Law / Ukraine

Law of Ukraine On the Protection of Personal Data

Zakon Ukrainy Pro zakhyst personalnykh danykh No. 2297-VI, in force 1 January 2011 (Law of Ukraine No. 2297-VI)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 January 2011.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Establish a lawful basis before processing personal data of a person in Ukraine under Law No. 2297-VI.
  • Notify the Ombudsperson before beginning to process biometric data, genetic data, health data, or another listed risky category of a person in Ukraine, under Article 7's notification-based mechanism; this law does not define biometric data anywhere, including in its Article 2 definitions.
  • Rely on the law's Convention 108, EEA, and United States adequacy-by-default treatment, or a documented safeguard, before transferring personal data of a person in Ukraine outside the country.
  • Expect a person in Ukraine to have both a complaint route to the Ombudsperson and a separate right to sue for compensation, including moral harm, for an infringement of this law.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Confirmed: Criminal Code of Ukraine (Kryminalnyi kodeks Ukrayiny, Law No. 2341-III of 5 April 2001) Art. 182, 'Порушення недоторканності приватного життя' (violation of the inviolability of private life), criminalizes illegal collection, storage, use, destruction, or dissemination of confidential information about a person, or its illegal alteration. Base offense (Part 1): a fine of 500-1,000 non-taxable minimum incomes of citizens (NMDG), or correctional labor for up to 2 years, or probation supervision for up to 3 years, or restriction of liberty for the same term. Aggravated offense (Part 2, a repeat offense or one causing substantial harm): probation supervision for 3-5 years, restriction of liberty for 3-5 years, or imprisonment for 3-5 years, the article's maximum penalty. A carve-out excludes public whistleblowing about a crime, made in compliance with legal requirements, from the offense. Current text confirmed at zakon.rada.gov.ua, last amended by Law No. 3342-IX of 23 August 2023, no later amendment found.

Who enforces it

Enforcement body

Ukrainian Parliament Commissioner for Human Rights (Ombudsperson) (Уповноважений Верховної Ради України з прав людини), per Law No. 2297-VI Art. 23, confirmed as of 2 September 2026 to still be the current and sole enforcement body; the GDPR-aligned Draft Law No. 8153 that would create a dedicated data-protection authority remains pending second reading and is not in force. The Ombudsperson's Art. 23(1) powers are complaint intake and case decisions, on-site and off-site inspections, and binding compliance orders (приписи), but NOT direct fining: under Art. 23(1)(10), authorized officials of the Ombudsperson's Secretariat draft an administrative-offense protocol under KUAP Art. 188-39 and refer it to a court, which alone adjudicates and imposes the fine. The Ombudsperson also reports annually to the Verkhovna Rada on the state of personal-data-protection compliance (Art. 23(2)).

What it reaches

Obligation class

Consent, Disclosure, Data subject rights, Transfer, Security, Governance, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Law No. 2297-VI predates General Data Protection Regulation (GDPR) by six years and follows the older Council of Europe Convention 108 and EU Directive 95/46 model: the Ukrainian Parliament Commissioner for Human Rights (Ombudsperson) is the supervisory authority, rather than a dedicated data-protection agency, and biometric data is treated as one of several categories triggering a notification duty rather than a prohibited-unless-excepted special category.

A legal-reference page confirms biometric and genetic data are listed among the categories requiring mandatory notification to the Ombudsperson before processing (Article 7), while the law's definitions provision (Article 2) does not itself define biometric data or distinguish voiceprints from faceprints, leaving no enumerated example to test for a recording-derived exclusion.

This instrument's substantive findings rest on that secondary legal-reference source rather than the primary statute text. Cross-border transfer is confirmed as a real, moderate regime: transfers proceed by default to Convention 108 signatories, EEA states, and the United States, with safeguards required elsewhere. A private right of action is confirmed, and breach notification's existence under the current law was not established.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • processes_voice
  • processes_biometrics

Read the law

recordinglaw.com legal-reference page, read in full (205,050 characters, not truncated)
the official Rada text at zakon.rada.gov.ua serves only a metadata shell

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app