Law of the Republic of Belarus On Personal Data Protection
Law No. 99-Z, Belarus's first comprehensive personal data statute, was adopted 7 May 2021 and took effect 15 November 2021 after a six-month compliance lead-in, administered by the National Center for Personal Data Protection. Consent is described as the default lawful basis, a more consent-centric framing than General Data Protection Regulation (GDPR)'s six coequal bases, though the full Article 8 lawful-basis list was not independently read beyond this commentary-level characterization.
Biometric data is explicitly classified as special personal data, with facial imagery named as a qualifying example, and processing without consent is generally prohibited subject to narrow public-interest exceptions. Data-subject rights run on notably fast statutory timelines relative to GDPR's one-month default, including 5 working days to respond to an access application and 15 days for correction, deletion, or restriction.
Cross-border transfer is the sharpest structural divergence found in this batch: Article 9 prohibits transfers to a country lacking an adequate level of protection unless a closed list of derogations applies or the National Center issues a case-by-case permit, with adequate countries limited to 1981 Council of Europe Convention parties and Eurasian Economic Union member states, and no Standard Contractual Clauses or Binding Corporate Rules self-assessment route available to an operator on its own initiative.
Breach notification runs to the National Center only, within three working days, with no confirmed duty to notify affected individuals directly. The law has no equivalent of GDPR Article 22's right against solely automated decisions. A pending amendment would add an AI-specific disclosure and human-review duty, but as of the most recent report it had not reached bill status and is not authored as a separate instrument here; it is noted as anticipated reform only.
What it asks of an app →