Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Comprehensive regime
cite Draft Law of Ukraine No. 8153, first reading passed 20 November 2024
stage Proposed
source recordinglaw.com legal-reference page, read directly through crawler infrastructure (205,050 characters, not truncated)
Draft Law No. 8153, a comprehensive General Data Protection Regulation (GDPR)-aligned replacement for Law No. 2297-VI, passed its first reading in the Verkhovna Rada on 20 November 2024. A direct fetch confirms it is reported to add a mandatory breach notification obligation the current law lacks, a Data Protection Officer requirement triggered by processing biometric or genetic data among other thresholds, an Article 39 Data Protection Impact Assessment duty, and an Article 18 duty to disclose automated decision-making mechanisms.
As of the most recent source located, dated to roughly May 2026, it was reported pending second reading with no completion date given; no source postdating that was found confirming further progress, a stall, or withdrawal, so this status may itself be stale by the time of this research. It has not been enacted and is not currently binding.
What it asks of an app →
cite Zakon Ukrainy Pro zakhyst personalnykh danykh No. 2297-VI, in force 1 January 2011 (Law of Ukraine No. 2297-VI)
stage In effect
since 2011-01-01
source recordinglaw.com legal-reference page, read directly through crawler infrastructure (205,050 characters, not truncated)
Law No. 2297-VI predates General Data Protection Regulation (GDPR) by six years and follows the older Council of Europe Convention 108 and EU Directive 95/46 model: the Ukrainian Parliament Commissioner for Human Rights (Ombudsperson) is the supervisory authority, rather than a dedicated data-protection agency, and biometric data is treated as one of several categories triggering a notification duty rather than a prohibited-unless-excepted special category.
A direct fetch of a legal-reference page confirms biometric and genetic data are listed among the categories requiring mandatory notification to the Ombudsperson before processing (Article 7), while the law's definitions provision (Article 2) does not itself define biometric data or distinguish voiceprints from faceprints, leaving no enumerated example to test for a recording-derived exclusion.
An attempt to read the consolidated statute directly at the official Rada site returned only a 33,942-character page shell with no article content, so this instrument's substantive findings rest on that direct fetch of a secondary legal-reference source rather than the primary statute text. Cross-border transfer is confirmed as a real, moderate regime: transfers proceed by default to Convention 108 signatories, EEA states, and the United States, with safeguards required elsewhere. A private right of action is confirmed, and breach notification's existence under the current law was not established.
What it asks of an app →