Law / Belarus

Belarus

privacy

Belarus is not a General Data Protection Regulation (GDPR) jurisdiction, and its comprehensive regime, Law No. 99-Z of 7 May 2021 On Personal Data Protection, in force since 15 November 2021, diverges from GDPR structurally rather than cosmetically. Cross-border transfer runs on a state-controlled adequate-country-list-plus-permit gatekeeper model with no Standard Contractual Clauses or Binding Corporate Rules self-assessment route, a stricter regime than every other jurisdiction corrected in this research wave.

The law has no equivalent of GDPR Article 22's right against solely automated decisions, and the National Center for Personal Data Protection can directly order an operator to change, block, or delete data rather than only refer to a separate penalty process. A pending amendment would add AI-specific disclosure and human-review duties, but as of the most recent report it had not even reached bill status, so it is recorded here only as anticipated reform, not as an instrument.

8 instruments named 1 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Comprehensive regime

Law of the Republic of Belarus On Personal Data Protection

cite Zakon Respubliki Belarus No. 99-Z ot 7 maia 2021 g. O zashchite personalnykh dannykh, v sile s 15 noiabria 2021 (Law No. 99-Z of 7 May 2021) stage In effect since 2021-11-15 source National Center for Personal Data Protection's own English pages (cpd.by), read through crawler infrastructure (71,842 characters)

Law No. 99-Z, Belarus's first comprehensive personal data statute, was adopted 7 May 2021 and took effect 15 November 2021 after a six-month compliance lead-in, administered by the National Center for Personal Data Protection. Consent is described as the default lawful basis, a more consent-centric framing than General Data Protection Regulation (GDPR)'s six coequal bases, though the full Article 8 lawful-basis list was not independently read beyond this commentary-level characterization.

Biometric data is explicitly classified as special personal data, with facial imagery named as a qualifying example, and processing without consent is generally prohibited subject to narrow public-interest exceptions. Data-subject rights run on notably fast statutory timelines relative to GDPR's one-month default, including 5 working days to respond to an access application and 15 days for correction, deletion, or restriction.

Cross-border transfer is the sharpest structural divergence found in this batch: Article 9 prohibits transfers to a country lacking an adequate level of protection unless a closed list of derogations applies or the National Center issues a case-by-case permit, with adequate countries limited to 1981 Council of Europe Convention parties and Eurasian Economic Union member states, and no Standard Contractual Clauses or Binding Corporate Rules self-assessment route available to an operator on its own initiative.

Breach notification runs to the National Center only, within three working days, with no confirmed duty to notify affected individuals directly. The law has no equivalent of GDPR Article 22's right against solely automated decisions. A pending amendment would add an AI-specific disclosure and human-review duty, but as of the most recent report it had not reached bill status and is not authored as a separate instrument here; it is noted as anticipated reform only.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.