Skip to the content
Global Data RulesData governance rules, country by country

Ukraine

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Ukraine — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: MediumEnforcement: Active

Ukraine still runs its 2010 privacy law, not a European-style one. Personal data may only go to a country the law treats as safe. That means Europe, plus the 50-odd countries that signed a Council of Europe data treaty. The United States is not on that list. Fines are tiny. But the human rights Commissioner really does inspect, and misusing data can be a crime.

Data governance in Ukraine

The eight things that decide how you handle data about people in Ukraine. Same eight on every country page, so you can compare.

Who has to follow these rules

Probably not, if you have nothing in Ukraine. The 2010 law simply says it covers personal data handled by computer or in structured paper files. It has no clause reaching foreign companies that only sell into Ukraine from abroad. It does not make you appoint a local representative. There is no size or revenue cut-off either. A corner shop and a bank are treated the same.

Not fully verified — see “What we're not sure about” below.

Where the data is allowed to live

Yes, but only to countries Ukraine already treats as safe. Those are the European Economic Area countries, plus every country that has signed the Council of Europe's data protection treaty. That is roughly 55 states. The United States has signed neither. So routine transfers to American servers do not fit the safe-country route. They need one of the narrow exceptions instead. Whole industries then change the answer. Government, defence and critical infrastructure are far tighter. Securities firms are unusually looser.

Ways to send data out:
Official 'this country is safe' decision · Explicit consent · Needed for a contract · To save someone’s life · Important public interest

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

There is no form to file and no government permission to get. Either you send the data to a country the law already treats as safe, or you rely on one of five narrow exceptions. One: the person's clear consent. Two: it is needed for a contract made for that person's benefit. Three: protecting someone's life. Four: an important public interest or a legal claim. Five: you give guarantees that private and family life will not be interfered with. That last one is broad, and a lot of Ukrainian practice leans on it.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Explicit consent · Needed for a contract · To save someone’s life · Legal claims

The regulator, and whether it actually acts

The Ukrainian Parliament Commissioner for Human Rights is the data protection regulator. This is the national ombudsman, and it is working. It publishes a fresh inspection programme every three months. The one for July to September 2026 went up on 2 July 2026. It also publishes what it found, including a run of checks on the national electronic health system. The catch is the money. The regulator cannot fine anyone itself. It writes up a case and sends it to a court, and the maximum penalty is about $800.

How long you must keep it — and when to delete it

Minimum keep times come from tax law. Companies must keep primary accounting documents and financial statements for 1,825 days, which is five years. Papers needed for transfer pricing checks run to 2,555 days, which is seven years. Everything else the tax authority may ask for runs 1,095 days, which is three years. The maximum comes from the privacy law. You must delete personal data when the agreed storage period runs out. You must also delete it when your relationship with the person ends, unless another law tells you to keep it.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

This is the biggest surprise in Ukrainian law. If you lose personal data, you have no duty to tell the regulator. You have no duty to tell the people affected either. The 2010 privacy law simply has no breach reporting clause. The only compulsory deadlines sit in the cyber security rules. They only apply if you run a state system or a piece of critical information infrastructure. Even there, the law does not set the hours. It leaves the deadline to an order of the cyber agency.

What you have to do here:
Report cyber incidents · Secure the data
Not fully verified — see “What we're not sure about” below.

What catches people out

Five things. (1) If a Ukrainian government body decides how personal data is used, only a Ukrainian state-owned or municipal company may handle that data for it. A private or foreign supplier is not allowed at all. (2) Misusing personal data is a crime, not just a fine. Repeat offences carry up to five years in prison. (3) The fines are aimed at named individuals and sole traders, not at companies. (4) Posting anything that shows where Ukrainian troops are carries five to eight years in prison. (5) Martial law lets the government limit the constitutional right to privacy that the whole system rests on.

What you have to do here:
Written vendor contract
What it costs if you get it wrong:
Criminal liability · Fixed maximum fine

What's changing next

The date to watch is not a new law. It is the end of the war. Martial law was extended again on 13 July 2026. It now runs from 2 August 2026 for 90 days, so to about 31 October 2026. Several of today's permissions exist only while it lasts. They end six months after it ends. A European-style replacement privacy law has been discussed for years and still has not passed. Do not plan around its arrival.

What to do: Diarise 31 October 2026 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries7 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data must stay in the country

Official name: Закон України "Про захист персональних даних", частина третя статті 4 · Law No. 2297-VI, Article 4(3), in the wording of Law No. 1907-IX of 18 November 2021 · Act of parliament

In forceNo — it stays put

Where a Ukrainian state authority or local council decides how personal data is used, only one kind of supplier may handle that data. That is an enterprise in state or municipal ownership. Private and foreign suppliers are shut out, whatever the contract says.

In force since 1 January 2022

Enforced by Ukrainian Parliament Commissioner for Human Rights

How this country controls where data goes: Not allowed

Government

Government data rules

Official name: Закон України "Про захист інформації в інформаційно-комунікаційних системах" · Law No. 80/94-VR of 5 July 1994, Article 8 rewritten by Law No. 4336-IX of 27 March 2025 · Act of parliament

Partly in forceA copy must stay

This is the rule that really governs Ukrainian government data. State information resources must run in systems that have passed a security authorisation. Backups may be moved abroad only while martial law lasts. Hosting in Russia, Belarus, occupied territory or sanctioned infrastructure is banned outright. And any part of the system sitting abroad forces a Ukrainian legal presence.

In force since 3 April 2025

Enforced by State Service of Special Communications and Information Protection of Ukraine

How this country controls where data goes: Any country except banned ones · Accepted routes: Security review needed, Certification scheme

Government

Government data must stay in the country (Government)

Official name: Постанова КМУ № 263 "Деякі питання забезпечення функціонування інформаційно-комунікаційних систем, електронних комунікаційних систем, публічних електронних реєстрів в умовах воєнного стану" · Cabinet of Ministers Resolution No. 263 of 12 March 2022, last amended by Resolution No. 635 of 20 May 2026 · Directly binding regulation

In forceYes, with paperwork

The wartime permission that moved Ukraine's state registers out of the country. It works only while martial law lasts, and the underlying laws restore the tighter default six months after martial law ends.

In force since 12 March 2022

Enforced by Cabinet of Ministers of Ukraine

How this country controls where data goes: Any country except banned ones · Accepted routes: Government sign-off needed

Applies to every company1 rule

These bind you whatever business you are in, once the country's rules reach you.

Breach reporting rules

Official name: Закон України "Про захист персональних даних" · Law No. 2297-VI of 1 June 2010, current revision 14 June 2025 · Act of parliament

In forceYes, with paperwork

This is Ukraine's general privacy law. Its structure has not changed since 2010, and no European-style statute has replaced it. Data may only go to European Economic Area states, or to countries that signed the Council of Europe data treaty. Otherwise you need one of five narrow exceptions. There is no breach reporting duty, no risk assessment duty and no general registration. The fines are among the smallest in Europe.

In force since 1 January 2011

Enforced by Ukrainian Parliament Commissioner for Human Rights

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Explicit consent, Needed for a contract, To save someone’s life, Important public interest, Legal claims

Who you would hear from

  • Уповноважений Верховної Ради України з прав людини

    General personal data protection supervision for all sectors

    Fully operational, and visibly so. Quarterly inspection programmes have been published without a break through the war. The programme for July to September 2026 was posted on 2 July 2026. Inspection findings are published, including a series on the national electronic health system. It cannot fine anyone directly. It issues binding orders and refers administrative offence reports to the courts, where the ceiling is about $800.

  • Державна служба спеціального зв’язку та захисту інформації України

    Protection of state information resources, critical information infrastructure, cyber incident response through CERT-UA

    Operational. Runs CERT-UA and sets the mandatory cyber incident reporting deadlines by its own order rather than through legislation.

  • Кабінет Міністрів України

    Holds the power to publish the list of states deemed to protect personal data adequately, and makes the wartime rules on hosting state registers abroad

    Operational as a government. But it has not used its power under Article 29(3) of the data protection law to publish the list of safe states.

  • Національний банк України

    Banks, payment institutions, payment infrastructure; sets the rules on banks' use of cloud computing

    Operational. Its 2017 information security rules for banks expressly leave out cloud services. Those are left to a separate document that we could not find on its own site.

  • Національна комісія, що здійснює державне регулювання у сферах електронних комунікацій, радіочастотного спектра та надання послуг поштового зв’язку

    Electronic communications; keeps the register of cloud and data centre providers that public bodies must buy from

    Site reachable on 18 August 2026. We could not open the cloud provider register itself, so whether it is populated is recorded as unconfirmed.

  • Національна комісія з цінних паперів та фондового ринку

    Securities and capital markets; the sector that benefits from the IOSCO adequacy route

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That the Cabinet of Ministers has never adopted the list of states ensuring adequate data protection required by Article 29(3)

    We could not confirm that no list of safe states has been adopted. We found no such list. On the official legislation site, every live cross-reference in the Act is linked to the document it names. This one is not.

  • The exact deadline, in hours, for mandatory cyber incident reports to CERT-UA

    We could not confirm the incident reporting deadline. The statute leaves it to an order of the State Service of Special Communications and Information Protection. We could not open that order. Treat the deadline as short and set by the agency. Confirm it with the agency before you rely on any number.

  • The status of the long-promised replacement privacy law aligned with European rules

    We could not confirm the status of the replacement bill. Our web search quota ran out before we could open the parliamentary bill card. We can show the part that matters commercially. The 2010 Act is still shown as in force, with its current revision dated 14 June 2025. So no replacement has started.

  • Whether the National Bank has issued a separate instrument governing banks' use of cloud services, and whether it restricts offshore hosting

    We could not find the cloud rules for banks. The 2017 information security rules for banks say cloud requirements are set in a separate document. The Cloud Services Act gave the National Bank the power to make one. We could not find that document on the bank's own site, whose search returned errors. If you are a bank, ask the National Bank.

  • Whether the register of cloud and data centre providers that public bodies must buy from actually has entries

    We could not confirm whether the cloud provider register has anyone on it. The electronic communications regulator's register page was unreachable from our network. An empty register would make the government purchasing route in the Cloud Services Act unusable.

  • That there is no rule forcing data to stay in the country requirement in Ukrainian banking, payments, insurance, telecoms, education, gaming or e-commerce law

    We found no transfer rule for these industries. We read the Payment Services Act and the Electronic Communications Act in full on 18 August 2026. We did not read the insurance, education or gaming statutes. We did not check every regulator's own rules. Treat this as a rule we could not find, not proof that none exists.

  • Whether the Commissioner's inspections have produced fines against private companies, as opposed to orders against public bodies

    We could not confirm how often money penalties are actually imposed. The published inspection results are dominated by councils, administrative service centres and state enterprises. Court outcomes on the administrative offence reports are not published on the Commissioner's site.

  • The exact commencement dates recorded for the amending laws — No. 1907-IX, No. 2075-IX, No. 2494-IX, No. 3585-IX and No. 4336-IX

    We could not confirm the exact start dates. Each of these laws starts by formula, not by a stated date. It is either the day after publication, or six months after publication. We verified the formula in each Act's final sections. We could not open the gazette issue that fixes the publication day. So the dates here are calculated to within a few days. The adoption dates and the substance are verified.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.