Law / Belarus

Law of the Republic of Belarus On Personal Data Protection, authorized agency and liability

Law No. 99-Z, arts. 15, 18-19 (authorized agency and liability)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 15 November 2021.

An enforcement supervision rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Expect a personal data subject in Belarus to be able to appeal your actions, inaction or decisions to the National Center for Personal Data Protection, and then to a court, under Article 15.
  • Comply with the National Center's requirement to rectify, restrict or erase false or illegally obtained personal data, or to eliminate another violation of this Law, under Article 16 and Article 18, paragraph 3.
  • Expect a person in Belarus to have a claim for moral damage under Article 19 for a breach of their rights under this law, separate from the National Center's own corrective process, and expect liability under other legislative acts for violating this Law.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Criminal Code No. 275-Z (9 July 1999, as amended by Law No. 112-Z of 26 May 2021) Art. 203-1 (“Illegal actions in relation to information on private life and personal data”): intentional illegal collection or provision of another person's private-life information and/or personal data without consent, causing substantial harm to a citizen's rights, freedoms or legitimate interests, is punishable by community service, a fine, arrest, restriction of freedom for up to two years, or deprivation of freedom for the same term (part 1); intentional illegal dissemination of the same, causing the same harm, by a fine, arrest, restriction of freedom for up to three years, or deprivation of freedom for the same term with or without a fine (part 2); either act committed against a person or their relatives because of that person's official activity or performance of a civic duty, by restriction of freedom for up to five years or deprivation of freedom for the same term with a fine (part 3, the article's maximum). A companion offence, Art. 203-2, punishes an operator's negligent failure to ensure personal-data protection measures where that failure causes the data's dissemination and grave consequences, by a fine, disqualification from holding certain positions or engaging in certain activity, corrective labor for up to one year, arrest, restriction of freedom for up to two years, or deprivation of freedom for up to one year.

Penalty structure

Law No. 99-Z itself states no fine amount; Article 19.1 refers liability to “legislative acts,” and the operative penalty clause is Code of Administrative Offences (Law No. 91-Z of 6 January 2021) Art. 23.7, which sets four separate tiers in base units (bazovaya velichina, BV): up to 50 BV for intentional illegal collection, processing, storage or provision of an individual's personal data or violation of their processing-related rights (part 1); 4 to 100 BV for the same acts by a person who knows the data through professional or official activity (part 2); up to 200 BV for intentional illegal dissemination of personal data (part 3, the article's ceiling); and, for failure to comply with data-protection security measures, 2 to 10 BV for an individual, 10 to 25 BV for a sole proprietor, and 20 to 50 BV for a legal entity (part 4). fixed_cap records only the part 3 ceiling (200 BV), converted at the base unit's current value of BYN 45 (Council of Ministers Resolution No. 651 of 20 November 2025, in effect from 1 January 2026); the lower tiers are not separately recorded on this instrument.

Rule
Fixed only
As of
2 September 2026
Currency
BYN
Fixed cap
9,000

Who enforces it

Enforcement body

The National Center for Personal Data Protection of the Republic of Belarus, the “authorized agency for the protection of personal data subjects’ rights” designated under Law No. 99-Z Art. 18 and established by Presidential Decree No. 422 of 28 October 2021. It supervises operators' processing, reviews data subjects' complaints and citizens'/legal entities' appeals, can order an operator to change, block or delete unlawfully obtained or inaccurate data, sets the list of countries with adequate protection and issues cross-border transfer permits, and must publish an annual activity report by 15 March each year (Art. 18.3). Administrative liability under Code of Administrative Offences Art. 23.7 and criminal liability under Criminal Code Art. 203-1/203-2 are adjudicated separately from the Center's own supervisory and corrective-order process; Art. 18.3 does not list a power to impose administrative fines itself.

Enforcement record

National Center for Personal Data Protection, own annual activity report for 2025 (published under the Art. 18.3 duty). actions_per_year counts the 556 formal requirements (prescriptions) the Center issued in 2025 ordering operators to remedy identified violations, up from approximately 370 in 2024, hence trend rising; the report frames this as its clearest count of operator-facing corrective actions actually issued. It does not count the 46 inspections conducted (an activity count, not all of which found a violation), the 580 data-subject complaints or 1,462 citizen/legal-entity appeals considered (intake counts that substantially overlap with the 556 figure, since complaint review is one of the two stated sources of the 556 orders), or private civil suits for moral damage under Art. 19.2, which the Center does not track. The report states no fines because the Center's own process results in corrective orders, not fines; fines_per_year, total_fines, median_fine and p90_fine are omitted rather than estimated.

As of
2 September 2026
Trend
Rising
Source link
https://cpd.by/o-centre/otchety-o-dejatelnosti/otchet-o-dejatelnosti-za-2025-god/
Actions per year
556

What it reaches

Obligation class

Reporting, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 15 lets a personal data subject appeal an operator's actions, inaction or decisions that violate their rights to the authorized agency in the manner legislation on citizens' and legal persons' appeals prescribes, and lets the agency's decision be further appealed to a court. Article 16 requires an operator to fulfill the agency's other requirements to eliminate data protection legislation violations.

Article 18 sets up the authorized agency, gives it control over operators' processing, complaint handling, and the power to require an operator to rectify, restrict or erase false or illegally obtained personal data and eliminate other violations of this Law, and requires it to publish an annual activity report by 15 March.

Article 19 makes a person guilty of violating this Law liable under other legislative acts, and entitles a personal data subject to compensation for moral damage caused by a violation of their rights under this Law, independent of any compensation for property damage.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • high_risk_decisions

Read the law

National Center for Personal Data Protection's own English pages (cpd.by), read in full (71,842 characters)
corroborated by e-sud.by practitioner guide

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app