Draft Law No. 8153, National Commission and penalties
Draft Law No. 8153, National Commission on Personal Data Protection and penalty structure
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Proposed: draft date not recorded.
An enforcement supervision rule binding public and private bodies.
As of 19 September 2026.
What it requires
- This draft has passed only a first reading and is not yet law; no enforcement duty currently attaches to it, and the following describe the regime the draft would create once enacted.
- Once enacted, expect the National Commission on Personal Data Protection and Access to Public Information, a new independent body, to replace the Ombudsperson as the authority that enforces personal data protection in Ukraine.
- Once enacted, expect an administrative fine of up to UAH 20 million for an individual, or up to the higher of UAH 150 million or 8 percent of the prior year's annual turnover for a legal entity in the most serious cases, doubling to 200 percent of the initial fine on a repeat violation within one year.
If you get it wrong
Penalty structure
Draft Law No. 8153 proposes a tiered fine scheme rather than one ceiling: an individual faces a fine from UAH 10,000 to UAH 20 million; a legal entity at the lower tier faces UAH 30,000 or 0.05 percent to 5 percent of annual turnover, not less than UAH 300,000; and a legal entity at the upper tier, for the most serious violations, faces up to UAH 150 million or 8 percent of the prior year's annual turnover, whichever is higher, the ceiling recorded here. A repeat violation within one year adds a penalty of 200 percent of the initial fine. This is proposed legislation that has passed only a first reading and is not yet enacted.
- Rule
- Higher of
- As of
- 19 September 2026
- Currency
- UAH
- Fixed cap
- 150,000,000
- Turnover percentage cap
- 8
Who enforces it
Enforcement body
National Commission on Personal Data Protection and Access to Public Information, a new independent body Draft Law No. 8153 would establish in place of the Ombudsperson; not yet established, since the draft has not been enacted.
What it reaches
Obligation class
Governance, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Draft Law No. 8153 would replace the Ombudsperson with the National Commission on Personal Data Protection and Access to Public Information, a new independent body responsible for both policymaking and enforcement, with quasi-investigative powers including the ability to engage technology and other subject-matter experts; a companion draft law, No. 6177, sets out the Commission's institutional structure, and the source expects the Commission to focus on institutional formation, without imposing penalties, during its first year.
The draft's penalty scheme is far higher than the current law's: an individual faces a fine from UAH 10,000 to UAH 20 million, a legal entity at the lower tier faces UAH 30,000 or 0.05 percent to 5 percent of annual turnover but not less than UAH 300,000, and a legal entity at the upper tier, for the most serious violations, faces up to UAH 150 million or 8 percent of the prior year's annual turnover, whichever is higher, doubling to 200 percent of the initial fine on a repeat violation within one year.
The current law's Ombudsperson, its narrower administrative fines, and the Criminal Code's separate offence are recorded on the sibling instrument ua-zakon-ukrainy-pro-zakhyst-personalnykh-danykh in this file. None of this binds today: the draft has passed only a first reading and remained in second reading preparation as of the most recent source located, dated May 2026.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbothigh_risk_decisionsis_listed_company
Read the law
recordinglaw.com
"Ukraine Data Privacy Laws: Personal Data Protection, Draft Law 8153, and the GDPR Reform," read in full (41,934 characters, not truncated)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.