Ukraine
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Ukraine — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Ukraine still runs its 2010 privacy law, not a European-style one. Personal data may only go to a country the law treats as safe. That means Europe, plus the 50-odd countries that signed a Council of Europe data treaty. The United States is not on that list. Fines are tiny. But the human rights Commissioner really does inspect, and misusing data can be a crime.
Data governance in Ukraine
The eight things that decide how you handle data about people in Ukraine. Same eight on every country page, so you can compare.
Who has to follow these rules
Probably not, if you have nothing in Ukraine. The 2010 law simply says it covers personal data handled by computer or in structured paper files. It has no clause reaching foreign companies that only sell into Ukraine from abroad. It does not make you appoint a local representative. There is no size or revenue cut-off either. A corner shop and a bank are treated the same.
Article 1 of Law No. 2297-VI sets out what the law covers. It says nothing about territory, and nothing about reaching companies with no office in Ukraine. Article 4 lists the parties to a data relationship, with no condition about where anyone is based. That gap cuts both ways. There is no stated foreign reach, but there is no stated exclusion either. The Commissioner has inspected Ukrainian-established organisations of all ownership types. A local presence rule does appear elsewhere. It is Article 8 of Law No. 80/94-VR, as rewritten by Law No. 4336-IX of 27 March 2025. If any part of a system or critical information infrastructure object sits outside Ukraine, the owner or operator must be a legal entity registered in Ukraine. Having an official representative in Ukraine is the alternative.
Sources
- Official sourceVerkhovna Rada of UkraineLaw of Ukraine on Personal Data Protection No. 2297-VI, Articles 1 and 4 (consolidated text, revision of 14 June 2025)
zakon.rada.gov.ua
“Цей Закон поширюється на діяльність з обробки персональних даних, яка здійснюється повністю або частково із застосуванням автоматизованих засобів, а також на обробку персональних даних, що містяться у картотеці чи призначені до внесення до картотеки, із застосуванням неавтоматизованих засобів.”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineLaw on Protection of Information in Information and Communication Systems No. 80/94-VR, Article 8 (as rewritten by Law No. 4336-IX of 27 March 2025)
zakon.rada.gov.ua
“власник або розпорядник системи, об’єкта критичної інформаційної інфраструктури або його представник, який надає послуги з використанням системи, об’єкта критичної інформаційної інфраструктури, елементи якої розміщуються поза межами України, є юридичною особою, зареєстрованою в Україні, або має свого офіційного представника в Україні”
Link checked 18 August 2026
Where the data is allowed to live
Yes, but only to countries Ukraine already treats as safe. Those are the European Economic Area countries, plus every country that has signed the Council of Europe's data protection treaty. That is roughly 55 states. The United States has signed neither. So routine transfers to American servers do not fit the safe-country route. They need one of the narrow exceptions instead. Whole industries then change the answer. Government, defence and critical infrastructure are far tighter. Securities firms are unusually looser.
- Ways to send data out:
- Official 'this country is safe' decision · Explicit consent · Needed for a contract · To save someone’s life · Important public interest
Article 29(3) of Law No. 2297-VI allows transfers to foreign parties only where the destination state ensures adequate protection. It must also be a case established by law or by an international treaty. The statute itself treats two groups as adequate. European Economic Area member states. And states that have signed the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108). Law No. 3585-IX of 22 February 2024 added a third group. It covers states whose capital markets regulators have signed the IOSCO Multilateral Memorandum of Understanding. This is a rare industry rule that widens the transfer route rather than narrowing it. It brings the United States back in for securities purposes. Article 29(3) also tells the Cabinet of Ministers to set a list of states that ensure adequate protection. We found no adopted list. On the official gazette site this cross-reference is not linked to any document. Every other live cross-reference in the same law is linked. INDUSTRY RULES: (a) Government. Where a state or local authority decides how data is used, only a state-owned or municipal enterprise may handle it for them (Article 4(3)). That shuts out private and foreign suppliers entirely. (b) Government and defence. Official information and state secrets may not be handled using cloud resources or data centres located abroad. During martial law the Ministry of Defence and the Armed Forces may do exactly that. (c) Government. State information resources and public electronic registers may currently be hosted abroad. That is only because martial law is in force. (d) All industries. Hosting is banned outright in four places. On temporarily occupied territory. In a state Parliament has recognised as an aggressor or occupier. In a state in a customs or military union with such a state. Or with a sanctioned person. (e) Health. A martial law exception lets telemedicine data follow the law of the treating clinician's country. Citizens of Russia and Belarus are excluded. (f) Securities. The IOSCO widening above. We found no transfer restriction specific to banking, payments, insurance, telecoms, education, gaming, e-commerce or mapping. That is based on the main statutes we read on 18 August 2026.
Sources
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Article 29(3) and (4) — international cooperation and transfer of personal data
zakon.rada.gov.ua
“Держави - учасниці Європейського економічного простору, а також держави, які підписали Конвенцію Ради Європи про захист осіб у зв’язку з автоматизованою обробкою персональних даних, визнаються такими, що забезпечують належний рівень захисту персональних даних.”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineLaw of Ukraine on Cloud Services No. 2075-IX, Article 11(3) — ban on foreign cloud for official information and state secrets, with a martial-law carve-out for the Ministry of Defence
zakon.rada.gov.ua
“Забороняється обробка службової інформації та інформації, що становить державну таємницю, за допомогою хмарних ресурсів та/або центрів обробки даних, що розміщені за кордоном (крім випадків, передбачених абзацом другим цієї частини) чи на тимчасово окупованих територіях України”
Link checked 18 August 2026
- Official sourceCabinet of Ministers of UkraineCabinet of Ministers Resolution No. 263 of 12 March 2022 on information systems and public electronic registers under martial law (as amended to 20 May 2026)
zakon.rada.gov.ua
“розміщувати державні інформаційні ресурси та публічні електронні реєстри на хмарних ресурсах та/або в центрах обробки даних, що розташовані за межами України”
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
There is no form to file and no government permission to get. Either you send the data to a country the law already treats as safe, or you rely on one of five narrow exceptions. One: the person's clear consent. Two: it is needed for a contract made for that person's benefit. Three: protecting someone's life. Four: an important public interest or a legal claim. Five: you give guarantees that private and family life will not be interfered with. That last one is broad, and a lot of Ukrainian practice leans on it.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Explicit consent · Needed for a contract · To save someone’s life · Legal claims
You can only send data to approved countries. But the approval works by category, not by named country. The categories are filled in by the law itself, not by a published government list. Article 29(4) of Law No. 2297-VI sets out the five alternatives. There is no standard contract published by the Ukrainian government. There is no company-wide binding rules scheme, no certification scheme, and no case-by-case approval process. The Cabinet of Ministers has the power under Article 29(3) to publish a list of safe states. We found no such list. So the categories written into the statute are doing all the work today. That means a transfer to a United States cloud provider under the general law usually rests on consent. The alternative is the guarantees limb in Article 29(4)(5). It does not rest on the destination being treated as safe.
Sources
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Article 29(4) — the five alternatives to adequacy
zakon.rada.gov.ua
“Персональні дані можуть передаватися іноземним суб’єктам відносин, пов’язаних з персональними даними, також у разі: 1) надання суб’єктом персональних даних однозначної згоди на таку передачу; ... 5) надання володільцем персональних даних відповідних гарантій щодо невтручання в особисте і сімейне життя суб’єкта персональних даних.”
Link checked 18 August 2026
- Official sourceSecretariat of the Ukrainian Parliament Commissioner for Human RightsCommissioner for Human Rights — recommendations and clarifications on personal data protection
ombudsman.gov.ua
Link checked 18 August 2026
The regulator, and whether it actually acts
The Ukrainian Parliament Commissioner for Human Rights is the data protection regulator. This is the national ombudsman, and it is working. It publishes a fresh inspection programme every three months. The one for July to September 2026 went up on 2 July 2026. It also publishes what it found, including a run of checks on the national electronic health system. The catch is the money. The regulator cannot fine anyone itself. It writes up a case and sends it to a court, and the maximum penalty is about $800.
Article 22 of Law No. 2297-VI gives supervision to the Commissioner and the courts. Article 23 sets out the Commissioner's powers. It can run planned and unplanned inspections, on site or on paper. It can demand any document, including restricted-access information. It can issue binding orders to stop or change how data is used. And it can draw up administrative offence reports for a court. The procedure is set by Commissioner's Order No. 1/02-14 of 8 January 2014. Published inspection targets lean heavily towards public bodies. City councils, administrative service centres, the National Health Service and the state enterprise eZdorovya, with a smaller number of private companies. Other bodies matter too. The State Service of Special Communications and Information Protection runs cyber incident response through CERT-UA. It also supervises the protection of state information resources. The National Bank supervises banks and payment providers. There is no separate specialist data protection authority. The draft law that would create one has not been passed.
Sources
- Official sourceSecretariat of the Ukrainian Parliament Commissioner for Human RightsInspection programmes in the field of personal data protection, including the third quarter of 2026 (published 2 July 2026)
ombudsman.gov.ua
Link checked 18 August 2026
- Official sourceSecretariat of the Ukrainian Parliament Commissioner for Human RightsCommissioner for Human Rights — supervision of compliance with data protection law, procedure under Order No. 1/02-14 of 8 January 2014
ombudsman.gov.ua
“на суб’єкта перевірки у встановленому законом порядку може накладатися штраф від ста до двох тисяч неоподатковуваних мінімумів доходів громадян”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Articles 22 and 23 — supervision and the Commissioner's powers
zakon.rada.gov.ua
Link checked 18 August 2026
How long you must keep it — and when to delete it
Minimum keep times come from tax law. Companies must keep primary accounting documents and financial statements for 1,825 days, which is five years. Papers needed for transfer pricing checks run to 2,555 days, which is seven years. Everything else the tax authority may ask for runs 1,095 days, which is three years. The maximum comes from the privacy law. You must delete personal data when the agreed storage period runs out. You must also delete it when your relationship with the person ends, unless another law tells you to keep it.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
Article 44.3 of the Tax Code sets the minimum periods. They are counted from the day the relevant return was filed. Article 6(8) of Law No. 2297-VI is the general storage limit. Data may be held in a form that identifies people no longer than the purpose requires. Article 15(2) makes that concrete by listing four deletion triggers. The second is the one people miss. It is the end of the legal relationship between the person and the organisation holding the data. Where the two directions clash, the tax and accounting minimum wins. Article 15(2)(2) is expressly subject to any contrary rule of law. Article 27(1) lets other laws add to the privacy law, as long as they do not contradict it. There is no general duty to keep logs in Ukrainian law. There is no rule making telecoms companies keep traffic data. We read Law No. 1089-IX on Electronic Communications in full on 18 August 2026. We found only a duty to keep billing records for the limitation period.
Sources
- Official sourceVerkhovna Rada of UkraineTax Code of Ukraine No. 2755-VI, paragraph 44.3 — minimum document retention of 2,555, 1,825 and 1,095 days
zakon.rada.gov.ua
“44.3.2. 1825 днів - для первинних документів, регістрів бухгалтерського обліку, фінансової звітності, інших документів, пов’язаних з обчисленням і сплатою податків і зборів”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Articles 6(8) and 15 — storage limitation and deletion triggers
zakon.rada.gov.ua
“Персональні дані підлягають видаленню або знищенню у разі: 1) закінчення строку зберігання даних, визначеного згодою суб'єкта персональних даних на обробку цих даних або законом; 2) припинення правовідносин між суб'єктом персональних даних та володільцем чи розпорядником, якщо інше не передбачено законом”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
This is the biggest surprise in Ukrainian law. If you lose personal data, you have no duty to tell the regulator. You have no duty to tell the people affected either. The 2010 privacy law simply has no breach reporting clause. The only compulsory deadlines sit in the cyber security rules. They only apply if you run a state system or a piece of critical information infrastructure. Even there, the law does not set the hours. It leaves the deadline to an order of the cyber agency.
- What you have to do here:
- Report cyber incidents · Secure the data
Law No. 2297-VI has no breach reporting duty of any kind. Article 24 imposes only a general security duty. The compulsory deadlines come from Article 9-1 of Law No. 2163-VIII on the Basic Principles of Cyber Security. It was rewritten by Law No. 4336-IX of 27 March 2025. Owners of systems holding state information resources, official information or state secrets must report ALL cyber incidents to the relevant response team. Owners of critical information infrastructure objects must report SIGNIFICANT incidents only. Article 9-1(4) says compulsory reports are made 'within the time limits and in the manner established by the Authorised Body'. That body is the State Service of Special Communications and Information Protection. So the deadline lives in a regulator's order, not in the statute. It can be changed without going through Parliament. Officials who miss it face administrative liability. Separately, Article 9(3) of Law No. 80/94-VR covers the owner of a system holding state information resources. They must tell the same agency about attempted or actual unauthorised access. So there are two deadlines for the public sector and its suppliers. There is no deadline at all for an ordinary private company that loses customer data.
Sources
- Official sourceVerkhovna Rada of UkraineLaw on the Basic Principles of Cyber Security No. 2163-VIII, Article 9-1 — mandatory cyber incident reporting
zakon.rada.gov.ua
“Усі обов’язкові повідомлення про кіберінциденти, кібератаки, кіберзагрози подаються суб’єктами, визначеними цією статтею, у строки та порядку, встановлені Уповноваженим органом.”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Article 24 — security duty, with no breach notification obligation anywhere in the Act
zakon.rada.gov.ua
Link checked 18 August 2026
What catches people out
Five things. (1) If a Ukrainian government body decides how personal data is used, only a Ukrainian state-owned or municipal company may handle that data for it. A private or foreign supplier is not allowed at all. (2) Misusing personal data is a crime, not just a fine. Repeat offences carry up to five years in prison. (3) The fines are aimed at named individuals and sole traders, not at companies. (4) Posting anything that shows where Ukrainian troops are carries five to eight years in prison. (5) Martial law lets the government limit the constitutional right to privacy that the whole system rests on.
- What you have to do here:
- Written vendor contract
- What it costs if you get it wrong:
- Criminal liability · Fixed maximum fine
(1) Article 4(3) of Law No. 2297-VI, in the wording introduced by Law No. 1907-IX of 18 November 2021. A state authority or a local self-government body may decide how data is used. If so, only an enterprise in state or municipal ownership may handle it for them. No contract can get around this. (2) Article 182 of the Criminal Code covers unlawful collection, storage, use, destruction or spreading of confidential information about a person. The punishment is a fine of 500 to 1,000 tax-free minimums (about $205 to $410). It can also be correctional labour, probation supervision, or restriction of liberty for up to three years. A repeat offence, or substantial harm, carries up to five years in prison. (3) Article 188-39 of the Code of Administrative Offences applies to citizens, officials and individual entrepreneurs. No administrative fine for a data protection breach is payable by a company. That is why the maximum exposure of about $800 is so misleadingly small. (4) Article 114-2 of the Criminal Code was added after the 2022 invasion. It punishes spreading information about the movement or location of Ukrainian forces, where they can be identified on the ground. The sentence is five to eight years in prison. Any product handling user photographs, check-ins or precise location data in Ukraine is exposed. (5) Presidential Decree No. 64/2022, paragraph 3. It expressly allows temporary limits on the constitutional privacy right under Article 32 of the Constitution. Those limits last as long as martial law does. The Commissioner's own guidance confirms it.
Sources
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Article 4(3) — only a state or municipal enterprise may process personal data for a public authority
zakon.rada.gov.ua
“Розпорядником персональних даних, володільцем яких є орган державної влади чи орган місцевого самоврядування, крім цих органів, може бути лише підприємство державної або комунальної форми власності.”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineCriminal Code of Ukraine No. 2341-III, Articles 182 and 114-2
zakon.rada.gov.ua
“Поширення інформації про переміщення, рух або розташування Збройних Сил України ... за можливості їх ідентифікації на місцевості ... карається позбавленням волі на строк від п’яти до восьми років.”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineCode of Ukraine on Administrative Offences, Article 188-39 — penalties addressed to citizens, officials and individual entrepreneurs
zakon.rada.gov.ua
Link checked 18 August 2026
- Official sourceSecretariat of the Ukrainian Parliament Commissioner for Human RightsCommissioner for Human Rights — guidance on personal data protection under martial law
ombudsman.gov.ua
“Згідно з пунктом 3 Указу у зв’язку із введенням в Україні воєнного стану тимчасово, на період дії правового режиму воєнного стану, можуть обмежуватися конституційні права і свободи людини і громадянина, передбачені, зокрема, статтею 32 Конституції України.”
Link checked 18 August 2026
What's changing next
The date to watch is not a new law. It is the end of the war. Martial law was extended again on 13 July 2026. It now runs from 2 August 2026 for 90 days, so to about 31 October 2026. Several of today's permissions exist only while it lasts. They end six months after it ends. A European-style replacement privacy law has been discussed for years and still has not passed. Do not plan around its arrival.
DATED ITEMS. Martial law was extended by Presidential Decree No. 596/2026 of 13 July 2026. It runs from 05:30 on 2 August 2026 for 90 days. This is the twenty-second extension since February 2022. Three permissions are tied to martial law and lapse six months after it is lifted. State information resources and public electronic registers may be hosted on clouds and in data centres abroad. The Ministry of Defence and the Armed Forces may handle defence information, official information and state secrets in foreign clouds. And telemedicine data may be transferred under the law of the treating clinician's country, except for Russian and Belarusian citizens. In each case the position that returns is more restrictive, not less. SWITCHES THAT COULD BE FLIPPED. First, the Cabinet of Ministers may at any time publish the list of states treated as safe under Article 29(3). That could confirm or narrow the current position, with no consultation. Second, the cyber agency sets the compulsory incident reporting deadline by its own order, so the deadline can be shortened administratively. Third, the martial law decree already allows limits on the constitutional privacy right. Further restrictions do not need a new act of Parliament. Fourth, the ban on hosting in aggressor, occupied or sanctioned territories keys off sanctions lists that change often.
Sources
- Official sourcePresident of Ukraine / Verkhovna Rada of UkrainePresidential Decree No. 64/2022 introducing martial law, as extended by Decree No. 596/2026 of 13 July 2026
zakon.rada.gov.ua
“Строк дії воєнного стану в Україні продовжено з 05 години 30 хвилин 2 серпня 2026 року строком на 90 діб згідно з Указом Президента № 596/2026 від 13.07.2026”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, card page showing the Act as in force with the current revision dated 14 June 2025
zakon.rada.gov.ua
Link checked 18 August 2026
What to do: Diarise 31 October 2026 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries7 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data must stay in the country
Official name: Закон України "Про захист персональних даних", частина третя статті 4 · Law No. 2297-VI, Article 4(3), in the wording of Law No. 1907-IX of 18 November 2021 · Act of parliament
Where a Ukrainian state authority or local council decides how personal data is used, only one kind of supplier may handle that data. That is an enterprise in state or municipal ownership. Private and foreign suppliers are shut out, whatever the contract says.
Enforced by Ukrainian Parliament Commissioner for Human Rights
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryThis is not written as a location rule, but it works like one. The only permitted supplier is a Ukrainian state or municipal enterprise. So the data cannot go to a foreign or private cloud operator at all.
- Written vendor contract
Sources
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Article 4(3)
zakon.rada.gov.ua
“Розпорядником персональних даних, володільцем яких є орган державної влади чи орган місцевого самоврядування, крім цих органів, може бути лише підприємство державної або комунальної форми власності.”
Link checked 18 August 2026
Government data rules
Official name: Закон України "Про захист інформації в інформаційно-комунікаційних системах" · Law No. 80/94-VR of 5 July 1994, Article 8 rewritten by Law No. 4336-IX of 27 March 2025 · Act of parliament
This is the rule that really governs Ukrainian government data. State information resources must run in systems that have passed a security authorisation. Backups may be moved abroad only while martial law lasts. Hosting in Russia, Belarus, occupied territory or sanctioned infrastructure is banned outright. And any part of the system sitting abroad forces a Ukrainian legal presence.
Enforced by State Service of Special Communications and Information Protection of Ukraine
How this country controls where data goes: Any country except banned ones · Accepted routes: Security review needed, Certification scheme
What you have to do
- Hold a security certificateState information resources and restricted-access information held by public bodies must run in a security-authorised system. The alternative is a system holding a certificate of conformity to an information security standard, issued by a conformity assessment body.
- Appoint a representativeAny part of the system or critical information infrastructure object may sit outside Ukraine. If it does, the operator must be a Ukrainian-registered legal entity, or have an official representative in Ukraine.
- Keep the data in the countryYou may not host the system, its parts or its backups in three places. On temporarily occupied territory. In a state Parliament has recognised as an aggressor or occupier. Or in a state in a customs or military union with such a state.
- Report cyber incidentsAttempted or actual unauthorised access must be reported to the State Service of Special Communications and Information Protection.
- Appoint a data protection officerA cyber protection unit, or named persons responsible for information protection, must be set up.
Sources
- Official sourceVerkhovna Rada of UkraineLaw No. 80/94-VR on Protection of Information in Information and Communication Systems, Articles 8 to 10
zakon.rada.gov.ua
“Розміщення систем, об’єктів критичної інформаційної інфраструктури або їх елементів та зберігання резервних копій державних інформаційних ресурсів на тимчасово окупованій території України, території держави, визнаної Верховною Радою України державою-агресором, або на території держави, яка входить до митного або воєнного союзу з такими державами, забороняється.”
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineLaw No. 4336-IX of 27 March 2025 amending the information protection and cyber security laws — commencement the day after publication
zakon.rada.gov.ua
“Цей Закон набирає чинності з дня, наступного за днем його опублікування, крім підпункту 5 пункту 4 розділу I цього Закону, який набирає чинності через шість місяців з дня його опублікування.”
Link checked 18 August 2026
Government data must stay in the country (Government)
Official name: Постанова КМУ № 263 "Деякі питання забезпечення функціонування інформаційно-комунікаційних систем, електронних комунікаційних систем, публічних електронних реєстрів в умовах воєнного стану" · Cabinet of Ministers Resolution No. 263 of 12 March 2022, last amended by Resolution No. 635 of 20 May 2026 · Directly binding regulation
The wartime permission that moved Ukraine's state registers out of the country. It works only while martial law lasts, and the underlying laws restore the tighter default six months after martial law ends.
Enforced by Cabinet of Ministers of Ukraine
How this country controls where data goes: Any country except banned ones · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryThis reverses the usual rule. While martial law lasts, ministries, executive bodies and state and municipal enterprises MAY place state information resources and public electronic registers outside Ukraine. That covers cloud resources and data centres. They may also register gov.ua domain names for that hosting.
Sources
- Official sourceCabinet of Ministers of UkraineCabinet of Ministers Resolution No. 263 of 12 March 2022, paragraph 1(1)
zakon.rada.gov.ua
“розміщувати державні інформаційні ресурси та публічні електронні реєстри на хмарних ресурсах та/або в центрах обробки даних, що розташовані за межами України, та реєструвати доменні імена у домені gov.ua для такого розміщення”
Link checked 18 August 2026
- Official sourcePresident of Ukraine / Verkhovna Rada of UkrainePresidential Decree No. 64/2022 on martial law, current extension to about 31 October 2026
zakon.rada.gov.ua
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Закон України "Про хмарні послуги" · Law No. 2075-IX of 17 February 2022, Articles 8 to 12, as amended by Law No. 3783-IX of 5 June 2024 · Act of parliament
This is Ukraine's cloud law. Government buyers may only use providers on an official register. Contracts must run under Ukrainian law, in Ukrainian courts. Official information and state secrets are barred from foreign clouds. Since June 2024 the armed forces may use them while martial law lasts.
How this country controls where data goes: Not allowed · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryOfficial information and state secrets may not be handled using cloud resources or data centres located abroad. There is one exception. During martial law the Ministry of Defence and the Armed Forces may use foreign clouds and data centres. That covers military and defence information, including state secrets.
- Register or notifyPublic bodies must buy cloud and data centre services only from providers entered on the register kept by the electronic communications regulator.
- Make switching cloud provider possibleContracts must set out how data and backups move to another provider, or back to the customer. The government sets a switching procedure built on interoperability.
- Prove the data stays under local controlContracts with public users and critical information infrastructure operators must be governed by Ukrainian law and disputes must go to Ukrainian courts.
- Report breaches to the regulatorThe contract must require immediate notice to the customer of any cyber security incident with significant impact.
Sources
- Official sourceVerkhovna Rada of UkraineLaw of Ukraine on Cloud Services No. 2075-IX, Articles 9 to 12
zakon.rada.gov.ua
“У період дії воєнного стану Міністерство оборони України та Збройні Сили України можуть обробляти інформацію у воєнній і оборонній сферах, у тому числі службову інформацію та інформацію, що становить державну таємницю ... за допомогою хмарних ресурсів та/або центрів обробки даних, що розміщені за кордоном”
Link checked 18 August 2026
Capital markets rules
Official name: Закон України "Про захист персональних даних", абзац третій частини третьої статті 29 · Law No. 2297-VI, Article 29(3) third paragraph, inserted by Law No. 3585-IX of 22 February 2024 · Act of parliament
This industry rule makes transfers easier, not harder. Since March 2024, a country counts as safe if its securities regulator has signed the right memorandum. That is the International Organization of Securities Commissions information-sharing memorandum. It brings in the United States and much of Asia for capital markets work.
Enforced by National Securities and Stock Market Commission
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision
What you have to do
- Put a transfer safeguard in placeNo extra paperwork. The destination simply counts as safe if its capital markets regulator has signed the IOSCO multilateral memorandum.
Sources
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Article 29(3), third paragraph
zakon.rada.gov.ua
“Держави, регулятори ринків капіталу яких є підписантами Багатостороннього меморандуму про взаєморозуміння щодо консультування та співробітництва і обміну інформацією Міжнародної організації комісій з цінних паперів (International Organization of Securities Commissions - IOSCO), визнаються такими, що забезпечують належний рівень захисту персональних даних.”
Link checked 18 August 2026
Health data rules
Official name: Закон України "Про захист персональних даних", пункт 2 статті 30 · Law No. 2297-VI, Article 30(2), inserted by Law No. 2494-IX of 29 July 2022 · Act of parliament
While martial law lasts, and for six months afterwards, telemedicine data may go abroad on different terms. Health and rehabilitation data needed for telemedicine follows the law of the treating clinician's own country. Ukraine's usual safe-country test does not apply. Russian and Belarusian citizens are excluded from this exception.
Enforced by Ukrainian Parliament Commissioner for Human Rights
How this country controls where data goes: Any country except banned ones · Accepted routes: To save someone’s life, Official 'this country is safe' decision
What you have to do
- Put a transfer safeguard in placeProtection follows the law of the country where the clinician or rehabilitation specialist is licensed. The usual safe-country test does not apply. Citizens of Russia and Belarus are excluded from the exception.
Sources
- Official sourceVerkhovna Rada of UkraineLaw No. 2297-VI, Article 30(2)
zakon.rada.gov.ua
“в період дії воєнного стану в Україні та протягом шести місяців після його припинення чи скасування, як виняток ... передача персональних даних іноземним суб’єктам ... що необхідні для надання медичної допомоги та/або реабілітаційної допомоги із застосуванням телемедицини, може здійснюватися із забезпеченням захисту персональних даних відповідно до законодавства тієї країни, в якій медичному працівнику ... надано право на провадження медичної практики (крім громадян Російської Федерації та Республіки Білорусь)”
Link checked 18 August 2026
- Official sourceSecretariat of the Ukrainian Parliament Commissioner for Human RightsCommissioner for Human Rights — findings from inspections of the national electronic health system, the National Health Service and the state enterprise eZdorovya
ombudsman.gov.ua
Link checked 18 August 2026
State and security data rules
Official name: Кримінальний кодекс України, стаття 114-2 · Criminal Code of Ukraine No. 2341-III, Article 114-2 · Act of parliament
Ukraine's real mapping rule is a criminal one. Publishing anything that pinpoints Ukrainian troops, weapons movements or military sites carries a prison sentence. It applies to user photographs, check-ins and any product that shows precise location.
Enforced by State Service of Special Communications and Information Protection of Ukraine
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryThis is not a storage rule. It is a publication ban. You may not spread location data that would let Ukrainian military positions be identified on the ground. The exception is where the General Staff or the Ministry of Defence has already published it.
What it costs if you get it wrong
- Criminal liability: Five to eight years' imprisonmentDisseminating information about the movement or location of Ukrainian forces where they can be identified on the ground, during martial law
- Criminal liability: Three to five years' imprisonmentDisseminating information about weapons deliveries into or across Ukraine not already published officially
Sources
- Official sourceVerkhovna Rada of UkraineCriminal Code of Ukraine, Article 114-2
zakon.rada.gov.ua
“Поширення інформації про переміщення, рух або розташування Збройних Сил України чи інших утворених відповідно до законів України військових формувань, за можливості їх ідентифікації на місцевості ... карається позбавленням волі на строк від п’яти до восьми років.”
Link checked 18 August 2026
Applies to every company1 rule
These bind you whatever business you are in, once the country's rules reach you.
Breach reporting rules
Official name: Закон України "Про захист персональних даних" · Law No. 2297-VI of 1 June 2010, current revision 14 June 2025 · Act of parliament
This is Ukraine's general privacy law. Its structure has not changed since 2010, and no European-style statute has replaced it. Data may only go to European Economic Area states, or to countries that signed the Council of Europe data treaty. Otherwise you need one of five narrow exceptions. There is no breach reporting duty, no risk assessment duty and no general registration. The fines are among the smallest in Europe.
Enforced by Ukrainian Parliament Commissioner for Human Rights
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Explicit consent, Needed for a contract, To save someone’s life, Important public interest, Legal claims
What you have to do
- Get consent
- Allowed because the law requires it
- Tell people what you doYou must tell the person within ten working days of collection. Tell them who holds the data, what is held, why, and who it will be passed to.
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Secure the data
- Register or notifyThis is not a general register. You only notify the Commissioner about data use that poses a special risk. Do it within thirty working days of starting. Report changes within ten working days.
- Appoint a data protection officer — applies at: Public bodies, and any controller whose processing must be notified as high riskYou appoint a unit or a named responsible person. You must report the appointment to the Commissioner, and it is published.
- Written vendor contractYou must hire anyone who handles data for you under a written contract. They may act only for the purpose and to the extent the contract states.
- Put a transfer safeguard in place
- Delete data after a periodDelete when the agreed or statutory storage period ends, or when the relationship with the person ends, unless another law requires retention.
What it costs if you get it wrong
- Fixed maximum fine: 2,000 tax-free minimum incomes (UAH 34,000) — about $820Repeat failure to protect data leading to unlawful access, or repeat failure to obey the Commissioner. Imposed by a court on an individual, an official or a sole trader — not on a company.
- Criminal liability: Up to five years' imprisonmentUnlawful collection, storage, use, destruction or dissemination of confidential information about a person, where repeated or causing substantial harm (Criminal Code Article 182)
- Order to stopThe Commissioner may order processing to be suspended or stopped, or data to be changed, deleted or destroyed.
Sources
- Official sourceVerkhovna Rada of UkraineLaw of Ukraine on Personal Data Protection No. 2297-VI, consolidated text
zakon.rada.gov.ua
Link checked 18 August 2026
- Official sourceVerkhovna Rada of UkraineCode of Ukraine on Administrative Offences, Article 188-39
zakon.rada.gov.ua
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That the Cabinet of Ministers has never adopted the list of states ensuring adequate data protection required by Article 29(3)
We could not confirm that no list of safe states has been adopted. We found no such list. On the official legislation site, every live cross-reference in the Act is linked to the document it names. This one is not.
The exact deadline, in hours, for mandatory cyber incident reports to CERT-UA
We could not confirm the incident reporting deadline. The statute leaves it to an order of the State Service of Special Communications and Information Protection. We could not open that order. Treat the deadline as short and set by the agency. Confirm it with the agency before you rely on any number.
The status of the long-promised replacement privacy law aligned with European rules
We could not confirm the status of the replacement bill. Our web search quota ran out before we could open the parliamentary bill card. We can show the part that matters commercially. The 2010 Act is still shown as in force, with its current revision dated 14 June 2025. So no replacement has started.
Whether the National Bank has issued a separate instrument governing banks' use of cloud services, and whether it restricts offshore hosting
We could not find the cloud rules for banks. The 2017 information security rules for banks say cloud requirements are set in a separate document. The Cloud Services Act gave the National Bank the power to make one. We could not find that document on the bank's own site, whose search returned errors. If you are a bank, ask the National Bank.
Whether the register of cloud and data centre providers that public bodies must buy from actually has entries
We could not confirm whether the cloud provider register has anyone on it. The electronic communications regulator's register page was unreachable from our network. An empty register would make the government purchasing route in the Cloud Services Act unusable.
That there is no rule forcing data to stay in the country requirement in Ukrainian banking, payments, insurance, telecoms, education, gaming or e-commerce law
We found no transfer rule for these industries. We read the Payment Services Act and the Electronic Communications Act in full on 18 August 2026. We did not read the insurance, education or gaming statutes. We did not check every regulator's own rules. Treat this as a rule we could not find, not proof that none exists.
Whether the Commissioner's inspections have produced fines against private companies, as opposed to orders against public bodies
We could not confirm how often money penalties are actually imposed. The published inspection results are dominated by councils, administrative service centres and state enterprises. Court outcomes on the administrative offence reports are not published on the Commissioner's site.
The exact commencement dates recorded for the amending laws — No. 1907-IX, No. 2075-IX, No. 2494-IX, No. 3585-IX and No. 4336-IX
We could not confirm the exact start dates. Each of these laws starts by formula, not by a stated date. It is either the day after publication, or six months after publication. We verified the formula in each Act's final sections. We could not open the gazette issue that fixes the publication day. So the dates here are calculated to within a few days. The adoption dates and the substance are verified.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.