Law No. 455-Z, Information System Operator's Duty to Protect Information (Article 40)
Law of the Republic of Belarus No. 455-Z of 10 November 2008 On Information Informatization and Protection of Information (as amended to 2016), art. 40
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
A security baseline statutes rule binding public and private bodies.
As of 19 September 2026.
What it requires
- This binds you if you operate an information system or provide information services through one, reaching Belarus or established there, whatever your sector or size: Law No. 455-Z defines an information system operator broadly and lists a private legal entity or an individual entrepreneur among the subjects of information relations it reaches.
- Ensure the integrity and safety of the information your system holds.
- Take measures to prevent disclosure, loss, distortion, destruction, or unauthorized modification of that information, and to prevent blocking of legitimate access to it.
- Where necessary, take measures to restore information that has been lost.
- This duty runs independently of Belarus's comprehensive personal-data statute, Law No. 99-Z, which carries its own security and breach-notice duties recorded separately under the privacy topic; article 40 reaches whatever information your system holds, not only personal data.
If you get it wrong
Criminal exposureNo
Criminal exposure note
Article 41 of Law No. 455-Z makes a bare cross-reference to unspecified legislative acts of the Republic of Belarus for the liability that attaches to any violation of the Law, including article 40, and does not itself create a criminal offense. The Criminal Code's own computer-security chapter (articles 349 to 355) punishes a person who defeats a protection system or unlawfully accesses, copies, or sabotages computer information, an intruder-facing offense filed under the scraping topic rather than a criminal penalty for an operator's failure to satisfy article 40's own duty; no separate criminal offense for that failure is confirmed present in the sources reachable here.
Who enforces it
Enforcement body
No single enforcement body is named for a violation of article 40 within Law No. 455-Z's own text. Article 8 assigns overlapping public regulation and administration in the field of information, informatization, and protection of information to the President, the Council of Ministers, the National Academy of Sciences, the Operation and Analysis Center under the President, and the Ministry of Communications and Informatization, without naming which of them acts on an article 40 breach specifically.
Settledness
- As of
- 19 September 2026
- Open questions
- Does a Belarusian court or regulator read article 40's duty as binding immediately, or does it treat the duty as awaiting a further legislative act specifying the cases in which it applies, the way article 31's parallel duty in the same chapter is expressly qualified?
- Which legislative act does article 41 point to for the liability that attaches to a violation of article 40, and does that act set a specific penalty amount?
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 40 of Law No. 455-Z of 10 November 2008 On Information, Informatization and Protection of Information obliges an information system operator to ensure the integrity and safety of information contained in its information system.
The same article also requires the operator to take measures preventing the disclosure, loss, distortion, destruction, or unauthorized modification of that information and the blocking of legitimate access to it, and, where necessary, to take measures to restore lost information. Article 1 defines an information system operator as any subject of information relations that operates an information system or provides information services through it.
Article 5 lists legal entities and individual entrepreneurs among the subjects of information relations the Law reaches, so the duty binds a private-sector operator rather than only a state body. The duty carries no personal-data trigger, sector gate, or size threshold, and it applies to whatever information the operator's system contains.
That is a stricter reading than article 31's parallel information-holder duty in the same chapter, which the Law itself qualifies to apply only in cases established by the legislation of the Republic of Belarus, a qualifier article 40's own obligation does not carry.
Article 41 makes a bare cross-reference to unspecified legislative acts of the Republic of Belarus for the liability that attaches to a violation, without stating a penalty amount, an enforcement body, or a specific offense for this duty within the Law's own text.
Article 44 sets commencement at six months after official publication of the Law, and the exact calendar date is not confirmed from a primary source here; the Law's own amendment history, most recently in 2016, establishes that it is currently in force regardless of that unconfirmed date.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricspublishes_adult_contentoperates_social_platformserves_minorsoperates_app_storeships_mobile_appaggregates_contentdistributes_software_producthandles_health_recordsprovides_financial_servicesoperates_essential_serviceis_listed_companyprovides_telecom_services
Read the law
Law of the Republic of Belarus No. 455-Z of 10 November 2008 On Information
Informatization and Protection of Information, English translation via rti-rating.org, arts. 1, 5, 8, 30, 31, 40, 41, 44
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.