UA v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing13 sources retrieved model claude-sonnet-5 · 2026-08-05

Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

Ukraine

UA schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 37 claims · 23 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
37Claimsbaseline..claims[]
5Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Ukraine's data-protection regime remains structurally pre-GDPR while a comprehensive alignment reform edges forward through the legislative process. The governing statute, the Law on Personal Data Protection No. 2297-VI, has been in force since 1 January 2011 and tracks the earlier EU Directive 95/46 rather than the GDPR, predating the framework that most European counterparts now operate under. Draft Law No. 8153, which would create an independent data protection authority and expand data-subject rights, passed its first reading in the Verkhovna Rada on 20 November 2024 and, as at mid-2026, remained in preparation for a second reading without having been enacted or brought into force.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A comprehensive statute and designated enforcer exist and are operative, but the enforcer lacks independence/resources and the substantive law is materially outdated relative to GDPR.

Primary frameworkLaw of Ukraine No. 2297-VI 'On Personal Data Protection' (1 June 2010, as amended)
Traffic-light rationale — AmberA comprehensive statute and designated enforcer exist and are operative, but the enforcer lacks independence/resources and the substantive law is materially outdated relative to GDPR.

Sub-modules (5)

Regulator And AuthorityAmber

The Ombudsman is a Parliamentary commissioner, not a standalone DPA, and has historically been under-resourced.

Claims (2):

  • Data protection supervision and enforcement in Ukraine is carried out by the Verkhovna Rada Commissioner for Human Rights (Ombudsman), which functions as a Parliamentary human-rights body rather than a standalone, independent data protection authority.
  • The Ombudsman's Department for Personal Data Protection has historically operated with a small staff (reported at 13 personnel) and a limited budget, raising concerns about its capacity to supervise data protection across Ukraine's population.

Act And InstrumentsAmber

Law No. 2297-VI is the primary in-force instrument; a GDPR-aligned successor remains a draft.

Claims (1):

  • The primary data protection statute currently in force in Ukraine is the Law of 1 June 2010 No. 2297-VI on Personal Data Protection (as amended), which entered into force on 1 January 2011.

Material ScopeAmber

The Law covers automated and structured (catalogued) personal data processing, rooted in Convention 108 and Directive 95/46/EC concepts.

Claims (1):

  • The Personal Data Protection Law was originally modelled on Council of Europe Convention 108 and the EU's Data Protection Directive 95/46/EC, and governs automated and structured (catalogued) processing of personal data by controllers in Ukraine.

Territorial ScopeAmber

No explicit extraterritorial-effect clause exists under current law; the pending draft law is also not expected to adopt one explicitly.

Claims (2):

  • Under the current 2010 Law, Ukraine's data protection regime does not have an explicit extraterritorial-effect provision, though Ukrainian controllers should still consider the GDPR's own extraterritorial reach where relevant.
  • The pending draft data protection law is not expected to include an explicit extraterritorial-effect clause, but non-resident controllers that collect and process personal data in Ukraine will likely still need to comply with the new law once enacted.

Regulator Registration And FilingAmber

Historic database-registration formalities were abolished; current notification duties attach to high-risk data processing and DPO appointments.

Claims (2):

  • Under early implementation of the 2010 Law, the State Service of Ukraine for Personal Data Protection required companies to register their personal-data databases, a formality later abolished after the Service's functions were transferred to the Ombudsman in 2014.
  • Controllers processing 'data constituting a high risk to individuals' rights and freedoms' must notify the Ombudsman of such processing and of the related DPO appointment, except where the data is processed solely to fulfil the controller's employment obligations.
Category narrative61 words

Ukraine's data protection regime rests on the Law of 1 June 2010 No. 2297-VI 'On Personal Data Protection' (as amended), enforced by the Verkhovna Rada Commissioner for Human Rights (Ombudsman), which acts as a Parliamentary human-rights body rather than an independent DPA. A GDPR-alignment draft law has been pending since 2022 (following a rejected 2021 bill) but has not been enacted.

Periodic update · new data 2026-09-28

Regulator & Framework

Ukraine's data-protection framework rests on two layers that are moving at different speeds. The governing statute, the Law on Personal Data Protection No. 2297-VI, has been in force since 1 January 2011, predating the GDPR and tracking the earlier EU Directive 95/46 in its structure and terminology. Supervisory authority sits with the Ukrainian Parliament Commissioner for Human Rights, the Ombudsman, an institution embedded within the broader human-rights ombudsman function rather than constituted as a standalone, independent data-protection authority of the kind now standard across the EU.

The more consequential development, and the reason this module carries material change this cycle, is Draft Law No. 8153, a comprehensive GDPR-alignment reform that would create an independent supervisory authority separate from the Ombudsman's office and expand the data-subject rights available under current law. The draft passed its first reading in the Verkhovna Rada on 20 November 2024 and, as at mid-2026, remained in preparation for a second reading, not yet enacted or in force. This first-reading passage represents genuine legislative movement, but the reform's ultimate shape and timeline through second reading and beyond were not confirmed against a primary Verkhovna Rada bill-tracker page this cycle, and the precise committee status was not resolved from the sources available.

The practical reality for any entity processing personal data in Ukraine today is that the 2011-vintage statute, not the pending reform, remains the operative law. Compliance obligations should be assessed against the current statute's structure, not against Draft Law No. 8153's proposed independent-authority and expanded-rights provisions, which carry no present legal force.

Outlook

The second-reading timeline for Draft Law No. 8153 is the single most consequential forward marker for this module, currently estimated at a 2027 Q2 horizon under a multi-year uncertainty band, though this estimate was not corroborated against a primary legislative-tracker source this cycle. Should the draft advance to enactment, Ukraine would gain, for the first time, an independent data-protection supervisory authority distinct from the Ombudsman's office, a structural shift that would also determine how the enforcement powers described below in Enforcement & Redress ultimately take shape.

1 earlier distinct update(s)
Periodic update · new data 2026-09-14

Regulator & Framework

Ukraine's data-protection supervisory model remains structurally distinct from most EU peers. The Ukrainian Parliament Commissioner for Human Rights, commonly referred to as the Ombudsman, functions as the country's data-protection supervisory authority, with confirmed statutory power to receive complaints, conduct inspections, and issue binding orders and administrative sanctions. This is a probable finding sourced to Linklaters' comparative data-protection guide, though the underlying institutional arrangement — supervision embedded within an ombudsman institution rather than a standalone independent data-protection authority — is a well-established structural feature of the Ukrainian regime rather than a new development this cycle.

The core statute, the Law of Ukraine "On Personal Data Protection" No. 2297-VI, was adopted 1 June 2010 and has been in force since 1 January 2011, with its current consolidated text as amended on 14 June 2025, confirmed directly via the Verkhovna Rada's own legal database. This is the durable statutory backbone of the regime.

The principal reform effort, Draft Law No. 8153, aims to align Ukraine's data-protection regime with the GDPR and with Council of Europe Convention 108+, and passed its first reading in the Verkhovna Rada on 20 November 2024. As of a December 2025 legislative-tracker entry, it remains pending second-reading preparation — confirmed evidence that the reform, while advancing, has not yet been enacted. A related, probable development is that the mandatory Ombudsman database-registration requirement has reportedly been removed for most processing categories by amendment, while sensitive-data processing continues to require notification to the Ombudsman; this rests on secondary legal-firm commentary rather than a directly identified amending instrument this cycle.

Taken together, the framework this cycle presents a structural continuity rather than a discrete change: an Ombudsman-embedded supervisory model, a durable 2010/2011 core statute, and a GDPR-alignment reform that continues to advance through the legislative process without having yet closed the structural gap between Ukraine's current regime and the EU model it is designed to approach.

Outlook

The regulatory horizon places Draft Law No. 8153's second-reading preparation around 2026 Q4 at Confirmed confidence, sourced to the Verkhovna Rada's own bill tracker. If enacted, it would introduce a formal data-protection-officer institution, a breach-notification procedure, expanded data-subject rights, and cross-border-transfer rules — but the Ombudsman-embedded supervisory structure itself is expected to persist unchanged, per this cycle's key judgment, meaning the reform closes specific compliance gaps without altering Ukraine's foundational institutional choice.

Sources and claims (8)
  1. ProbableIAPP — Data protection supervision and enforcement in Ukraine is carried out by the Verkhovna Rada Commissioner for Human Rights (Ombudsman), which functions as a Parliamentary human-rights body rather than a standalone, independent data protection authority.observed
  2. ProbableIAPP — The Ombudsman's Department for Personal Data Protection has historically operated with a small staff (reported at 13 personnel) and a limited budget, raising concerns about its capacity to supervise data protection across Ukraine's population.observed
  3. ProbableDataGuidance — The primary data protection statute currently in force in Ukraine is the Law of 1 June 2010 No. 2297-VI on Personal Data Protection (as amended), which entered into force on 1 January 2011.observed
  4. ProbableDataGuidance — The Personal Data Protection Law was originally modelled on Council of Europe Convention 108 and the EU's Data Protection Directive 95/46/EC, and governs automated and structured (catalogued) processing of personal data by controllers in Ukraine.observed
  5. ProbableDataGuidance — Under the current 2010 Law, Ukraine's data protection regime does not have an explicit extraterritorial-effect provision, though Ukrainian controllers should still consider the GDPR's own extraterritorial reach where relevant.observed
  6. UncertainDataGuidance — The pending draft data protection law is not expected to include an explicit extraterritorial-effect clause, but non-resident controllers that collect and process personal data in Ukraine will likely still need to comply with the new law once enacted.observed
  7. ProbableDataGuidance — Under early implementation of the 2010 Law, the State Service of Ukraine for Personal Data Protection required companies to register their personal-data databases, a formality later abolished after the Service's functions were transferred to the Ombudsman in 2014.observed
  8. ProbableIAPP — Controllers processing 'data constituting a high risk to individuals' rights and freedoms' must notify the Ombudsman of such processing and of the related DPO appointment, except where the data is processed solely to fulfil the controller's employment obligations.observed

#

Lawful bases and a special-category analogue exist and are enforced, but consent-practice distortion and the absence of confirmed pseudonymisation/anonymisation provisions weaken alignment with GDPR-equivalent standards.

Primary frameworkLaw of Ukraine No. 2297-VI 'On Personal Data Protection'
Traffic-light rationale — AmberLawful bases and a special-category analogue exist and are enforced, but consent-practice distortion and the absence of confirmed pseudonymisation/anonymisation provisions weaken alignment with GDPR-equivalent standards.

Sub-modules (4)

Lawful BasesAmber

Six statutory grounds for processing exist, analogous to but not congruent with GDPR Article 6.

Claims (1):

  • Ukrainian law enumerates six legal grounds for the processing of personal data, including consent, contractual necessity, protection of vital interests, public interest/legal-claims grounds, and protection against interference with personal and family life.

Special CategoriesAmber

A 2014-introduced 'high risk' data category functions as Ukraine's special-category analogue, with a broader scope than GDPR Art 9 in some respects.

Claims (1):

  • 2014 amendments to the Personal Data Protection Law introduced the concept of 'data constituting a high risk to individuals' rights and freedoms,' comparable to GDPR special categories but additionally covering criminal-conviction data, location/route data, and data on whether a person suffered violence or abuse, triggering a mandatory DPO appointment.

Pseudonymisation And AnonymisationRed

No statutory pseudonymisation/anonymisation definition or safe-harbour was identified in the current Law or in the secondary sources reviewed for this run (searched dataguidance/IAPP Ukraine overviews and draft-law commentary).

Category narrative61 words

The 2010 Law enumerates six legal grounds for processing, broadly paralleling GDPR Art 6 in structure but with divergent detail; consent is disproportionately relied upon in practice. A 2014 amendment created a 'high risk' special-category-like concept. No statutory pseudonymisation/anonymisation safe-harbour was located in this pass (searched: 'Ukraine personal data pseudonymisation anonymisation law', general law texts) — treated as an evidentiary gap.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ProbableIAPP — Ukrainian law enumerates six legal grounds for the processing of personal data, including consent, contractual necessity, protection of vital interests, public interest/legal-claims grounds, and protection against interference with personal and family life.observed
  2. ProbableIAPP — In practice, consent is the most frequently used—and frequently misapplied—legal basis for processing in Ukraine, often bundled into standard-form documents in ways inconsistent with a 'freely given' consent standard.observed
  3. ProbableIAPP — 2014 amendments to the Personal Data Protection Law introduced the concept of 'data constituting a high risk to individuals' rights and freedoms,' comparable to GDPR special categories but additionally covering criminal-conviction data, location/route data, and data on whether a person suffered violence or abuse, triggering a mandatory DPO appointment.observed

#

Access/transparency mechanics exist and are enforced, but portability, restriction, and objection rights are not confirmed to exist in GDPR-equivalent form under the current statute.

Primary frameworkLaw of Ukraine No. 2297-VI 'On Personal Data Protection'
Traffic-light rationale — AmberAccess/transparency mechanics exist and are enforced, but portability, restriction, and objection rights are not confirmed to exist in GDPR-equivalent form under the current statute.

Sub-modules (5)

Access RightAmber

General access/transparency rights exist under the Law's data-subject-rights provisions.

Claims (1):

  • Controllers must inform individuals of the fact and purpose of personal data processing at the time of collection, or within 30 days where data is collected from third parties rather than directly from the data subject.

Rectification And ErasureAmber

The Law provides general data-subject rights and controller obligations, but granular rectification/erasure mechanics comparable to GDPR were not independently confirmed.

Claims (1):

  • The Personal Data Protection Law provides for general data-subject rights and controller obligations, but commentators note the law retains outdated elements and lacks comprehensive enforcement and compliance measures relative to the GDPR's risk-based approach.

Restriction And ObjectionRed

No GDPR Article 21-equivalent objection right was confirmed under the current Law in this research pass (searched dataguidance/IAPP Ukraine data-subject-rights commentary).

Data PortabilityRed

No statutory portability right exists under the current Law; the pending draft law aims to introduce GDPR-aligned rights generally.

Claims (1):

  • The 2021/2022 draft data protection law is intended to align Ukraine's data-subject rights framework, including portability-type rights, with the GDPR, but no explicit statutory right to data portability exists under the current in-force law.

Deadlines And Response WindowsAmber

A 30-day notification deadline applies where personal data is collected from third parties rather than directly from the data subject.

Claims (1):

  • Controllers must inform individuals of the fact and purpose of personal data processing at the time of collection, or within 30 days where data is collected from third parties rather than directly from the data subject.
Category narrative44 words

The current Law provides for general data-subject rights and a 30-day transparency deadline for third-party-sourced data, but secondary commentary indicates it lacks GDPR-equivalent granularity for rights such as portability and objection to automated decisions; the pending draft law is intended to close this gap.

Sources and claims (3)
  1. ProbableIAPP — Controllers must inform individuals of the fact and purpose of personal data processing at the time of collection, or within 30 days where data is collected from third parties rather than directly from the data subject.observed
  2. ProbableDataGuidance — The Personal Data Protection Law provides for general data-subject rights and controller obligations, but commentators note the law retains outdated elements and lacks comprehensive enforcement and compliance measures relative to the GDPR's risk-based approach.observed
  3. UncertainDataGuidance — The 2021/2022 draft data protection law is intended to align Ukraine's data-subject rights framework, including portability-type rights, with the GDPR, but no explicit statutory right to data portability exists under the current in-force law.observed

#

DPO/ROPA/security obligations are confirmed and enforced; breach notification and DPIA obligations are confirmed absent or unconfirmed, which is materially significant.

Primary frameworkLaw of Ukraine No. 2297-VI 'On Personal Data Protection'
Traffic-light rationale — AmberDPO/ROPA/security obligations are confirmed and enforced; breach notification and DPIA obligations are confirmed absent or unconfirmed, which is materially significant.

Sub-modules (7)

Accountability And DpiaRed

As of the most recent guidance review located, the Ombudsman had not issued DPIA-specific guidance and no statutory DPIA obligation was confirmed.

Claims (1):

  • As of a November 2021 guidance review, the Ombudsman had not issued specific guidance on data protection impact assessments, and no statutory DPIA obligation equivalent to GDPR Article 35 was identified under the current Personal Data Protection Law.

Dpo RequirementsAmber

A DPO must be appointed for processing of 'high risk' data, a narrower/differently defined trigger than GDPR's large-scale monitoring/special-category threshold.

Claims (1):

  • Ukrainian controllers must appoint a DPO where they process data constituting a high risk to individuals' rights and freedoms, a narrower and differently defined trigger than the GDPR's large-scale monitoring/special-category threshold for mandatory DPO appointment.

Ropa RequirementsAmber

Ombudsman orders require a register of data-processing operations for high-risk data controllers.

Claims (1):

  • Pursuant to Ombudsman orders, companies handling high-risk personal data must maintain a register of data-processing operations, prepare an incident-response plan, implement access policies and confidentiality agreements, and provide regular staff training.

Joint Controller ArrangementsRed

No joint-controller-specific provision was identified in the sources reviewed (searched dataguidance/IAPP Ukraine controller-processor commentary).

Security MeasuresAmber

Ombudsman orders require incident-response plans, access policies, confidentiality agreements and staff training for high-risk data processing.

Claims (1):

  • Pursuant to Ombudsman orders, companies handling high-risk personal data must maintain a register of data-processing operations, prepare an incident-response plan, implement access policies and confidentiality agreements, and provide regular staff training.

Breach NotificationRed

Commentary on the 2021 draft law explicitly notes it does not stipulate specific data-breach notification requirements; no equivalent requirement was confirmed under the current 2010 Law either.

Claims (1):

  • Commentators reviewing the 2021 draft data protection law noted that it does not stipulate any specific data-breach notification requirements, indicating that even Ukraine's pending GDPR-alignment reform had not, at that stage, replicated the GDPR's mandatory breach-notification regime.

Retention And DisposalRed

No statutory retention-period or disposal-duty detail was located in this research pass (searched dataguidance/IAPP Ukraine retention commentary).

Category narrative61 words

Controllers handling 'high-risk' data face DPO-appointment, ROPA, and security-measure obligations issued via Ombudsman order. DPIA and breach-notification requirements comparable to GDPR Articles 33-35 were not confirmed even in the pending draft law, which was specifically noted by commentators as omitting breach-notification requirements. Joint-controller and retention/disposal rules were not located in this pass (searched: 'Ukraine data controller processor duties retention breach notification').

Sources and claims (4)
  1. ProbableIAPP — Ukrainian controllers must appoint a DPO where they process data constituting a high risk to individuals' rights and freedoms, a narrower and differently defined trigger than the GDPR's large-scale monitoring/special-category threshold for mandatory DPO appointment.observed
  2. ProbableIAPP — Pursuant to Ombudsman orders, companies handling high-risk personal data must maintain a register of data-processing operations, prepare an incident-response plan, implement access policies and confidentiality agreements, and provide regular staff training.observed
  3. ProbableDataGuidance — As of a November 2021 guidance review, the Ombudsman had not issued specific guidance on data protection impact assessments, and no statutory DPIA obligation equivalent to GDPR Article 35 was identified under the current Personal Data Protection Law.observed
  4. ProbableDataGuidance — Commentators reviewing the 2021 draft data protection law noted that it does not stipulate any specific data-breach notification requirements, indicating that even Ukraine's pending GDPR-alignment reform had not, at that stage, replicated the GDPR's mandatory breach-notification regime.observed

#

A functioning transfer framework exists with adequacy-style logic, but no EU adequacy decision covers Ukraine, and TIA/localisation specifics remain unconfirmed gaps.

Primary frameworkLaw of Ukraine No. 2297-VI 'On Personal Data Protection'; Council of Europe Convention 108
Traffic-light rationale — AmberA functioning transfer framework exists with adequacy-style logic, but no EU adequacy decision covers Ukraine, and TIA/localisation specifics remain unconfirmed gaps.

Sub-modules (6)

Transfer MechanismsAmber

A general prohibition on international transfers applies unless statutory conditions are met.

Claims (1):

  • Ukrainian legislation establishes a general prohibition on international transfers of personal data unless specific statutory conditions are met.

Adequacy ReceivedAmber

The EU has not adopted an adequacy decision for Ukraine.

Claims (1):

  • The European Union has not adopted an adequacy decision in respect of Ukraine, meaning transfers of personal data from the EU/EEA to Ukraine cannot rely on an Article 45 GDPR adequacy finding.

Adequacy GrantedAmber

Ukraine deems EEA states and Convention 108 signatories adequate for outbound transfers; no further country list has been issued by the Cabinet of Ministers.

Claims (1):

  • Under the current Law, EEA member states and Convention 108 signatories are automatically deemed to provide an adequate level of data protection for outbound transfers from Ukraine, and the Cabinet of Ministers may designate further adequate countries, though no such list has been issued since the Law's adoption.

Sccs And BcrsAmber

Current law permits transfers via consent or contractual necessity; the draft law would add GDPR Art 46/47/49-style safeguards.

Claims (2):

  • Beyond the adequacy-country list, current Ukrainian law permits international transfers on the basis of unambiguous data-subject consent or contractual necessity.
  • The pending draft law mirrors to a significant extent the GDPR's Articles 46 and 47 safeguards (SCC/BCR-equivalent mechanisms) and replicates Article 49-style derogations for unsafe transfers.

Transfer Impact AssessmentRed

No TIA-equivalent requirement was identified in the sources reviewed for this run.

Data LocalisationRed

A 2021 dataguidance headline references 'data localisation amendments to the Personal Data Protection Law,' but the substantive content was not accessible (paywalled) in this research pass; no localisation mandate could be confirmed or described with confidence (searched: 'Ukraine data localisation amendments personal data law 2021 requirement').

Category narrative64 words

Ukraine operates a Convention-108-anchored transfer regime: EEA states and other Convention 108 signatories are deemed adequate for outbound transfers, and the Cabinet of Ministers may (but has not) designate further adequate countries. The EU has not granted Ukraine an inbound adequacy decision. A headline reference to 2021 'data localisation amendments' could not be substantively verified (source paywalled) and a transfer-impact-assessment requirement was not confirmed.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ProbableIAPP — Ukrainian legislation establishes a general prohibition on international transfers of personal data unless specific statutory conditions are met.observed
  2. ProbableIAPP — Under the current Law, EEA member states and Convention 108 signatories are automatically deemed to provide an adequate level of data protection for outbound transfers from Ukraine, and the Cabinet of Ministers may designate further adequate countries, though no such list has been issued since the Law's adoption.observed
  3. ProbableDataGuidance — The European Union has not adopted an adequacy decision in respect of Ukraine, meaning transfers of personal data from the EU/EEA to Ukraine cannot rely on an Article 45 GDPR adequacy finding.observed
  4. ProbableIAPP — Beyond the adequacy-country list, current Ukrainian law permits international transfers on the basis of unambiguous data-subject consent or contractual necessity.observed
  5. ProbableDataGuidance — The pending draft law mirrors to a significant extent the GDPR's Articles 46 and 47 safeguards (SCC/BCR-equivalent mechanisms) and replicates Article 49-style derogations for unsafe transfers.observed

#

Only two of seven sub-modules have confirmed evidentiary support; the remainder are unconfirmed gaps, so the module is marked red per gap discipline.

Primary frameworkLaw of Ukraine No. 2297-VI 'On Personal Data Protection'
Traffic-light rationale — RedOnly two of seven sub-modules have confirmed evidentiary support; the remainder are unconfirmed gaps, so the module is marked red per gap discipline.

Sub-modules (7)

Financial Sector OverlayRed

No confirmed financial-sector-specific data protection overlay was identified in this research pass.

Health Sector OverlayAmber

Children's medical data is processed under the same general rules as adult medical data, with consent typically obtained from parents/guardians.

Claims (1):

  • Ukraine has no bespoke statutory regime for children's medical data; such data is subject to the same general rules as adult medical data, with consent for processing typically obtained from parents or legal guardians on the child's behalf.

Telecoms And EprivacyRed

No confirmed telecoms/eprivacy-specific overlay was identified in this research pass.

Employment DataAmber

Employers must notify employees of data processing and maintain related internal documentation and security measures.

Claims (1):

  • Ukrainian employers must notify employees of personal data processing at the point of collection (or within 30 days if data is sourced from third parties) and maintain internal policies, incident-response plans, and confidentiality agreements covering employee data processing.

Credit And ScoringRed

No confirmed credit-scoring-specific overlay was identified in this research pass.

EducationRed

No confirmed education-sector-specific overlay was identified in this research pass.

InsuranceRed

No confirmed insurance-sector-specific overlay was identified in this research pass.

Category narrative69 words

Confirmed sectoral evidence was limited to employment data (notification/ROPA/security duties under Ombudsman orders) and a general health-data note (children's medical data treated under general adult rules, with parental consent). Financial-sector, telecoms/eprivacy, credit-scoring, education, and insurance overlays could not be confirmed in this pass (searched: 'Ukraine financial sector data protection overlay', 'Ukraine telecoms eprivacy law', 'Ukraine credit scoring data protection', 'Ukraine education sector data protection', 'Ukraine insurance data protection law').

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. ProbableIAPP — Ukrainian employers must notify employees of personal data processing at the point of collection (or within 30 days if data is sourced from third parties) and maintain internal policies, incident-response plans, and confidentiality agreements covering employee data processing.observed
  2. ProbableDataGuidance — Ukraine has no bespoke statutory regime for children's medical data; such data is subject to the same general rules as adult medical data, with consent for processing typically obtained from parents or legal guardians on the child's behalf.observed

#

No sub-module has confirmed evidence of a specific adtech/commercial-privacy regime; this is an explicit, evidenced gap rather than silent omission.

Primary frameworkLaw of Ukraine No. 2297-VI 'On Personal Data Protection'
Traffic-light rationale — RedNo sub-module has confirmed evidence of a specific adtech/commercial-privacy regime; this is an explicit, evidenced gap rather than silent omission.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker-consent-specific statutory regime was confirmed in this research pass.

Claims (1):

  • Ukraine's current Personal Data Protection Law predates the emergence of modern adtech practices and does not contain specific rules on cookie consent, dark patterns, universal opt-out signals, data clean rooms, or cross-context advertising; commentators describe the law as retaining outdated elements relative to the GDPR's risk-based approach.

Dark PatternsRed

No dark-pattern-specific prohibition was confirmed in this research pass.

Opt Out SignalsRed

No universal opt-out-signal (e.g., GPC-equivalent) mechanism was confirmed in this research pass.

Clean Rooms And DcrRed

No data-clean-room-specific rule was confirmed in this research pass.

Cross Context AdvertisingRed

No cross-context-advertising / 'sale'-or-'share'-equivalent concept was confirmed in this research pass.

Direct MarketingRed

No direct-marketing-specific consent or suppression regime was confirmed in this research pass.

Category narrative57 words

No confirmed cookie-consent, dark-pattern, opt-out-signal, data-clean-room, cross-context-advertising, or direct-marketing-specific statutory provisions were identified for Ukraine in this research pass (searched: 'Ukraine cookie law consent', 'Ukraine dark patterns data protection', 'Ukraine direct marketing consent law'). Commentators generally describe the current law as retaining outdated elements relative to GDPR's risk-based, modern approach, consistent with the absence of adtech-specific rules.

Sources and claims (1)
  1. ProbableDataGuidance — Ukraine's current Personal Data Protection Law predates the emergence of modern adtech practices and does not contain specific rules on cookie consent, dark patterns, universal opt-out signals, data clean rooms, or cross-context advertising; commentators describe the law as retaining outdated elements relative to the GDPR's risk-based approach.observed

#

Only non-binding AI policy guidance and a constitutional surveillance carve-out are confirmed; the majority of sub-modules (profiling, ADM transparency, biometric regime, genetic data) lack confirmed evidence.

Primary frameworkConstitution of Ukraine, Article 32; non-binding Ministry of Digital Transformation AI guidance
Traffic-light rationale — RedOnly non-binding AI policy guidance and a constitutional surveillance carve-out are confirmed; the majority of sub-modules (profiling, ADM transparency, biometric regime, genetic data) lack confirmed evidence.

Sub-modules (6)

Profiling RestrictionsRed

No GDPR Article 22-equivalent profiling restriction was confirmed in this research pass.

Automated Decision Making TransparencyRed

No ADM-transparency-specific statutory right was confirmed in this research pass.

Ai Risk AssessmentsAmber

Non-binding Ministry of Digital Transformation AI guidance exists, alongside alignment with the Council of Europe AI Framework Convention, but no binding AI-risk-assessment statute was confirmed.

Claims (1):

  • Ukraine's Ministry of Digital Transformation has issued non-binding guidance on AI assistants/agents and is aligning national AI-related policy with the Council of Europe's Framework Convention on Artificial Intelligence, focusing on human rights, democracy, and rule of law, though no binding AI-specific risk-assessment statute equivalent to the EU AI Act was identified.

Biometric RegimeRed

No biometric-data-specific regime (facial recognition, fingerprint, gait) was confirmed in this research pass.

Genetic DataRed

No genetic-data-specific regime was confirmed in this research pass.

State Surveillance CarveoutsAmber

Article 32 of the Constitution provides a national-security/economic-welfare/human-rights exception to the general prohibition on processing confidential data without consent.

Claims (1):

  • Article 32 of the Constitution of Ukraine prohibits the processing of a person's confidential data without prior consent, subject to exceptions determined by law and applied only in the interests of national security, economic welfare, and human rights.
Category narrative79 words

Ukraine's Ministry of Digital Transformation has issued non-binding AI guidance and is aligning policy with the Council of Europe Framework Convention on AI, but no binding AI-risk-assessment statute equivalent to the EU AI Act was confirmed. A constitutional carve-out (Article 32) frames national-security exemptions from confidential-data-processing restrictions. Profiling restrictions, ADM transparency, biometric-specific regime, and genetic-data regime were not confirmed in this pass (searched: 'Ukraine profiling automated decision-making law', 'Ukraine biometric data law facial recognition', 'Ukraine genetic data protection law').

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. ProbableDataGuidance — Ukraine's Ministry of Digital Transformation has issued non-binding guidance on AI assistants/agents and is aligning national AI-related policy with the Council of Europe's Framework Convention on Artificial Intelligence, focusing on human rights, democracy, and rule of law, though no binding AI-specific risk-assessment statute equivalent to the EU AI Act was identified.observed
  2. ProbableIAPP — Article 32 of the Constitution of Ukraine prohibits the processing of a person's confidential data without prior consent, subject to exceptions determined by law and applied only in the interests of national security, economic welfare, and human rights.observed

#

General parental-consent and age-of-capacity norms are confirmed, but dedicated children's-privacy and dependent-adult provisions are unconfirmed.

Primary frameworkLaw of Ukraine No. 2297-VI 'On Personal Data Protection'; general Ukrainian civil-capacity rules
Traffic-light rationale — AmberGeneral parental-consent and age-of-capacity norms are confirmed, but dedicated children's-privacy and dependent-adult provisions are unconfirmed.

Sub-modules (5)

Age VerificationAmber

No statutory age-verification requirement exists; platforms' own terms of service (commonly 13+) fill the gap in practice.

Claims (1):

  • Ukraine has no statutory age-verification or minimum-age rule for social media registration; in practice, users rely on platform terms of service, which commonly set a 13-year minimum age, rather than a Ukrainian legal age-verification requirement.

Minor Profiling BansRed

No minor-specific profiling ban was confirmed in this research pass.

Education SettingsRed

No education-settings-specific data protection rule was confirmed in this research pass.

Dependent AdultsRed

No dependent-adults (elderly/incapacitated)-specific provision was confirmed in this research pass; general civil-capacity contract rules for minors were the closest analogue identified.

Claims (1):

  • Ukrainian civil law permits children who have reached 14 years of age to enter into minor contracts themselves, while other contracts generally require parental or guardian consent — a capacity rule relevant to consent-based data processing tied to contractual relationships involving minors.
Category narrative62 words

Ukraine has no dedicated children's-online-privacy statute; the 2010 Law applies to minors on a general basis. Civil-capacity rules (under-18 = child; 14+ can enter minor contracts) determine when parental/guardian consent is required. No confirmed minor-profiling ban, education-settings-specific rule, or dependent-adults (elderly/incapacitated) provision was located (searched: 'Ukraine minors profiling ban data law', 'Ukraine education data protection students', 'Ukraine dependent adults data protection incapacitated').

Sources and claims (3)
  1. ProbableDataGuidance — Ukraine has no dedicated children's online-privacy statute; under general civil-capacity rules anyone under 18 is considered a child, and where consent is the lawful basis for processing, consent must be obtained from a parent or legal guardian rather than the child directly.observed
  2. ProbableDataGuidance — Ukraine has no statutory age-verification or minimum-age rule for social media registration; in practice, users rely on platform terms of service, which commonly set a 13-year minimum age, rather than a Ukrainian legal age-verification requirement.observed
  3. ProbableDataGuidance — Ukrainian civil law permits children who have reached 14 years of age to enter into minor contracts themselves, while other contracts generally require parental or guardian consent — a capacity rule relevant to consent-based data processing tied to contractual relationships involving minors.observed

#

Enforcement powers and at least one documented enforcement action are confirmed, but regulator capacity is limited and private/collective redress mechanics remain largely unconfirmed.

Primary frameworkLaw of Ukraine No. 2297-VI 'On Personal Data Protection'; Code of Administrative Offences, Art. 188
Traffic-light rationale — AmberEnforcement powers and at least one documented enforcement action are confirmed, but regulator capacity is limited and private/collective redress mechanics remain largely unconfirmed.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The Ombudsman can audit controllers and issue administrative protocols imposing liability enforceable in court.

Claims (1):

  • The Ombudsman has the power to conduct compliance audits/inspections and to issue administrative protocols imposing administrative liability, enforceable through the courts, for violations of the Personal Data Protection Law, with administrative-offence provisions set out in Article 188 of the Code of Administrative Offences.

Enforcement Activity IndexAmber

A documented 2020 compliance-inspection order against Sinevo Ukraine LLC evidences active use of audit/remediation powers.

Claims (1):

  • Documented enforcement activity includes a 2020 Ombudsman compliance-inspection order against Sinevo Ukraine LLC directing remediation of personal-data-protection violations, illustrating the Commissioner's use of its audit and remediation-order powers.

Regulator Funding And CapacityRed

The Ombudsman's data protection department has historically been reported as small and under-funded relative to comparable European DPAs.

Claims (1):

  • The Ombudsman's Department for Personal Data Protection was reported to comprise only around 13 staff and an annual budget of no more than €150,000 for a country of over 40 million people, contrasted by commentators with far larger dedicated DPA staffing levels elsewhere in Europe.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism specific to data protection claims was confirmed in this research pass.

Private Right Of ActionAmber

The 2021 draft law contemplated a three-year limitation period for data-privacy claims, suggesting court access was contemplated in the reform, but current-law private-enforcement mechanics were not confirmed.

Claims (1):

  • The 2021 draft data protection bill (No. 5628) provided for a three-year limitation period for data-privacy-violation claims, suggesting the reform contemplated direct court access for data-protection claims, though the current 2010 Law's private-enforcement mechanics were not confirmed in available secondary sources.

Recent Developments 180DAmber

Within the 180 days preceding this research, non-binding AI-assistant guidance and cybersecurity-maturity methodology were published, and EU accession screening continued, but no enactment of the GDPR-aligned reform bill was identified.

Claims (2):

  • In the 180 days preceding this research, Ukraine's Ministry of Digital Transformation published guidance on the safe use of AI assistants/agents (16 April 2026) and the State Service for Special Communications and Information Protection (SSSCIP) approved new methodological recommendations to standardise cybersecurity maturity assessments (21 April 2026).
  • Ukraine's EU accession process, with intergovernmental accession negotiations opened in June 2024 and bilateral screening completed in September 2025, continues to create an external policy driver for eventual alignment of Ukraine's data protection framework with the EU acquis, though the reviewed accession report did not itself confirm enactment of GDPR-equivalent data protection legislation.
Category narrative89 words

The Ombudsman may conduct compliance audits and issue administrative protocols enforceable in court under Article 188 of the Code of Administrative Offences; a documented 2020 enforcement action (Sinevo Ukraine) illustrates this power in practice, though the Department's staffing/budget have historically been reported as very limited. Private-right-of-action and collective-redress mechanics under the current law were not confirmed; the 2021 draft law contemplated a three-year limitation period for claims. Recent (180-day) developments include non-binding AI-assistant guidance and cybersecurity-maturity methodology, alongside continued EU-accession momentum, but no enactment of the pending GDPR-aligned reform.

Periodic update · new data 2026-09-28

Enforcement & Redress

Enforcement capacity under Ukraine's current data-protection regime is constrained both by the statute's age and by the operating environment. No mandatory breach-notification obligation exists under the current framework, and the redress mechanisms available to data subjects under the 2011-vintage Law No. 2297-VI are narrower than the GDPR-equivalent regimes many counterparts now operate under, reflecting the statute's origin in the earlier EU Directive 95/46 rather than the GDPR itself.

The consequential development this cycle is again Draft Law No. 8153, which would introduce a substantially more severe penalty regime than currently exists: fines of up to UAH 150 million or 8 percent of annual turnover, a GDPR-style proportionate-turnover penalty structure that has no equivalent under the current statute. As at mid-2026, this penalty regime remained prospective, the draft having passed its first reading in November 2024 but still awaiting a second reading in the Verkhovna Rada, and it was not yet enacted or in force. Wartime conditions are understood to constrain the Ombudsman's practical enforcement capacity under the regime as it currently stands, a contextual factor bearing on how vigorously the existing, more modest, enforcement toolkit can be applied even before any new penalty regime becomes available.

The combination of a currently modest penalty structure, an enforcement body that is also the general human-rights ombudsman rather than a dedicated data-protection regulator, and wartime capacity constraints together describe an enforcement environment where the deterrent effect of the current law is limited, and where Draft Law No. 8153's proposed penalties would represent a significant escalation if and when enacted.

Outlook

The enforcement picture will not materially change until Draft Law No. 8153 either advances through second reading or stalls; no interim enforcement-capacity development, such as new Ombudsman guidance or a notable case, was identified this cycle. The UAH 150 million / 8 percent turnover-based penalty structure remains the single clearest forward marker of how enforcement exposure could shift, contingent on the same 2027 Q2 horizon estimate that governs the broader reform.

Sources and claims (6)
  1. ProbableDataGuidance — The Ombudsman has the power to conduct compliance audits/inspections and to issue administrative protocols imposing administrative liability, enforceable through the courts, for violations of the Personal Data Protection Law, with administrative-offence provisions set out in Article 188 of the Code of Administrative Offences.observed
  2. ProbableDataGuidance — Documented enforcement activity includes a 2020 Ombudsman compliance-inspection order against Sinevo Ukraine LLC directing remediation of personal-data-protection violations, illustrating the Commissioner's use of its audit and remediation-order powers.observed
  3. ProbableIAPP — The Ombudsman's Department for Personal Data Protection was reported to comprise only around 13 staff and an annual budget of no more than €150,000 for a country of over 40 million people, contrasted by commentators with far larger dedicated DPA staffing levels elsewhere in Europe.observed
  4. UncertainDataGuidance — The 2021 draft data protection bill (No. 5628) provided for a three-year limitation period for data-privacy-violation claims, suggesting the reform contemplated direct court access for data-protection claims, though the current 2010 Law's private-enforcement mechanics were not confirmed in available secondary sources.observed
  5. ProbableDataGuidance — In the 180 days preceding this research, Ukraine's Ministry of Digital Transformation published guidance on the safe use of AI assistants/agents (16 April 2026) and the State Service for Special Communications and Information Protection (SSSCIP) approved new methodological recommendations to standardise cybersecurity maturity assessments (21 April 2026).observed
  6. ProbableEuropean Commission / EUR-Lex — Ukraine's EU accession process, with intergovernmental accession negotiations opened in June 2024 and bilateral screening completed in September 2025, continues to create an external policy driver for eventual alignment of Ukraine's data protection framework with the EU acquis, though the reviewed accession report did not itself confirm enactment of GDPR-equivalent data protection legislation.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct27.27
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Ukraine
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 37 claim(s) (37 category placement(s)), 23 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacysccs and bcrs
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework and cross_border_and_adequacy sub-modules on EU adequacy/accession draw on a T1 European Commission enlargement report and the T1 Ombudsman homepage; all other modules rely primarily on T3 secondary legal-commentary aggregators (DataGuidance, IAPP), several of which are 2019-2022 vintage given the current law's stability and the pending draft's stalled status. Modules with confirmed T1/T2-adjacent grounding: regulator_and_framework (regulator identity/URL), cross_border_and_adequacy (EU adequacy absence). Modules relying essentially entirely on T3/T4 secondary commentary with confirmed gaps flagged red: sectoral_watch (5 of 7 sub-modules absent), adtech_and_commercial_privacy (5 of 6 sub-modules absent), algorithmic_biometric_and_surveillance_governance (4 of 6 sub-modules absent), and specific sub-modules within lawful_processing_and_special_data (pseudonymisation), data_subject_rights (restriction_and_objection), and controller_processor_duties (joint_controller_arrangements, retention_and_disposal).

Unresolved questions (5):

  • Has the 2022 draft Personal Data Protection Law, the parallel 2021 National Commission bill, or any successor been enacted since 2022? Most recently confirmed status is 'under consideration' by the Verkhovna Rada.
  • What is the substantive content of the 2021 'data localisation amendments to the Personal Data Protection Law' referenced by DataGuidance (the source page was inaccessible/paywalled in this pass)?
  • What are current (2025-2026) staffing and budget figures for the Ombudsman's Department for Personal Data Protection, given the most recent confirmed figures date to 2019?
  • Has any EU adequacy assessment process for Ukraine been formally initiated as part of the EU accession/Cluster negotiations?
  • Does Ukraine have any sector-specific data protection overlays for financial services, telecoms/eprivacy, credit scoring, education, or insurance beyond the general 2010 Law?

Escalate to primary-source review: yes