Law / Belarus

Belarus

10 of 14 named instruments researched to a stage, across four of the six areas of law we track: 10 in force. As of 19 September 2026.

When they take effect9 of 10 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 3 instruments (3 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 6 instruments (6 in force) 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (141 words)

Belarus is not a General Data Protection Regulation (GDPR) jurisdiction, and its comprehensive regime, Law No. 99-Z of 7 May 2021 On Personal Data Protection, in force since 15 November 2021, diverges from GDPR structurally rather than cosmetically. Cross-border transfer runs on a state-controlled adequate-country-list-plus-permit gatekeeper model with no Standard Contractual Clauses or Binding Corporate Rules self-assessment route, a stricter regime than every other jurisdiction corrected.

The law has no equivalent of GDPR Article 22's right against solely automated decisions, and the National Center for Personal Data Protection can directly order an operator to change, block, or delete data rather than only refer to a separate penalty process. A pending amendment would add AI-specific disclosure and human-review duties, but as of the most recent report it had not even reached bill status, so it is recorded here only as anticipated reform, not as an instrument.

Breach notification

Law of the Republic of Belarus On Personal Data Protection, notification of personal data protection violations

Law No. 99-Z, art. 16.1 (notification of personal data protection violations)National Center for Personal Data Protection's own English pages (cpd.by), read in full (71,842 characters)

In force since 15 November 2021. Binds public and private bodies.

What this law does

Article 16 requires the operator to notify the authorized agency for the protection of personal data subjects' rights of a violation of personal data protection systems immediately, and no later than three working days after the operator became aware of it, except as the agency itself otherwise provides. This Law states no separate duty to notify an affected personal data subject of the violation, and no content requirements for the notification to the agency beyond the deadline itself.

What it requires

Comprehensive regime

Law of the Republic of Belarus On Personal Data Protection

Zakon Respubliki Belarus No. 99-Z ot 7 maia 2021 g. O zashchite personalnykh dannykh v sile s 15 noiabria 2021 (Law No. 99-Z of 7 May 2021), arts. 1-7, 17 and 20-21 (general processing and security)National Center for Personal Data Protection's own English pages (cpd.by), read in full (71,842 characters)

In force since 15 November 2021. Binds public and private bodies.

What this law does

Article 2 applies this Law to personal data processed using automation tools, or without automation tools where the data can be searched or accessed by specific criteria, and Article 2 excludes an individual's purely personal, family or household activity and data classified as a state secret.

Article 4 requires processing to be proportionate to its stated purposes, based on the personal data subject's consent except where this Law provides otherwise, limited to explicit, pre declared legitimate purposes, transparent, and no more than necessary, and requires the operator to keep the data accurate and to store it only as long as the stated purposes require.

Article 5 defines that consent as a freely given, unambiguous, informed expression of will, obtainable in writing, as an electronic document, or in another electronic form, with the burden of proving it on the operator.

Article 7 lets an operator entrust processing to an authorized person only under a contract, an act of legislation or a public authority decision that fixes the purposes, the permitted actions, a confidentiality duty and the Article 17 protection measures, and makes the operator responsible to the personal data subject for that person's actions.

Article 17 requires the operator to take legal, organizational and technical measures against unauthorized or accidental access, modification, termination, copying, dissemination, transmission or erasure of personal data, including appointing a data protection officer or a dedicated unit, publishing a data processing policy, training staff, and implementing technical and cryptographic protection, and a republican public authority operator must publicize on its website the information resources containing personal data it owns.

What it requires

Cross border transfer

Law of the Republic of Belarus On Personal Data Protection, cross border transfer of personal data

Law No. 99-Z, art. 9 (cross border transfer of personal data)National Center for Personal Data Protection's own English pages (cpd.by), read in full (71,842 characters)

In force since 15 November 2021. Binds public and private bodies.

What this law does

Article 9 prohibits cross-border transfer of personal data where an adequate level of protection of personal data subjects' rights is not provided in the destination country, unless one of seven listed exceptions applies, including the personal data subject's informed consent to the risks, performance of a contract with the subject, a transfer the subject could obtain by request under legislation, protecting vital interests where consent cannot be obtained, execution of a Belarusian treaty, financial monitoring against money laundering or terrorist financing, or a permit from the authorized agency.

Article 9 also gives the authorized agency for the protection of personal data subjects' rights the power to determine the list of foreign countries whose territory ensures an appropriate level of protection, so an operator transferring to a country outside that list needs one of the other Article 9 exceptions or the agency's own permit.

What it requires

Data subject rights

Law of the Republic of Belarus On Personal Data Protection, rights of the personal data subject

Law No. 99-Z, arts. 10-14 (rights of the personal data subject)National Center for Personal Data Protection's own English pages (cpd.by), read in full (71,842 characters)

In force since 15 November 2021. Binds public and private bodies.

What this law does

Article 10 lets a personal data subject withdraw consent at any time without giving reasons, and requires the operator, within fifteen days and absent another legal basis, to stop processing, erase the data and notify the subject, or where erasure is not technically possible to restrict further processing and notify the subject instead.

Article 11 gives a personal data subject the right to receive information on the processing of his or her personal data, including the operator's identity, confirmation of processing, the data and its source, and the legal basis and purposes, which the operator must provide within five working days or explain why it is refused, and gives the right to require rectification of personal data that are incomplete, outdated or inaccurate.

Article 12 gives a personal data subject the right to receive, once a calendar year and free of charge, information from the operator about the transmission of his or her personal data to third parties. Article 13 gives a personal data subject the right to demand the free termination of processing, including erasure, absent a legal basis for it, which the operator must carry out within fifteen days, or, where erasure is not technically possible, restrict further processing instead.

Article 14 requires a personal data subject exercising the Articles 10 to 13 rights to submit a written or electronic application to the operator, and requires the operator's response to match the form of that application unless the subject asks otherwise.

What it requires

Enforcement supervision

Law of the Republic of Belarus On Personal Data Protection, authorized agency and liability

Law No. 99-Z, arts. 15, 18-19 (authorized agency and liability)National Center for Personal Data Protection's own English pages (cpd.by), read in full (71,842 characters)

In force since 15 November 2021. Binds public and private bodies.

What this law does

Article 15 lets a personal data subject appeal an operator's actions, inaction or decisions that violate their rights to the authorized agency in the manner legislation on citizens' and legal persons' appeals prescribes, and lets the agency's decision be further appealed to a court. Article 16 requires an operator to fulfill the agency's other requirements to eliminate data protection legislation violations.

Article 18 sets up the authorized agency, gives it control over operators' processing, complaint handling, and the power to require an operator to rectify, restrict or erase false or illegally obtained personal data and eliminate other violations of this Law, and requires it to publish an annual activity report by 15 March.

Article 19 makes a person guilty of violating this Law liable under other legislative acts, and entitles a personal data subject to compensation for moral damage caused by a violation of their rights under this Law, independent of any compensation for property damage.

What it requires

Sensitive categories

Law of the Republic of Belarus On Personal Data Protection, special personal data

Law No. 99-Z, arts. 1, 8 (special personal data)National Center for Personal Data Protection's own English pages (cpd.by), read in full (71,842 characters)

In force since 15 November 2021. Binds public and private bodies.

What this law does

Article 1 defines special personal data as personal data related to race or nationality, political opinions, trade union membership, religious or other beliefs, sex life or health, administrative or criminal records, and biometric and genetic personal data, with biometric personal data itself defined as information characterizing the physiological and biological particularities of an individual used for unique identification, naming fingerprints, palmprints, iris, and face features and their image as examples.

This definition is not confined to a directly captured biometric template, and reaches an image from which those features can be read.

Article 8 prohibits processing special personal data without the personal data subject's consent, except in the listed cases, including where the personal data subject has made the special personal data publicly disclosed himself, for labor relations, for medical care by a professional bound to patient confidentiality, for the administration of justice, or for national security, anti corruption or anti money laundering purposes, and permits processing in those cases only where a set of measures against the risks it poses to personal data subjects' rights and freedoms has been adopted.

What it requires

Scraping law2 instruments, 2 in force

Research summary (311 words)

Belarus has no scraping-specific statute, so general law governs each dimension separately.

The Criminal Code's computer-security chapter (arts. 349, 350, 352, 354, and 355) requires either a breach of a protection system, a corrupt purpose, or negligent substantial harm before unauthorized access to computer information is an offence, so reading a public, unauthenticated page without defeating any access control or security measure does not fit a plain reading of these articles, and no reported case has tested the point.

No reported Belarusian decision addresses whether a browsewrap or clickwrap terms-of-service is enforceable against a scraper, or whether logging in or accepting terms changes the answer.

The Law on Copyright and Related Rights (Law No. 262-Z) protects a database as a compilation only, with no protection extending to the underlying data, and carries no sui generis database right; its free-use chapter permits quotation, educational use, and reproduction of press articles on current affairs, but has no text-and-data-mining exception or opt-out mechanism, so training a model on scraped copyrighted text ordinarily requires the rightsholder's authorization unless one of those free-use grounds applies.

The Law on Personal Data Protection (Law No. 99-Z) grants only a narrow self-disclosure exception rather than a general carve-out for publicly accessible data, so scraping personal data of a person in Belarus remains subject to that Law's lawful-basis, security, and cross-border-transfer duties even where the data came from a public source.

No statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule; the general Information Law (Law No. 455-Z) recognizes a category of publicly accessible information whose dissemination may not be restricted and lets an information holder require attribution when its disclosed public information is redisseminated by others, but this is a general information-law norm rather than a rule targeting crawling or AI training.

Computer misuse

Criminal Code, Crimes Against Computer Security

Criminal Code No. 275-Z of 9 July 1999, arts. 349, 350, 352, 354 and 355 (as amended to 2023)Criminal Code No. 275-Z of 9 July 1999, consolidated text, National Legal Internet Portal of the Republic of Belarus (ETALON-ONLINE)

In force since 1 January 2001. Binds public and private bodies.

What this law does

Article 349(1) punishes unauthorized access to computer information accompanied by a breach of a protection system, committed for gain or negligently causing substantial harm, with a fine, disqualification from certain positions or activity, arrest, restriction of freedom for up to two years, or deprivation of freedom for the same term; article 349(2) raises the penalty to restriction of freedom for up to five years or deprivation of freedom for up to seven years where the same conduct negligently causes a crash, accident, casualties, or other grave consequences.

Article 352(1) separately punishes intentional unauthorized copying, interception, or other unlawful acquisition of computer information causing substantial harm, without requiring a breach of a protection system, at up to three years' restriction of freedom or two years' deprivation of freedom.

Article 354 punishes developing, using, distributing, or selling a computer program or device known to be intended for defeating a protection system or for unauthorized access, destruction, blocking, or modification of computer information, and article 355 punishes a person with lawful access who negligently breaches computer-system operating rules and thereby causes substantial harm.

Because articles 349(1) and 352(1) require a breach of a protection system, a corrupt purpose, or a resulting harm, reading a public, unauthenticated page without defeating any access control falls outside a plain reading of these provisions.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (523 words)

Belarus has one enacted, in-force instrument that imposes a security-posture duty on a private-sector information system operator, distinct from a personal-data trigger and from an intruder-facing computer-misuse offense: article 40 of Law No. 455-Z of 10 November 2008 On Information, Informatization and Protection of Information.

The article obliges an information system operator, defined broadly enough to include a private legal entity or an individual entrepreneur, to ensure the integrity and safety of the information its system holds and to take measures against disclosure, loss, distortion, destruction, unauthorized modification, and illegitimate blocking of access to that information.

No product-placement or connected-device security regime comparable to the Cyber Resilience Act or the United Kingdom's product-security regime is confirmed present in Belarus: no statute sets security requirements a software product or connected device must meet before or after it reaches the market, and no update, support-period, or vulnerability-disclosure duty binds a manufacturer as such.

No vulnerability or incident-reporting regime running to a computer emergency response team or a sector authority is confirmed either. The only reporting clock this corpus holds for Belarus is the personal-data breach notice to the National Center for Personal Data Protection within three working days, which belongs to Law No. 99-Z's own record under the privacy topic and is not restated here as a security duty.

No sector-specific cyber-resilience regime naming a digital service, a financial entity, or a telecommunications operator is confirmed present in Belarus. A Presidential decree or a National Bank directive addressing information security specifically, separate from Decree No. 8's digital-economy and High Technologies Park regime, is neither confirmed to exist nor confirmed absent from the sources reachable here, and stays an open question for the corpus rather than a recorded absence.

Law No. 455-Z's own chapter on public administration assigns rulemaking competence over informatization to the Ministry of Communications and Informatization and competence over technical and cryptographic protection of information to the Operation and Analysis Center under the President, and either body's subordinate regulatory acts could plausibly narrow or extend article 40's baseline duty; neither is authored as an instrument here, because neither body's own regulatory text is confirmed available.

Belarus's Criminal Code (Law No. 275-Z), articles 349, 350, 352, 354, and 355, is already filed in this corpus under the scraping topic's computer_misuse family. Those articles punish a person who defeats a protection system, unlawfully acquires computer information, distributes a circumvention tool, or negligently breaches operating rules while holding lawful access, all offenses against the system rather than a duty on its operator, so no row is added here on top of that filing.

Law No. 99-Z On Personal Data Protection carries its own security, breach-notice, and governance duties for personal data specifically, already filed under the privacy topic as the comprehensive regime Belarus's data-protection law is. Article 40 of Law No. 455-Z binds an information system operator regardless of whether the information the system holds is personal data, so the two duties reach different triggers and neither restates the other.

Decree No. 8 On Development of the Digital Economy and the Law On Investments remain filed as compute and investment-incentive instruments and are not restated here.

Security baseline statutes

Law No. 455-Z, Information System Operator's Duty to Protect Information (Article 40)

Law of the Republic of Belarus No. 455-Z of 10 November 2008 On Information Informatization and Protection of Information (as amended to 2016), art. 40Law of the Republic of Belarus No. 455-Z of 10 November 2008 On Information

In force. Binds public and private bodies.

What this law does

Article 40 of Law No. 455-Z of 10 November 2008 On Information, Informatization and Protection of Information obliges an information system operator to ensure the integrity and safety of information contained in its information system.

The same article also requires the operator to take measures preventing the disclosure, loss, distortion, destruction, or unauthorized modification of that information and the blocking of legitimate access to it, and, where necessary, to take measures to restore lost information. Article 1 defines an information system operator as any subject of information relations that operates an information system or provides information services through it.

Article 5 lists legal entities and individual entrepreneurs among the subjects of information relations the Law reaches, so the duty binds a private-sector operator rather than only a state body. The duty carries no personal-data trigger, sector gate, or size threshold, and it applies to whatever information the operator's system contains.

That is a stricter reading than article 31's parallel information-holder duty in the same chapter, which the Law itself qualifies to apply only in cases established by the legislation of the Republic of Belarus, a qualifier article 40's own obligation does not carry.

Article 41 makes a bare cross-reference to unspecified legislative acts of the Republic of Belarus for the liability that attaches to a violation, without stating a penalty amount, an enforcement body, or a specific offense for this duty within the Law's own text.

Article 44 sets commencement at six months after official publication of the Law, and the exact calendar date is not confirmed from a primary source here; the Law's own amendment history, most recently in 2016, establishes that it is currently in force regardless of that unconfirmed date.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (240 words)

Belarus has no press-publisher neighbouring right, no compelled platform-to-publisher bargaining code, and no reported hot-news or misappropriation doctrine distinct from ordinary copyright law.

The Law on Copyright and Related Rights (Law No. 262-Z) is the only law reaching an aggregator's reproduction of news content: its quotation provision permits reproducing excerpts of a lawfully published work, in the original or in translation, for research, educational, polemical, critical, or informational purposes, to the extent the purpose justifies, and a separate free-use provision lets a lawfully published newspaper or magazine article on current economic, political, social, or religious affairs, including one lawfully placed for public information on the internet, be reproduced by another print or electronic outlet unless the author or rightsholder has specially prohibited it.

Neither provision carries a headline-length or short-extract cap distinct from its own purpose-justified or reservation test, and no reported Belarusian decision applies either to a systematic online news aggregator rather than an individual quoting or reprinting a published work.

The general Information Law (Law No. 455-Z) separately lets a holder of publicly accessible information require attribution as its source when the information is redisseminated by others, a general information-law norm rather than a press-publisher right.

No statute or case law addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and the Copyright Law predates any machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.