Ukraine
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Ukraine still runs its 2010 privacy law, not a European-style one. Personal data may leave the country only to a country the law treats as safe — that means Europe and the 50-odd countries that signed a Council of Europe data treaty. The United States is not on that list. Fines are tiny, but the human rights Commissioner really does inspect, and misusing data can be a crime.
Eight questions about Ukraine
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Ukraine's rules apply to my company?
Probably not, if you have nothing in Ukraine. The 2010 law simply says it covers the processing of personal data by automated means or in structured paper files. It contains no clause reaching foreign companies that only sell into Ukraine from abroad, and it does not make you appoint a local representative. There is no size or revenue threshold either — a corner shop and a bank are treated the same.
Article 1 of Law No. 2297-VI defines the subject matter with no territorial or extraterritorial trigger, and Article 4 lists the parties to a data relationship without any residency condition. The absence of a territorial clause cuts both ways: there is no explicit foreign reach, but there is also no explicit exclusion, and the Commissioner has in practice inspected Ukrainian-established entities of all ownership types. A local-presence requirement does appear elsewhere: under Article 8 of Law No. 80/94-VR, as rewritten by Law No. 4336-IX of 27 March 2025, where any element of a system or critical information infrastructure object sits outside Ukraine, the owner or operator must be a legal entity registered in Ukraine or must have an official representative in Ukraine.
Sources
- Official sourceVerkhovna Rada of UkraineLaw of Ukraine on Personal Data Protection No. 2297-VI, Articles 1 and 4 (consolidated text, revision of 14 June 2025)
zakon.rada.gov.ua
“Цей Закон поширюється на діяльність з обробки персональних даних, яка здійснюється повністю або частково із застосуванням автоматизованих засобів, а також на обробку персональних даних, що містяться у картотеці чи призначені до внесення до картотеки, із застосуванням неавтоматизованих засобів.”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineLaw on Protection of Information in Information and Communication Systems No. 80/94-VR, Article 8 (as rewritten by Law No. 4336-IX of 27 March 2025)
zakon.rada.gov.ua
“власник або розпорядник системи, об’єкта критичної інформаційної інфраструктури або його представник, який надає послуги з використанням системи, об’єкта критичної інформаційної інфраструктури, елементи якої розміщуються поза межами України, є юридичною особою, зареєстрованою в Україні, або має свого офіційного представника в Україні”
Link checked 18 August 2026
Can I store my users' data outside Ukraine?
Yes, but only to countries Ukraine already treats as safe. Those are the European Economic Area countries plus every country that has signed the Council of Europe's data protection treaty — roughly 55 states. The United States has signed neither, so routine transfers to American servers do not fit the safe-country route and need one of the narrow exceptions instead. Whole sectors then override this: government, defence and critical infrastructure are far tighter, and securities firms are unusually looser.
Article 29(3) of Law No. 2297-VI permits transfer to foreign parties only where the destination state ensures adequate protection, in cases established by law or by an international treaty. Two categories are deemed adequate by the statute itself: European Economic Area member states, and states that have signed the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108). A third category was inserted by Law No. 3585-IX of 22 February 2024: states whose capital markets regulators are signatories to the IOSCO Multilateral Memorandum of Understanding. That third limb is a rare example of a sector rule that widens rather than narrows the transfer route, and it pulls the United States back in for securities purposes. Article 29(3) also directs the Cabinet of Ministers to determine a list of states ensuring adequate protection; we found no adopted list and the statutory cross-reference on the official gazette site is not hyperlinked to any instrument, unlike every other live cross-reference in the same law. SECTOR OVERRIDES: (a) government — where a state or local authority is the controller, only a state-owned or municipal enterprise may act as processor (Article 4(3)), which excludes private and foreign suppliers entirely; (b) government and defence — official information and state secrets may not be processed using cloud resources or data centres located abroad, except that during martial law the Ministry of Defence and the Armed Forces may do exactly that; (c) government — state information resources and public electronic registers may currently be hosted abroad, but only because martial law is in force; (d) all sectors — hosting on temporarily occupied territory, in a state recognised by Parliament as an aggressor or occupier, in a state in a customs or military union with such a state, or with a sanctioned person, is prohibited outright; (e) health — a martial law exception lets telemedicine data follow the law of the treating clinician's country, except for citizens of Russia and Belarus; (f) securities — the IOSCO widening above. No transfer restriction specific to banking, payments, insurance, telecoms, education, gaming, e-commerce or mapping was found in the primary statutes we read on 18 August 2026.
Sources
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Article 29(3) and (4) — international cooperation and transfer of personal data
zakon.rada.gov.ua
“Держави - учасниці Європейського економічного простору, а також держави, які підписали Конвенцію Ради Європи про захист осіб у зв’язку з автоматизованою обробкою персональних даних, визнаються такими, що забезпечують належний рівень захисту персональних даних.”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineLaw of Ukraine on Cloud Services No. 2075-IX, Article 11(3) — ban on foreign cloud for official information and state secrets, with a martial-law carve-out for the Ministry of Defence
zakon.rada.gov.ua
“Забороняється обробка службової інформації та інформації, що становить державну таємницю, за допомогою хмарних ресурсів та/або центрів обробки даних, що розміщені за кордоном (крім випадків, передбачених абзацом другим цієї частини) чи на тимчасово окупованих територіях України”
Link checked 18 August 2026
- Official sourceCabinet of Ministers of UkraineCabinet of Ministers Resolution No. 263 of 12 March 2022 on information systems and public electronic registers under martial law (as amended to 20 May 2026)
zakon.rada.gov.ua
“розміщувати державні інформаційні ресурси та публічні електронні реєстри на хмарних ресурсах та/або в центрах обробки даних, що розташовані за межами України”
Link checked 18 August 2026
What do I need in place before data leaves Ukraine?
There is no form to file and no government permission to obtain. You either send the data to a country the law already treats as safe, or you rely on one of five narrow exceptions. Those are: the person's clear consent, necessity for a contract made for that person's benefit, protecting someone's life, an important public interest or a legal claim, and the sender giving guarantees that private and family life will not be interfered with. That last one is a catch-all that a lot of Ukrainian practice leans on.
The model is an allowlist by category rather than by named country, and the categories are populated by operation of law, not by a published government list. Article 29(4) of Law No. 2297-VI sets out the five alternatives. There is no standard contract published by the Ukrainian government, no binding corporate rules scheme, no certification scheme and no case-by-case approval process. The Cabinet of Ministers has the power under Article 29(3) to publish a list of adequate states; we found no such list, so the deemed-adequate categories in the statute are doing all the work today. The practical consequence is that a transfer to a United States cloud provider under the general law usually rests on consent or on the Article 29(4)(5) guarantees limb, not on adequacy.
Sources
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Article 29(4) — the five alternatives to adequacy
zakon.rada.gov.ua
“Персональні дані можуть передаватися іноземним суб’єктам відносин, пов’язаних з персональними даними, також у разі: 1) надання суб’єктом персональних даних однозначної згоди на таку передачу; ... 5) надання володільцем персональних даних відповідних гарантій щодо невтручання в особисте і сімейне життя суб’єкта персональних даних.”
Link checked 18 August 2026
- Official sourceSecretariat of the Ukrainian Parliament Commissioner for Human RightsCommissioner for Human Rights — recommendations and clarifications on personal data protection
ombudsman.gov.ua
Link checked 18 August 2026
Who enforces the rules in Ukraine, and what can they do?
The Ukrainian Parliament Commissioner for Human Rights — the national ombudsman — is the data protection regulator, and it is genuinely working. It publishes a fresh inspection programme every three months; the one for July to September 2026 went up on 2 July 2026. It also publishes what it found, including a run of checks on the national electronic health system. The catch is the money: the regulator cannot fine anyone itself, it writes up a case and sends it to a court, and the maximum penalty is about $800.
Article 22 of Law No. 2297-VI gives supervision to the Commissioner and the courts. Article 23 gives the Commissioner the power to run planned and unplanned, on-site and desk inspections, to demand any document including restricted-access information, to issue binding orders to stop or change processing, and to draw up administrative offence reports for a court. The procedure is set by Commissioner's Order No. 1/02-14 of 8 January 2014. Published inspection targets are heavily weighted towards public bodies — city councils, administrative service centres, the National Health Service, the state enterprise eZdorovya — with a smaller number of private companies. Separately, the State Service of Special Communications and Information Protection runs cyber incident response through CERT-UA and supervises the protection of state information resources, and the National Bank supervises banks and payment providers. There is no separate specialised data protection authority, and the draft law that would create one has not been enacted.
Sources
- Official sourceSecretariat of the Ukrainian Parliament Commissioner for Human RightsInspection programmes in the field of personal data protection, including the third quarter of 2026 (published 2 July 2026)
ombudsman.gov.ua
Link checked 18 August 2026
- Official sourceSecretariat of the Ukrainian Parliament Commissioner for Human RightsCommissioner for Human Rights — supervision of compliance with data protection law, procedure under Order No. 1/02-14 of 8 January 2014
ombudsman.gov.ua
“на суб’єкта перевірки у встановленому законом порядку може накладатися штраф від ста до двох тисяч неоподатковуваних мінімумів доходів громадян”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Articles 22 and 23 — supervision and the Commissioner's powers
zakon.rada.gov.ua
Link checked 18 August 2026
How long do I have to keep the data?
The floor comes from tax law. Companies must keep primary accounting documents and financial statements for 1,825 days — five years. Papers needed for transfer pricing checks run to 2,555 days, which is seven years. Everything else the tax authority may ask for runs 1,095 days, three years. The ceiling comes from the privacy law: you must delete personal data when the agreed storage period runs out, or when your relationship with the person ends, unless another law tells you to keep it.
Article 44.3 of the Tax Code sets the minimum periods, counted from the day the relevant return was filed. Article 6(8) of Law No. 2297-VI is the general storage-limitation principle: data may be held in identifiable form no longer than is necessary for the purposes for which it was collected. Article 15(2) makes that concrete by listing four deletion triggers, of which the second is the one people miss — the end of the legal relationship between the person and the controller. Where the two directions conflict, the tax and accounting floor wins because Article 15(2)(2) is expressly subject to any contrary provision of law, and Article 27(1) allows other laws to supplement the privacy law provided they do not contradict it. There is no general log retention duty in Ukrainian law, and no telecoms traffic data retention regime: we read Law No. 1089-IX on Electronic Communications in full on 18 August 2026 and found only a duty to keep billing records for the limitation period.
Sources
- Official sourceVerkhovna Rada of UkraineTax Code of Ukraine No. 2755-VI, paragraph 44.3 — minimum document retention of 2,555, 1,825 and 1,095 days
zakon.rada.gov.ua
“44.3.2. 1825 днів - для первинних документів, регістрів бухгалтерського обліку, фінансової звітності, інших документів, пов’язаних з обчисленням і сплатою податків і зборів”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Articles 6(8) and 15 — storage limitation and deletion triggers
zakon.rada.gov.ua
“Персональні дані підлягають видаленню або знищенню у разі: 1) закінчення строку зберігання даних, визначеного згодою суб'єкта персональних даних на обробку цих даних або законом; 2) припинення правовідносин між суб'єктом персональних даних та володільцем чи розпорядником, якщо інше не передбачено законом”
Link checked 18 August 2026
What happens if there is a breach?
This is the biggest surprise in Ukrainian law: if you lose personal data, there is no duty to tell the regulator and no duty to tell the people affected. The 2010 privacy law simply has no breach reporting clause. The only mandatory clocks sit in the cyber security regime, and they only bite if you run a state system or a piece of critical information infrastructure. Even there the law does not set the hours — it leaves the deadline to an order of the cyber agency.
Law No. 2297-VI contains no breach notification obligation of any kind; Article 24 imposes only a general security duty. The mandatory clocks come from Article 9-1 of Law No. 2163-VIII on the Basic Principles of Cyber Security, as rewritten by Law No. 4336-IX of 27 March 2025. Owners of systems processing state information resources, official information or state secrets must report ALL cyber incidents to the relevant response team; owners of critical information infrastructure objects must report SIGNIFICANT incidents only. Article 9-1(4) states that mandatory notifications are made 'within the time limits and in the manner established by the Authorised Body', which is the State Service of Special Communications and Information Protection — so the deadline lives in a regulator's order, not in the statute, and can be changed without going through Parliament. Officials who miss it face administrative liability. Separately, Article 9(3) of Law No. 80/94-VR requires the owner of a system holding state information resources to notify the same agency of attempted or actual unauthorised access. The practical result is two clocks for the public sector and its suppliers, and no clock at all for an ordinary private company that loses customer data.
Sources
- Official sourceVerkhovna Rada of UkraineLaw on the Basic Principles of Cyber Security No. 2163-VIII, Article 9-1 — mandatory cyber incident reporting
zakon.rada.gov.ua
“Усі обов’язкові повідомлення про кіберінциденти, кібератаки, кіберзагрози подаються суб’єктами, визначеними цією статтею, у строки та порядку, встановлені Уповноваженим органом.”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Article 24 — security duty, with no breach notification obligation anywhere in the Act
zakon.rada.gov.ua
Link checked 18 August 2026
What trips people up in Ukraine?
Five. (1) If a Ukrainian government body is the one deciding how personal data is used, only a Ukrainian state-owned or municipal company may handle that data for it — a private or foreign supplier is not allowed at all. (2) Misusing personal data is a crime, not just a fine, and repeat offences carry up to five years in prison. (3) The fines are aimed at named individuals and sole traders, not at companies. (4) Posting anything that shows where Ukrainian troops are carries five to eight years in prison. (5) Martial law lets the government limit the constitutional right to privacy that the whole system rests on.
(1) Article 4(3) of Law No. 2297-VI, in the wording introduced by Law No. 1907-IX of 18 November 2021: where the controller is a state authority or a local self-government body, the processor may only be an enterprise in state or municipal ownership. This is a hard procurement wall that no contract can cure. (2) Article 182 of the Criminal Code punishes unlawful collection, storage, use, destruction or dissemination of confidential information about a person with a fine of 500 to 1,000 tax-free minimums (about $205 to $410), correctional labour, probation supervision or restriction of liberty for up to three years; a repeat offence or substantial harm attracts up to five years' imprisonment. (3) Article 188-39 of the Code of Administrative Offences addresses citizens, officials and individual entrepreneurs — there is no administrative fine payable by a legal entity for a data protection breach, which is why the maximum exposure of about $800 is so misleadingly small. (4) Article 114-2 of the Criminal Code, added after the 2022 invasion, punishes dissemination of information about the movement or location of Ukrainian forces where they can be identified on the ground with five to eight years' imprisonment. Any product handling user-generated photographs, check-ins or fine-grained location data in Ukraine is exposed. (5) Presidential Decree No. 64/2022, paragraph 3, expressly allows temporary limitation of the constitutional privacy right under Article 32 of the Constitution for the duration of martial law, and the Commissioner's own guidance confirms it.
Sources
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Article 4(3) — only a state or municipal enterprise may process personal data for a public authority
zakon.rada.gov.ua
“Розпорядником персональних даних, володільцем яких є орган державної влади чи орган місцевого самоврядування, крім цих органів, може бути лише підприємство державної або комунальної форми власності.”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineCriminal Code of Ukraine No. 2341-III, Articles 182 and 114-2
zakon.rada.gov.ua
“Поширення інформації про переміщення, рух або розташування Збройних Сил України ... за можливості їх ідентифікації на місцевості ... карається позбавленням волі на строк від п’яти до восьми років.”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineCode of Ukraine on Administrative Offences, Article 188-39 — penalties addressed to citizens, officials and individual entrepreneurs
zakon.rada.gov.ua
Link checked 18 August 2026
- Official sourceSecretariat of the Ukrainian Parliament Commissioner for Human RightsCommissioner for Human Rights — guidance on personal data protection under martial law
ombudsman.gov.ua
“Згідно з пунктом 3 Указу у зв’язку із введенням в Україні воєнного стану тимчасово, на період дії правового режиму воєнного стану, можуть обмежуватися конституційні права і свободи людини і громадянина, передбачені, зокрема, статтею 32 Конституції України.”
Link checked 18 August 2026
What is changing soon in Ukraine?
The date to watch is not a new law — it is the end of the war. Martial law was extended again on 13 July 2026 and now runs from 2 August 2026 for 90 days, so to about 31 October 2026. Several of today's permissions exist only while it lasts, and they die six months after it ends. A European-style replacement privacy law has been discussed for years and has still not been passed, so nothing about the current regime should be planned around its arrival.
DATED ITEMS. Martial law was extended by Presidential Decree No. 596/2026 of 13 July 2026 from 05:30 on 2 August 2026 for 90 days, the twenty-second extension since February 2022. Three permissions are tied to it and lapse six months after it is lifted: state information resources and public electronic registers may be hosted on clouds and in data centres abroad; the Ministry of Defence and the Armed Forces may process defence information, official information and state secrets in foreign clouds; and telemedicine data may be transferred under the law of the treating clinician's country, except for Russian and Belarusian citizens. In each case the default position that returns is more restrictive, not less. DORMANT SWITCHES. First, the Cabinet of Ministers may at any time publish the list of states deemed to ensure adequate protection under Article 29(3), which could either confirm or narrow the current position without consultation. Second, the cyber agency sets the mandatory incident reporting deadline by its own order, so the clock can be shortened administratively. Third, the martial law decree already authorises limitation of the constitutional privacy right, meaning further restrictions do not need new primary legislation. Fourth, the ban on hosting in aggressor, occupied or sanctioned territories keys off sanctions lists that change frequently.
Sources
- Official sourcePresident of Ukraine / Verkhovna Rada of UkrainePresidential Decree No. 64/2022 introducing martial law, as extended by Decree No. 596/2026 of 13 July 2026
zakon.rada.gov.ua
“Строк дії воєнного стану в Україні продовжено з 05 години 30 хвилин 2 серпня 2026 року строком на 90 діб згідно з Указом Президента № 596/2026 від 13.07.2026”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, card page showing the Act as in force with the current revision dated 14 June 2025
zakon.rada.gov.ua
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
1 rule here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
7 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules1 rule
Закон України "Про захист персональних даних"
Act of parliament · Law No. 2297-VI of 1 June 2010, current revision 14 June 2025
Ukraine's general privacy law, unchanged in structure since 2010 and never replaced by a European-style statute. Data may leave only to European Economic Area states, Council of Europe data treaty signatories or under five narrow exceptions. There is no breach notification duty, no risk assessment duty and no general registration, and the fines are among the smallest in Europe.
Enforced by Ukrainian Parliament Commissioner for Human Rights
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Explicit consent, Needed for a contract, Someone's life is at risk, Important public interest, Legal claims
What it makes you do
- Get consent
- Allowed because the law requires it
- Tell people what you doThe person must be told within ten working days of collection who holds the data, what is held, why, and to whom it will be passed.
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Secure the data
- Register or notifyNot a general register. Only processing that poses a special risk must be notified to the Commissioner, within thirty working days of starting, and changes within ten working days.
- Appoint a data protection officer — applies at: Public bodies, and any controller whose processing must be notified as high riskA unit or a named responsible person; the appointment itself must be reported to the Commissioner and is published.
- Written vendor contractProcessor engagement must be by written contract and the processor may act only for the purpose and to the extent stated in it.
- Put a transfer safeguard in place
- Delete data after a periodDelete when the agreed or statutory storage period ends, or when the relationship with the person ends, unless another law requires retention.
What it costs if you get it wrong
- Fixed maximum fine: 2,000 tax-free minimum incomes (UAH 34,000) — about $820Repeat failure to protect data leading to unlawful access, or repeat failure to obey the Commissioner. Imposed by a court on an individual, an official or a sole trader — not on a company.
- Criminal liability: Up to five years' imprisonmentUnlawful collection, storage, use, destruction or dissemination of confidential information about a person, where repeated or causing substantial harm (Criminal Code Article 182)
- Order to stopThe Commissioner may order processing to be suspended or stopped, or data to be changed, deleted or destroyed.
Sources
- Official sourceVerkhovna Rada of UkraineLaw of Ukraine on Personal Data Protection No. 2297-VI, consolidated text
zakon.rada.gov.ua
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineCode of Ukraine on Administrative Offences, Article 188-39
zakon.rada.gov.ua
Link checked 18 August 2026
Industry rules7 rules
Закон України "Про захист персональних даних", частина третя статті 4
Act of parliament · Law No. 2297-VI, Article 4(3), in the wording of Law No. 1907-IX of 18 November 2021 · Government
Where a Ukrainian state authority or local council decides how personal data is used, the only party allowed to process that data on its behalf is an enterprise in state or municipal ownership. Private and foreign suppliers are excluded outright, whatever the contract says.
Enforced by Ukrainian Parliament Commissioner for Human Rights
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryNot phrased as a location rule, but it works like one: the only permitted processor is a Ukrainian state or municipal enterprise, so the data cannot be handed to a foreign or private cloud operator at all.
- Written vendor contract
Sources
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Article 4(3)
zakon.rada.gov.ua
“Розпорядником персональних даних, володільцем яких є орган державної влади чи орган місцевого самоврядування, крім цих органів, може бути лише підприємство державної або комунальної форми власності.”
Link checked 18 August 2026
Закон України "Про захист інформації в інформаційно-комунікаційних системах"
Act of parliament · Law No. 80/94-VR of 5 July 1994, Article 8 rewritten by Law No. 4336-IX of 27 March 2025 · Government
The rule that really governs Ukrainian government data. State information resources must run in systems that have passed a security authorisation, backups may be moved abroad only while martial law lasts, hosting in Russia, Belarus, occupied territory or sanctioned infrastructure is banned outright, and any offshore element forces a Ukrainian legal presence.
Enforced by State Service of Special Communications and Information Protection of Ukraine
Transfer model: Blocklist · Accepted routes: Security review needed, Certification scheme
What it makes you do
- Hold a security certificateState information resources and restricted-access information held by public bodies must run in a security-authorised system, or in one holding a certificate of conformity to an information security standard issued by a conformity assessment body.
- Appoint a local representativeIf any element of the system or critical information infrastructure object sits outside Ukraine, the operator must be a Ukrainian-registered legal entity or have an official representative in Ukraine.
- Keep the data in the countryHosting the system, its elements or backups on temporarily occupied territory, in a state Parliament has recognised as an aggressor or occupier, or in a state in a customs or military union with such a state, is prohibited.
- Report cyber incidentsAttempted or actual unauthorised access must be reported to the State Service of Special Communications and Information Protection.
- Appoint a data protection officerA cyber protection unit, or named persons responsible for information protection, must be set up.
Sources
- Official sourceVerkhovna Rada of UkraineLaw No. 80/94-VR on Protection of Information in Information and Communication Systems, Articles 8 to 10
zakon.rada.gov.ua
“Розміщення систем, об’єктів критичної інформаційної інфраструктури або їх елементів та зберігання резервних копій державних інформаційних ресурсів на тимчасово окупованій території України, території держави, визнаної Верховною Радою України державою-агресором, або на території держави, яка входить до митного або воєнного союзу з такими державами, забороняється.”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineLaw No. 4336-IX of 27 March 2025 amending the information protection and cyber security laws — commencement the day after publication
zakon.rada.gov.ua
“Цей Закон набирає чинності з дня, наступного за днем його опублікування, крім підпункту 5 пункту 4 розділу I цього Закону, який набирає чинності через шість місяців з дня його опублікування.”
Link checked 18 August 2026
Постанова КМУ № 263 "Деякі питання забезпечення функціонування інформаційно-комунікаційних систем, електронних комунікаційних систем, публічних електронних реєстрів в умовах воєнного стану"
Directly binding regulation · Cabinet of Ministers Resolution No. 263 of 12 March 2022, last amended by Resolution No. 635 of 20 May 2026 · Government
The wartime permission that moved Ukraine's state registers out of the country. It works only while martial law lasts, and the underlying laws restore the tighter default six months after martial law ends.
Enforced by Cabinet of Ministers of Ukraine
Transfer model: Blocklist · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryReverse localisation. For the duration of martial law only, ministries, executive bodies and state and municipal enterprises MAY place state information resources and public electronic registers on cloud resources or in data centres located outside Ukraine, and register gov.ua domain names for that hosting.
Sources
- Official sourceCabinet of Ministers of UkraineCabinet of Ministers Resolution No. 263 of 12 March 2022, paragraph 1(1)
zakon.rada.gov.ua
“розміщувати державні інформаційні ресурси та публічні електронні реєстри на хмарних ресурсах та/або в центрах обробки даних, що розташовані за межами України, та реєструвати доменні імена у домені gov.ua для такого розміщення”
Link checked 18 August 2026
- Official sourcePresident of Ukraine / Verkhovna Rada of UkrainePresidential Decree No. 64/2022 on martial law, current extension to about 31 October 2026
zakon.rada.gov.ua
Link checked 18 August 2026
Закон України "Про хмарні послуги"
Act of parliament · Law No. 2075-IX of 17 February 2022, Articles 8 to 12, as amended by Law No. 3783-IX of 5 June 2024 · Defence
Ukraine's cloud law. Government buyers may only use providers on an official register, contracts must run under Ukrainian law in Ukrainian courts, and official information and state secrets are barred from foreign clouds — except that since June 2024 the armed forces may use them while martial law lasts.
Transfer model: Not allowed · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryOfficial information and state secrets may not be processed using cloud resources or data centres located abroad. The one exception: during martial law the Ministry of Defence and the Armed Forces may use foreign clouds and data centres for military and defence information, including state secrets.
- Register or notifyPublic bodies must buy cloud and data centre services only from providers entered on the register kept by the electronic communications regulator.
- Make switching cloud provider possibleContracts must set out how data and backups move to another provider or back to the customer, and the government sets a switching procedure built on interoperability.
- Prove the data stays under local controlContracts with public users and critical information infrastructure operators must be governed by Ukrainian law and disputes must go to Ukrainian courts.
- Report breaches to the regulatorThe contract must require immediate notice to the customer of any cyber security incident with significant impact.
Sources
- Official sourceVerkhovna Rada of UkraineLaw of Ukraine on Cloud Services No. 2075-IX, Articles 9 to 12
zakon.rada.gov.ua
“У період дії воєнного стану Міністерство оборони України та Збройні Сили України можуть обробляти інформацію у воєнній і оборонній сферах, у тому числі службову інформацію та інформацію, що становить державну таємницю ... за допомогою хмарних ресурсів та/або центрів обробки даних, що розміщені за кордоном”
Link checked 18 August 2026
Закон України "Про захист персональних даних", абзац третій частини третьої статті 29
Act of parliament · Law No. 2297-VI, Article 29(3) third paragraph, inserted by Law No. 3585-IX of 22 February 2024 · Securities
A sector rule that makes transfers easier, not harder. Since March 2024 any country whose securities regulator has signed the International Organization of Securities Commissions information-sharing memorandum counts as offering adequate protection — which brings in the United States and much of Asia for capital markets purposes.
Enforced by National Securities and Stock Market Commission
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision
What it makes you do
- Put a transfer safeguard in placeNo extra paperwork. The destination simply qualifies as adequate if its capital markets regulator has signed the IOSCO multilateral memorandum.
Sources
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Article 29(3), third paragraph
zakon.rada.gov.ua
“Держави, регулятори ринків капіталу яких є підписантами Багатостороннього меморандуму про взаєморозуміння щодо консультування та співробітництва і обміну інформацією Міжнародної організації комісій з цінних паперів (International Organization of Securities Commissions - IOSCO), визнаються такими, що забезпечують належний рівень захисту персональних даних.”
Link checked 18 August 2026
Закон України "Про захист персональних даних", пункт 2 статті 30
Act of parliament · Law No. 2297-VI, Article 30(2), inserted by Law No. 2494-IX of 29 July 2022 · Health and social care
While martial law lasts and for six months afterwards, health and rehabilitation data needed for telemedicine may go abroad under the law of the treating clinician's own country rather than Ukraine's adequacy test. Russian and Belarusian citizens are carved out of the exception.
Enforced by Ukrainian Parliament Commissioner for Human Rights
Transfer model: Blocklist · Accepted routes: Someone's life is at risk, Official 'this country is safe' decision
What it makes you do
- Put a transfer safeguard in placeProtection follows the law of the country where the clinician or rehabilitation specialist is licensed, instead of the usual adequacy test. Citizens of Russia and Belarus are excluded from the exception.
Sources
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Article 30(2)
zakon.rada.gov.ua
“в період дії воєнного стану в Україні та протягом шести місяців після його припинення чи скасування, як виняток ... передача персональних даних іноземним суб’єктам ... що необхідні для надання медичної допомоги та/або реабілітаційної допомоги із застосуванням телемедицини, може здійснюватися із забезпеченням захисту персональних даних відповідно до законодавства тієї країни, в якій медичному працівнику ... надано право на провадження медичної практики (крім громадян Російської Федерації та Республіки Білорусь)”
Link checked 18 August 2026
- Official sourceSecretariat of the Ukrainian Parliament Commissioner for Human RightsCommissioner for Human Rights — findings from inspections of the national electronic health system, the National Health Service and the state enterprise eZdorovya
ombudsman.gov.ua
Link checked 18 August 2026
Кримінальний кодекс України, стаття 114-2
Act of parliament · Criminal Code of Ukraine No. 2341-III, Article 114-2 · Mapping and location
Ukraine's real mapping rule is a criminal one. Publishing anything that pinpoints Ukrainian troops, weapons movements or military sites carries a prison sentence, and it applies to user-generated photographs, check-ins and any product that surfaces fine-grained location.
Enforced by State Service of Special Communications and Information Protection of Ukraine
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryNot a storage rule but a publication ban. Location data that would let Ukrainian military positions be identified on the ground may not be disseminated at all unless the General Staff or the Ministry of Defence has already published it.
What it costs if you get it wrong
- Criminal liability: Five to eight years' imprisonmentDisseminating information about the movement or location of Ukrainian forces where they can be identified on the ground, during martial law
- Criminal liability: Three to five years' imprisonmentDisseminating information about weapons deliveries into or across Ukraine not already published officially
Sources
- Official sourceVerkhovna Rada of UkraineCriminal Code of Ukraine, Article 114-2
zakon.rada.gov.ua
“Поширення інформації про переміщення, рух або розташування Збройних Сил України чи інших утворених відповідно до законів України військових формувань, за можливості їх ідентифікації на місцевості ... карається позбавленням волі на строк від п’яти до восьми років.”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That the Cabinet of Ministers has never adopted the list of states ensuring adequate data protection required by Article 29(3)
We can prove a negative only indirectly. On the official legislation site every live cross-reference in the Act is hyperlinked to the instrument it names, and this one is not. We found no adopted list, but we could not run a full-text search of government resolutions because the search form on the legislation site requires JavaScript.
The exact deadline, in hours, for mandatory cyber incident reports to CERT-UA
The statute deliberately leaves it to an order of the State Service of Special Communications and Information Protection, and we could not open that order. Treat the deadline as short and set administratively, and confirm it directly with the agency before relying on any number.
The status of the long-promised replacement privacy law aligned with European rules
Our web search quota was exhausted before we could open the parliamentary bill card, and the parliament's bill search will not filter by number without JavaScript. What we can prove is the negative that matters commercially: the 2010 Act is still shown as in force, with its current revision dated 14 June 2025, so no replacement has commenced.
Whether the National Bank has issued a separate instrument governing banks' use of cloud services, and whether it restricts offshore hosting
The 2017 information security regulation for banks says in terms that cloud requirements are set by a separate document, and the Cloud Services Act gave the National Bank the power to make one. We could not locate that instrument on the bank's own site, whose search endpoints returned errors.
Whether the register of cloud and data centre providers that public bodies must buy from actually has entries
The electronic communications regulator's register page was unreachable from our network. An empty register would make the public procurement route in the Cloud Services Act unusable in practice.
That there is no data localisation requirement in Ukrainian banking, payments, insurance, telecoms, education, gaming or e-commerce law
We read the Payment Services Act and the Electronic Communications Act in full on 18 August 2026 and found none. We did not read the insurance, education or gaming statutes, and subordinate regulator acts were not exhaustively checked. Recorded as no rule found on 18 August 2026, not as an assertion that none exists.
Whether the Commissioner's inspections have produced fines against private companies, as opposed to orders against public bodies
The published results are dominated by councils, administrative service centres and state enterprises. Court outcomes on the administrative offence reports are not published on the Commissioner's site, so the real rate of monetary penalties is unknown.
The exact commencement dates recorded for the amending laws — No. 1907-IX, No. 2075-IX, No. 2494-IX, No. 3585-IX and No. 4336-IX
Each of these commences by formula rather than by a stated date: the day after publication, or six months after publication. We verified the formula in each Act's final provisions but could not open the gazette issue that fixes the publication day, so the dates in this record are calculated to within a few days. The adoption dates and the substance are verified.
60-day cadence. Martial law runs in 90-day cycles and the current one ends about 31 October 2026. At least three permissions in this record — state registers abroad, foreign clouds for the armed forces, and the telemedicine transfer exception — exist only while martial law lasts and expire six months after it is lifted, and in every case the default that returns is stricter. A longer cadence risks the site asserting a permission that has already lapsed.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Ukraine versus Argentina
- Ukraine versus Armenia
- Ukraine versus Australia
- Ukraine versus Austria
- Ukraine versus Azerbaijan
- Ukraine versus Brazil
- Ukraine versus Bulgaria
- Ukraine versus Cambodia
- Ukraine versus Canada
- Ukraine versus China
- Ukraine versus Croatia
- Ukraine versus Cyprus
- Ukraine versus Estonia
- Ukraine versus France
- Ukraine versus Georgia
- Ukraine versus Germany
- Ukraine versus Greece
- Ukraine versus Hong Kong SAR
- Ukraine versus Hungary
- Ukraine versus Iceland
- Ukraine versus India
- Ukraine versus Indonesia
- Ukraine versus Ireland
- Ukraine versus Israel
- Ukraine versus Italy
- Ukraine versus Japan
- Ukraine versus Latvia
- Ukraine versus Lithuania
- Ukraine versus Luxembourg
- Ukraine versus Malta
- Ukraine versus Mexico
- Ukraine versus Mongolia
- Ukraine versus Nepal
- Ukraine versus Netherlands
- Ukraine versus Poland
- Ukraine versus Russia
- Ukraine versus Saudi Arabia
- Ukraine versus Serbia
- Ukraine versus Singapore
- Ukraine versus Slovakia
- Ukraine versus Slovenia
- Ukraine versus South Korea
- Ukraine versus Spain
- Ukraine versus Sri Lanka
- Ukraine versus Sweden
- Ukraine versus Switzerland
- Ukraine versus Taiwan
- Ukraine versus Thailand
- Ukraine versus Turkey
- Ukraine versus United Arab Emirates
- Ukraine versus United Kingdom
- Ukraine versus United States
- Ukraine versus Uzbekistan