World Watch/Ukraine/Data & Privacy

Data & Privacy · Ukraine

Data protection & privacy laws in Ukraine (2026)

Comprehensive lawLaw of Ukraine No. 2297-VI "On Personal Data Protection" (adopted 1 June 2010, in force since 1 January 2011), supervised by the Ukrainian Parliament Commissioner for Human Rights (Ombudsman). A GDPR-aligned overhaul (Draft Law No. 8153) passed first reading on 20 Nov 2024 but is not yet enacted.Country index 74 · B+

Ukraine shaded by its data & privacy status

Ukraine has a comprehensive, cross-sectoral personal-data protection law in force — Law No. 2297-VI of 2010 — that applies to automated and structured manual processing, grounded in Council of Europe Convention 108. Oversight rests with the Parliament Commissioner for Human Rights (Ombudsman) rather than a dedicated independent regulator. A major GDPR/Convention 108+ alignment reform (Draft Law No. 8153) is pending in Parliament after a first reading in November 2024.

Key points

Comprehensive law in force

Law No. 2297-VI "On Personal Data Protection" (1 June 2010) is the general statute governing protection and processing of personal data, covering fully/partly automated processing and structured manual (card-index) data.

Supervisory authority

Since 1 January 2014 the Ukrainian Parliament Commissioner for Human Rights (Ombudsman) is the state authority controlling compliance with data-protection legislation; it is a parliamentary human-rights body, not a standalone independent DPA.

Data-subject rights

The law guarantees rights to restrict processing, withdraw consent, place limits when giving consent, know the logic of automated processing, and protection against legally significant automated decisions.

Sensitive data prohibition

Processing of data on racial/ethnic origin, political, religious or philosophical beliefs, party or trade-union membership, health or sex life is prohibited unless based on the data subject's unambiguous consent or other grounds explicitly set out in law.

Pending GDPR-aligned reform

Draft Law No. 8153, a new redaction harmonizing Ukrainian rules with the GDPR and Convention 108+, passed first reading on 20 Nov 2024 and was returned for refinement; it would add breach notification, DPIAs, mandatory DPOs and turnover-based fines, but is not yet enacted.

Proposed independent regulator

The reform package envisions a dedicated independent supervisory authority (a National Commission for the Protection of Personal Data and Access to Public Information) to replace the Ombudsman's current oversight role, in line with EU norms.

Ukraine - other topics

Last verified 5/25/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →