Law / Ukraine

Ukraine

privacy

Ukraine is not a General Data Protection Regulation (GDPR) jurisdiction. Its governing act, Law No. 2297-VI On the Protection of Personal Data, was adopted 1 June 2010 and took effect 1 January 2011, built on the older Council of Europe Convention 108 and EU Directive 95/46 model rather than GDPR.

Biometric and genetic data trigger a notification-to-the-Ombudsperson duty as one of several risky categories, but the law does not define biometric data anywhere, including in its own definitions provision, a genuinely thin, pre-GDPR treatment rather than an assimilated GDPR Article 9 answer.

A comprehensive GDPR-aligned replacement, Draft Law No. 8153, passed first reading on 20 November 2024 and remains pending second reading with no completion date reported as of the most recent source found (roughly May 2026), a status that may itself be stale by the time of this research.

9 instruments named 2 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Comprehensive regime

Draft Law No. 8153 on Personal Data Protection (GDPR-Aligned Reform)

cite Draft Law of Ukraine No. 8153, first reading passed 20 November 2024 stage Proposed source recordinglaw.com legal-reference page, read directly through crawler infrastructure (205,050 characters, not truncated)

Draft Law No. 8153, a comprehensive General Data Protection Regulation (GDPR)-aligned replacement for Law No. 2297-VI, passed its first reading in the Verkhovna Rada on 20 November 2024. A direct fetch confirms it is reported to add a mandatory breach notification obligation the current law lacks, a Data Protection Officer requirement triggered by processing biometric or genetic data among other thresholds, an Article 39 Data Protection Impact Assessment duty, and an Article 18 duty to disclose automated decision-making mechanisms.

As of the most recent source located, dated to roughly May 2026, it was reported pending second reading with no completion date given; no source postdating that was found confirming further progress, a stall, or withdrawal, so this status may itself be stale by the time of this research. It has not been enacted and is not currently binding.

What it asks of an app

Law of Ukraine On the Protection of Personal Data

cite Zakon Ukrainy Pro zakhyst personalnykh danykh No. 2297-VI, in force 1 January 2011 (Law of Ukraine No. 2297-VI) stage In effect since 2011-01-01 source recordinglaw.com legal-reference page, read directly through crawler infrastructure (205,050 characters, not truncated)

Law No. 2297-VI predates General Data Protection Regulation (GDPR) by six years and follows the older Council of Europe Convention 108 and EU Directive 95/46 model: the Ukrainian Parliament Commissioner for Human Rights (Ombudsperson) is the supervisory authority, rather than a dedicated data-protection agency, and biometric data is treated as one of several categories triggering a notification duty rather than a prohibited-unless-excepted special category.

A direct fetch of a legal-reference page confirms biometric and genetic data are listed among the categories requiring mandatory notification to the Ombudsperson before processing (Article 7), while the law's definitions provision (Article 2) does not itself define biometric data or distinguish voiceprints from faceprints, leaving no enumerated example to test for a recording-derived exclusion.

An attempt to read the consolidated statute directly at the official Rada site returned only a 33,942-character page shell with no article content, so this instrument's substantive findings rest on that direct fetch of a secondary legal-reference source rather than the primary statute text. Cross-border transfer is confirmed as a real, moderate regime: transfers proceed by default to Convention 108 signatories, EEA states, and the United States, with safeguards required elsewhere. A private right of action is confirmed, and breach notification's existence under the current law was not established.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.