Law note · Belarus

Law of the Republic of Belarus On Personal Data Protection

cite Zakon Respubliki Belarus No. 99-Z ot 7 maia 2021 g. O zashchite personalnykh dannykh, v sile s 15 noiabria 2021 (Law No. 99-Z of 7 May 2021) stage In effect since 2021-11-15 reviewed 2026-08-24

Law No. 99-Z, Belarus's first comprehensive personal data statute, was adopted 7 May 2021 and took effect 15 November 2021 after a six-month compliance lead-in, administered by the National Center for Personal Data Protection. Consent is described as the default lawful basis, a more consent-centric framing than General Data Protection Regulation (GDPR)'s six coequal bases, though the full Article 8 lawful-basis list was not independently read beyond this commentary-level characterization.

Biometric data is explicitly classified as special personal data, with facial imagery named as a qualifying example, and processing without consent is generally prohibited subject to narrow public-interest exceptions. Data-subject rights run on notably fast statutory timelines relative to GDPR's one-month default, including 5 working days to respond to an access application and 15 days for correction, deletion, or restriction.

Cross-border transfer is the sharpest structural divergence found in this batch: Article 9 prohibits transfers to a country lacking an adequate level of protection unless a closed list of derogations applies or the National Center issues a case-by-case permit, with adequate countries limited to 1981 Council of Europe Convention parties and Eurasian Economic Union member states, and no Standard Contractual Clauses or Binding Corporate Rules self-assessment route available to an operator on its own initiative.

Breach notification runs to the National Center only, within three working days, with no confirmed duty to notify affected individuals directly. The law has no equivalent of GDPR Article 22's right against solely automated decisions. A pending amendment would add an AI-specific disclosure and human-review duty, but as of the most recent report it had not reached bill status and is not authored as a separate instrument here; it is noted as anticipated reform only.

What it asks of an app

  • Establish a lawful basis, generally consent unless another basis applies, before processing personal data of a person in Belarus.
  • Obtain consent before processing biometric data of a person in Belarus as special personal data under Article 8.1, except for narrow public-interest exceptions.
  • Confirm the destination is on the National Center for Personal Data Protection's adequate-country list, or obtain a case-by-case National Center permit, before transferring personal data of a person in Belarus outside the country; this law has no Standard Contractual Clauses or Binding Corporate Rules self-assessment route.
  • Notify the National Center for Personal Data Protection immediately, and no later than three working days after becoming aware, of a personal data protection violation, under Article 16.1; the law does not require separate notification to affected individuals.
  • Expect a person in Belarus to have a civil claim for moral damage under Article 19.2 for a breach of their rights under this law, separate from the National Center's administrative process.

When LexLint raises it

Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, processes_voice, processes_biometrics

Primary source: National Center for Personal Data Protection's own English pages (cpd.by), read through crawler infrastructure (71,842 characters)
corroborated by e-sud.by practitioner guide

← Back to the example  ·  Lint your app →