Skip to the content
Global Data RulesData governance rules, country by country

Ukraine

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Depends on your industryWork: MediumEnforcement: Active

Ukraine still runs its 2010 privacy law, not a European-style one. Personal data may leave the country only to a country the law treats as safe — that means Europe and the 50-odd countries that signed a Council of Europe data treaty. The United States is not on that list. Fines are tiny, but the human rights Commissioner really does inspect, and misusing data can be a crime.

Eight questions about Ukraine

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Ukraine's rules apply to my company?

Probably not, if you have nothing in Ukraine. The 2010 law simply says it covers the processing of personal data by automated means or in structured paper files. It contains no clause reaching foreign companies that only sell into Ukraine from abroad, and it does not make you appoint a local representative. There is no size or revenue threshold either — a corner shop and a bank are treated the same.

Medium confidenceNational rulesControllerProcessor

Can I store my users' data outside Ukraine?

Yes, but only to countries Ukraine already treats as safe. Those are the European Economic Area countries plus every country that has signed the Council of Europe's data protection treaty — roughly 55 states. The United States has signed neither, so routine transfers to American servers do not fit the safe-country route and need one of the narrow exceptions instead. Whole sectors then override this: government, defence and critical infrastructure are far tighter, and securities firms are unusually looser.

High confidenceDepends on your industryAllowlistOfficial 'this country is safe' decisionExplicit consentNeeded for a contractSomeone's life is at riskImportant public interest

What do I need in place before data leaves Ukraine?

There is no form to file and no government permission to obtain. You either send the data to a country the law already treats as safe, or you rely on one of five narrow exceptions. Those are: the person's clear consent, necessity for a contract made for that person's benefit, protecting someone's life, an important public interest or a legal claim, and the sender giving guarantees that private and family life will not be interfered with. That last one is a catch-all that a lot of Ukrainian practice leans on.

High confidenceAllowlistOfficial 'this country is safe' decisionExplicit consentNeeded for a contractSomeone's life is at riskLegal claimsPut a transfer safeguard in place

Who enforces the rules in Ukraine, and what can they do?

The Ukrainian Parliament Commissioner for Human Rights — the national ombudsman — is the data protection regulator, and it is genuinely working. It publishes a fresh inspection programme every three months; the one for July to September 2026 went up on 2 July 2026. It also publishes what it found, including a run of checks on the national electronic health system. The catch is the money: the regulator cannot fine anyone itself, it writes up a case and sends it to a court, and the maximum penalty is about $800.

High confidenceActiveRegulator

How long do I have to keep the data?

The floor comes from tax law. Companies must keep primary accounting documents and financial statements for 1,825 days — five years. Papers needed for transfer pricing checks run to 2,555 days, which is seven years. Everything else the tax authority may ask for runs 1,095 days, three years. The ceiling comes from the privacy law: you must delete personal data when the agreed storage period runs out, or when your relationship with the person ends, unless another law tells you to keep it.

High confidenceKeep data for a minimum periodDelete data after a period

What happens if there is a breach?

This is the biggest surprise in Ukrainian law: if you lose personal data, there is no duty to tell the regulator and no duty to tell the people affected. The 2010 privacy law simply has no breach reporting clause. The only mandatory clocks sit in the cyber security regime, and they only bite if you run a state system or a piece of critical information infrastructure. Even there the law does not set the hours — it leaves the deadline to an order of the cyber agency.

Medium confidenceReport cyber incidentsSecure the data

What trips people up in Ukraine?

Five. (1) If a Ukrainian government body is the one deciding how personal data is used, only a Ukrainian state-owned or municipal company may handle that data for it — a private or foreign supplier is not allowed at all. (2) Misusing personal data is a crime, not just a fine, and repeat offences carry up to five years in prison. (3) The fines are aimed at named individuals and sole traders, not at companies. (4) Posting anything that shows where Ukrainian troops are carries five to eight years in prison. (5) Martial law lets the government limit the constitutional right to privacy that the whole system rests on.

High confidenceCriminal liabilityFixed maximum fineWritten vendor contractPrecise location data

What is changing soon in Ukraine?

The date to watch is not a new law — it is the end of the war. Martial law was extended again on 13 July 2026 and now runs from 2 August 2026 for 90 days, so to about 31 October 2026. Several of today's permissions exist only while it lasts, and they die six months after it ends. A European-style replacement privacy law has been discussed for years and has still not been passed, so nothing about the current regime should be planned around its arrival.

High confidenceIn forceProposed

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    1 rule here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    7 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules1 rule

Закон України "Про захист персональних даних"

Act of parliament · Law No. 2297-VI of 1 June 2010, current revision 14 June 2025

In forceYes, with paperwork

Ukraine's general privacy law, unchanged in structure since 2010 and never replaced by a European-style statute. Data may leave only to European Economic Area states, Council of Europe data treaty signatories or under five narrow exceptions. There is no breach notification duty, no risk assessment duty and no general registration, and the fines are among the smallest in Europe.

In force since 1 January 2011

Enforced by Ukrainian Parliament Commissioner for Human Rights

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Explicit consent, Needed for a contract, Someone's life is at risk, Important public interest, Legal claims

High confidence

Industry rules7 rules

Закон України "Про захист персональних даних", частина третя статті 4

Act of parliament · Law No. 2297-VI, Article 4(3), in the wording of Law No. 1907-IX of 18 November 2021 · Government

In forceNo — it stays put

Where a Ukrainian state authority or local council decides how personal data is used, the only party allowed to process that data on its behalf is an enterprise in state or municipal ownership. Private and foreign suppliers are excluded outright, whatever the contract says.

In force since 1 January 2022

Enforced by Ukrainian Parliament Commissioner for Human Rights

Transfer model: Not allowed

High confidence

Закон України "Про захист інформації в інформаційно-комунікаційних системах"

Act of parliament · Law No. 80/94-VR of 5 July 1994, Article 8 rewritten by Law No. 4336-IX of 27 March 2025 · Government

Partly in forceA copy must stay

The rule that really governs Ukrainian government data. State information resources must run in systems that have passed a security authorisation, backups may be moved abroad only while martial law lasts, hosting in Russia, Belarus, occupied territory or sanctioned infrastructure is banned outright, and any offshore element forces a Ukrainian legal presence.

In force since 3 April 2025

Enforced by State Service of Special Communications and Information Protection of Ukraine

Transfer model: Blocklist · Accepted routes: Security review needed, Certification scheme

High confidence

Постанова КМУ № 263 "Деякі питання забезпечення функціонування інформаційно-комунікаційних систем, електронних комунікаційних систем, публічних електронних реєстрів в умовах воєнного стану"

Directly binding regulation · Cabinet of Ministers Resolution No. 263 of 12 March 2022, last amended by Resolution No. 635 of 20 May 2026 · Government

In forceYes, with paperwork

The wartime permission that moved Ukraine's state registers out of the country. It works only while martial law lasts, and the underlying laws restore the tighter default six months after martial law ends.

In force since 12 March 2022

Enforced by Cabinet of Ministers of Ukraine

Transfer model: Blocklist · Accepted routes: Government sign-off needed

High confidence

Who you would hear from

  • Уповноважений Верховної Ради України з прав людини

    General personal data protection supervision for all sectors

    Fully operational and visibly so. Quarterly inspection programmes have been published without interruption through the war; the programme for July to September 2026 was posted on 2 July 2026. Inspection findings are published, including a series on the national electronic health system. It cannot fine anyone directly — it issues binding orders and refers administrative offence reports to the courts, where the ceiling is about $800.

  • Державна служба спеціального зв’язку та захисту інформації України

    Protection of state information resources, critical information infrastructure, cyber incident response through CERT-UA

    Operational. Runs CERT-UA and sets the mandatory cyber incident reporting deadlines by its own order rather than through legislation.

  • Кабінет Міністрів України

    Holds the power to publish the list of states deemed to protect personal data adequately, and makes the wartime rules on hosting state registers abroad

    Operational as a government, but it has not exercised its power under Article 29(3) of the data protection law to publish the list of adequate states.

  • Національний банк України

    Banks, payment institutions, payment infrastructure; sets the rules on banks' use of cloud computing

    Operational. Its 2017 information security regulation for banks expressly excludes cloud services, leaving them to a separate instrument we could not locate on its own site.

  • Національна комісія, що здійснює державне регулювання у сферах електронних комунікацій, радіочастотного спектра та надання послуг поштового зв’язку

    Electronic communications; keeps the register of cloud and data centre providers that public bodies must buy from

    Site reachable on 18 August 2026. We could not open the cloud provider register itself, so whether it is populated is recorded as unconfirmed.

  • Національна комісія з цінних паперів та фондового ринку

    Securities and capital markets; the sector that benefits from the IOSCO adequacy route

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That the Cabinet of Ministers has never adopted the list of states ensuring adequate data protection required by Article 29(3)

    We can prove a negative only indirectly. On the official legislation site every live cross-reference in the Act is hyperlinked to the instrument it names, and this one is not. We found no adopted list, but we could not run a full-text search of government resolutions because the search form on the legislation site requires JavaScript.

  • The exact deadline, in hours, for mandatory cyber incident reports to CERT-UA

    The statute deliberately leaves it to an order of the State Service of Special Communications and Information Protection, and we could not open that order. Treat the deadline as short and set administratively, and confirm it directly with the agency before relying on any number.

  • The status of the long-promised replacement privacy law aligned with European rules

    Our web search quota was exhausted before we could open the parliamentary bill card, and the parliament's bill search will not filter by number without JavaScript. What we can prove is the negative that matters commercially: the 2010 Act is still shown as in force, with its current revision dated 14 June 2025, so no replacement has commenced.

  • Whether the National Bank has issued a separate instrument governing banks' use of cloud services, and whether it restricts offshore hosting

    The 2017 information security regulation for banks says in terms that cloud requirements are set by a separate document, and the Cloud Services Act gave the National Bank the power to make one. We could not locate that instrument on the bank's own site, whose search endpoints returned errors.

  • Whether the register of cloud and data centre providers that public bodies must buy from actually has entries

    The electronic communications regulator's register page was unreachable from our network. An empty register would make the public procurement route in the Cloud Services Act unusable in practice.

  • That there is no data localisation requirement in Ukrainian banking, payments, insurance, telecoms, education, gaming or e-commerce law

    We read the Payment Services Act and the Electronic Communications Act in full on 18 August 2026 and found none. We did not read the insurance, education or gaming statutes, and subordinate regulator acts were not exhaustively checked. Recorded as no rule found on 18 August 2026, not as an assertion that none exists.

  • Whether the Commissioner's inspections have produced fines against private companies, as opposed to orders against public bodies

    The published results are dominated by councils, administrative service centres and state enterprises. Court outcomes on the administrative offence reports are not published on the Commissioner's site, so the real rate of monetary penalties is unknown.

  • The exact commencement dates recorded for the amending laws — No. 1907-IX, No. 2075-IX, No. 2494-IX, No. 3585-IX and No. 4336-IX

    Each of these commences by formula rather than by a stated date: the day after publication, or six months after publication. We verified the formula in each Act's final provisions but could not open the gazette issue that fixes the publication day, so the dates in this record are calculated to within a few days. The adoption dates and the substance are verified.

60-day cadence. Martial law runs in 90-day cycles and the current one ends about 31 October 2026. At least three permissions in this record — state registers abroad, foreign clouds for the armed forces, and the telemedicine transfer exception — exist only while martial law lasts and expire six months after it is lifted, and in every case the default that returns is stricter. A longer cadence risks the site asserting a permission that has already lapsed.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.