Law / Ukraine

Ukraine

13 of 17 named instruments researched to a stage, across five of the six areas of law we track: 8 in force and 5 proposed. As of 19 September 2026.

When they take effect8 of 13 carry a date, 5 do not. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 2 instruments (2 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 1 instrument (1 in force) 2023: 3 instruments (3 in force) 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 1 in force, 5 proposed

Research summary (131 words)

Ukraine is not a General Data Protection Regulation (GDPR) jurisdiction. Its governing act, Law No. 2297-VI On the Protection of Personal Data, was adopted 1 June 2010 and took effect 1 January 2011, built on the older Council of Europe Convention 108 and EU Directive 95/46 model rather than GDPR.

Biometric and genetic data trigger a notification-to-the-Ombudsperson duty as one of several risky categories, but the law does not define biometric data anywhere, including in its own definitions provision, a genuinely thin, pre-GDPR treatment rather than an assimilated GDPR Article 9 answer.

A comprehensive GDPR-aligned replacement, Draft Law No. 8153, passed first reading on 20 November 2024 and remains pending second reading with no completion date reported as of the most recent source found (roughly May 2026), a status that may itself now be stale.

Breach notification

Draft Law No. 8153, personal data breach notification

Draft Law No. 8153, 72 hour breach notification to the National Commissionrecordinglaw.com

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Draft Law No. 8153 would introduce a mandatory personal data breach notification duty the current 2010 law does not state at all. A controller would notify the new supervisory authority within 72 hours of becoming aware of a breach affecting personal data security, and the notification would cover the nature of the breach, the number of affected individuals, the data types involved, the likely consequences, and the remedial measures taken.

The source describes this as a significant change from the current law, which it says contains no mandatory breach notification obligation. None of this binds today: the draft has passed only a first reading and remained in second reading preparation as of the most recent source located, dated May 2026.

What it requires

Comprehensive regime

Draft Law No. 8153 on Personal Data Protection (GDPR-Aligned Reform)

Draft Law of Ukraine No. 8153 first reading passed 20 November 2024 (processing principles, legal bases, data protection by design, DPO, art. 39 DPIA)recordinglaw.com

Proposed: draft date not recorded. In committee, dated 19 December 2025, as of 12 September 2026. Binds public and private bodies.

What this law does

Draft Law No. 8153 was registered in the Verkhovna Rada on 25 October 2022, developed with expert support from the Council of Europe and the EU4DigitalUA program, and passed its first reading on 20 November 2024. It remained in second reading preparation as of the most recent source located, dated May 2026, and has not been enacted.

If enacted, it would apply the General Data Protection Regulation (GDPR) aligned processing principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability, and it would add legitimate interests to the current law's consent and contract legal bases, aligning Ukraine with GDPR Article 6.

It would require data protection by design and by default so that only necessary personal data is processed by default, require a data protection officer where an organization regularly and systematically monitors data subjects at large scale or processes large volumes of sensitive data or biometric or genetic data, and require a data protection impact assessment under Article 39 for processing that involves systematic automated analysis or another high risk activity.

Its data subject rights, breach notification, cross border transfer, and enforcement provisions are recorded on the sibling instruments this draft is split into in this file.

What it requires

Law of Ukraine On the Protection of Personal Data

Zakon Ukrainy Pro zakhyst personalnykh danykh No. 2297-VI, in force 1 January 2011 (Law of Ukraine No. 2297-VI)recordinglaw.com legal-reference page, read in full (205,050 characters, not truncated)

In force since 1 January 2011. Binds public and private bodies.

What this law does

Law No. 2297-VI predates General Data Protection Regulation (GDPR) by six years and follows the older Council of Europe Convention 108 and EU Directive 95/46 model: the Ukrainian Parliament Commissioner for Human Rights (Ombudsperson) is the supervisory authority, rather than a dedicated data-protection agency, and biometric data is treated as one of several categories triggering a notification duty rather than a prohibited-unless-excepted special category.

A legal-reference page confirms biometric and genetic data are listed among the categories requiring mandatory notification to the Ombudsperson before processing (Article 7), while the law's definitions provision (Article 2) does not itself define biometric data or distinguish voiceprints from faceprints, leaving no enumerated example to test for a recording-derived exclusion.

This instrument's substantive findings rest on that secondary legal-reference source rather than the primary statute text. Cross-border transfer is confirmed as a real, moderate regime: transfers proceed by default to Convention 108 signatories, EEA states, and the United States, with safeguards required elsewhere. A private right of action is confirmed, and breach notification's existence under the current law was not established.

What it requires

Cross border transfer

Draft Law No. 8153, cross border transfer reform

Draft Law No. 8153, GDPR Chapter V style cross border transfer frameworkrecordinglaw.com

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Draft Law No. 8153 is expected to introduce a more detailed cross border transfer framework modeled on General Data Protection Regulation (GDPR) Chapter V, formalizing adequacy assessments, standard contractual clauses, binding corporate rules, and derogations for specific circumstances, in place of the current 2010 law's Convention 108 and adequacy by default treatment, recorded on the sibling instrument ua-zakon-ukrainy-pro-zakhyst-personalnykh-danykh in this file.

The source states this as the reform's expected direction rather than as first reading text already adopted, and gives no article number for it. None of this binds today: the draft has passed only a first reading and remained in second reading preparation as of the most recent source located, dated May 2026.

What it requires

Data subject rights

Draft Law No. 8153, automated decision making and data subject rights

Draft Law No. 8153, arts. 18, 25 (automated decision making disclosure and data subject rights: erasure, restriction, portability)recordinglaw.com

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Draft Law No. 8153 would add rights the current 2010 law does not carry in this form. Article 18 would require a controller to disclose its automated decision making mechanisms to a data subject, and Article 25 would prohibit a decision that significantly affects a data subject if that decision is based solely on automated processing, including profiling.

The draft would also add a right to erasure, a right to restriction of processing, and a right to data portability; the current law's own access, objection, rectification, and automated decision protections are recorded on the sibling instrument ua-zakon-ukrainy-pro-zakhyst-personalnykh-danykh in this file. None of this binds today: the draft has passed only a first reading and remained in second reading preparation as of the most recent source located, dated May 2026.

What it requires

Enforcement supervision

Draft Law No. 8153, National Commission and penalties

Draft Law No. 8153, National Commission on Personal Data Protection and penalty structurerecordinglaw.com

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Draft Law No. 8153 would replace the Ombudsperson with the National Commission on Personal Data Protection and Access to Public Information, a new independent body responsible for both policymaking and enforcement, with quasi-investigative powers including the ability to engage technology and other subject-matter experts; a companion draft law, No. 6177, sets out the Commission's institutional structure, and the source expects the Commission to focus on institutional formation, without imposing penalties, during its first year.

The draft's penalty scheme is far higher than the current law's: an individual faces a fine from UAH 10,000 to UAH 20 million, a legal entity at the lower tier faces UAH 30,000 or 0.05 percent to 5 percent of annual turnover but not less than UAH 300,000, and a legal entity at the upper tier, for the most serious violations, faces up to UAH 150 million or 8 percent of the prior year's annual turnover, whichever is higher, doubling to 200 percent of the initial fine on a repeat violation within one year.

The current law's Ombudsperson, its narrower administrative fines, and the Criminal Code's separate offence are recorded on the sibling instrument ua-zakon-ukrainy-pro-zakhyst-personalnykh-danykh in this file. None of this binds today: the draft has passed only a first reading and remained in second reading preparation as of the most recent source located, dated May 2026.

What it requires

Scraping law3 instruments, 3 in force

Research summary (314 words)

Ukraine has no scraping-specific statute, so general law governs each dimension separately.

The Criminal Code's article 361 criminalizes unauthorized interference in the operation of an information, electronic communications or telecommunications system; the offense turns on interference rather than on defeating a named access control, and no reported case establishes whether merely reading or downloading data from a public, unauthenticated page, without altering, blocking or disrupting the system's operation, meets that threshold.

Article 361-1 separately criminalizes creating, distributing or selling malicious software or technical means designed for such unauthorized interference. Articles 362 and 363 address a person who already has a right of access and a person responsible for operating the system respectively, so neither reaches an outside scraper. No Ukrainian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Law on Copyright and Related Rights (No. 2811-IX) confers a sui generis right on the maker of a database who has made a qualitatively or quantitatively significant investment in obtaining, verifying or presenting its contents, running for 15 years from completion (or first publication) of the database, but a database created to systematize information that is public information under the Law on Access to Public Information is carved out of that right; the Law contains no text-and-data-mining exception, so training on scraped copyrighted text rests only on the general free-use exceptions of article 22 where a use can be characterised as falling within them.

Ukraine's personal-data statute, Law No. 2297-VI (covered in this jurisdiction's privacy-topic finding), applies to personal data without a general exemption for information the data subject has made public, so scraping personal data from a public Ukrainian website remains subject to that Law's lawful-basis and other duties.

No Ukrainian statute or reported case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Criminal Code, Creation and Distribution of Malicious Software

Criminal Code of Ukraine, Law No. 2341-III, art. 361-1 (malicious software)Official consolidated text of the Criminal Code of Ukraine on the Verkhovna Rada legislative database (zakon.rada.gov.ua)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://zakon.rada.gov.ua/laws/show/2341-14

In force since 23 December 2004. Binds public and private bodies.

What this law does

Article 361-1 punishes creating malicious software or technical means for the purpose of unlawful use, distribution or sale, and their distribution or sale, where those tools are designed for unauthorized interference in the operation of an information, electronic communications or information-and-communications system or network of the kind article 361 punishes.

A repeat offense, one committed by prior conspiracy of a group, or one causing significant harm, carries a higher maximum term of imprisonment.

What it requires

Criminal Code, Unauthorized Interference with Information Systems

Criminal Code of Ukraine, Law No. 2341-III, art. 361 (unauthorized interference)Official consolidated text of the Criminal Code of Ukraine on the Verkhovna Rada legislative database (zakon.rada.gov.ua)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://zakon.rada.gov.ua/laws/show/2341-14

In force since 24 March 2022. Binds public and private bodies.

What this law does

Article 361 punishes unauthorized interference in the operation of an information (automated), electronic communications or information-and-communications system, or an electronic communications network, with escalating penalties where the act is repeated, committed by a prior conspiracy of a group, causes a leak, loss, forgery or blocking of information, distorts the processing of information or disrupts its routing, or causes significant harm or a danger of serious technological accident or environmental catastrophe.

Part 6 excludes from the offense conduct carried out in accordance with an established procedure for searching for and detecting the systems' or networks' potential vulnerabilities. This redaction of the article dates from Law No. 2149-IX (24 March 2022), which added the martial-law tier described above; the article has since been further amended by Law No. 3342-IX (23 August 2023).

What it requires

Database right

Copyright Law, Sui Generis Database Right

Law of Ukraine No. 2811-IX, art. 21 (database sui generis right)Official consolidated text of Law No. 2811-IX "On Copyright and Related Rights" on the Verkhovna Rada legislative database

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://zakon.rada.gov.ua/laws/show/2811-20

In force since 31 March 2023. Binds public and private bodies.

What this law does

Article 21 protects a database (a compilation of data) by copyright where its selection or arrangement of contents is the result of creative activity, but that protection does not extend to or prejudice rights in the database's individual contents or in a computer program used to create or needed to operate it.

Separately, article 21(4)-(8) confers a sui generis right on the maker of a database who has made a qualitatively or quantitatively significant investment in obtaining, verifying or presenting its contents, protecting against extraction and re-utilisation of the whole or a substantial part of the database, for 15 years from completion of the database's creation (or from first publication, if that occurs within the initial term), with a fresh 15-year term for a substantial new investment in the database's contents.

A database created to systematize information that is public information under the Law on Access to Public Information is carved out of the sui generis right.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (765 words)

Ukraine's private-sector cybersecurity posture rests on one currently enacted critical-infrastructure-owner duty, filed here in two provision-scoped rows, plus a second, broader physical-and-cyber resilience statute named but not filed, and an EU-accession NIS2-alignment reform track this review could not confirm has produced a text.

The Law "On the Basic Principles of Ensuring Cybersecurity of Ukraine" (Закон України "Про основні засади забезпечення кібербезпеки України"), Law No. 2163-VIII of 5 October 2017, took effect six months after its official publication under its own final provisions, commonly dated 9 May 2018, and remains in force.

Its Article 6(4) places responsibility for the cyber-defense of a critical infrastructure object's communication and technological systems, for the protection of technological information, for immediately informing Ukraine's governmental Computer Emergency Response Team (CERT-UA) of a cybersecurity incident, and for organizing an independent information-security audit of the object, on the owners and/or managers of the enterprise, institution or organization the object belongs to.

Article 6(1) defers the designation of a critical infrastructure object, and the Register of Critical Infrastructure Objects itself, to a separate statute, the Law "On Critical Infrastructure" (Закон України "Про критичну інфраструктуру"), Law No. 1882-IX of 16 November 2021, in force six months after its own publication under its own final provisions.

That Law's Article 9(4) sector list of protected "vital functions and services" names, among seventeen sectors, governance and essential public administrative services, energy, water, food, healthcare, the pharmaceutical industry, vaccine manufacturing, information services, electronic communications, financial services, transport, defense and state security, law enforcement, civil protection, space activity, the chemical industry, and research.

Law No. 1882-IX's own Article 21 separately binds a designated critical-infrastructure operator to a further duty, naming cybersecurity as one strand of an integrated physical-security, operational-systems-security and cybersecurity protection obligation, together with a general, not cyber-specific, duty to inform the national critical-infrastructure-protection system's sectoral and functional bodies of an incident at the object and to file an annual compliance report; because that duty is bundled into a single physical-and-cyber resilience mandate rather than separable into this topic's four registered law families, and because its own final and transitional provisions (paragraph 11) still task the future Authorized Body with drafting the administrative and criminal sanctions for a violation of it within one year of that body's start of operations, it is named here rather than filed as its own instrument, the treatment this jurisdiction's own companion German row gives the CER Directive's physical-resilience KRITIS-Dachgesetz.

Neither Law No. 2163-VIII's Article 6(4) nor Law No. 1882-IX's Article 21 currently carries its own fixed monetary or custodial penalty for a breach: Law No. 2163-VIII's Article 12 is a generic cross-reference to whatever civil, administrative or criminal liability already exists under other legislation for the underlying conduct, rather than a penalty of its own, and Law No. 1882-IX's final provisions confirm that a dedicated sanctions regime for its own operator duties had not yet been drafted as of the text reviewed here.

Because zakon.rada.gov.ua, the Verkhovna Rada's official consolidated-legislation database, and its data.rada.gov.ua open-data sibling both return a site-wide robots.txt disallow for every crawler, both instruments below are pinned to a fixed Internet Archive Wayback Machine snapshot of the official zakon.rada.gov.ua page, since the live host answers every crawler with the same disallow; the archived text is the government's own, unaltered, and the snapshot used for Law No. 2163-VIII records the text as current to 3 April 2025 (basis: Law № 4070-IX), while the document's own status card, read on a later, shell-only snapshot, names a further amendment, Law № 4336-IX, in force from 19 October 2025, not reflected in the text pinned here.

No product-security or market-placement duty on a software or connected-device manufacturer, independent of the critical-infrastructure-owner regime above, was located; nor was a general "reasonable security" or information-security-programme statute with no sector gate.

This review could not confirm whether Ukraine has introduced a dedicated NIS2-aligned reform bill comparable to the pending reforms this topic's Spain row documents; if one exists, it was not found in the sources this review could reach.

This jurisdiction's own privacy row, the Law "On the Protection of Personal Data" (Law No. 2297-VI, in force 1 January 2011), carries Ukraine's data-protection regime, including the cross-reference Law No. 2163-VIII's own Article 6(5) makes to it for a cybersecurity incident's personal-data component, and is researched there rather than restated here.

The Criminal Code's Article 361 (unauthorized interference with an information, electronic-communications or telecommunications system) and Article 361-1 (creating or distributing malicious software) are intruder-offense provisions that bind the person doing the interfering rather than the operator, and are researched on this jurisdiction's scraping-topic row rather than here.

Sector security regimes

Law on the Basic Principles of Ensuring Cybersecurity, Critical Infrastructure Owner Cyber-Defense and Audit Duty

Закон України "Про основні засади забезпечення кібербезпеки України" № 2163-VIII від 05.10.2017 (редакція від 03.04.2025, підстава -… 4070-IX), ст. 6(4)Internet Archive Wayback Machine snapshot (20250419072232) of the official consolidated text, zakon.rada.gov.ua, Law No. 2163-VIII

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived April 19, 2025. Publisher's page: https://zakon.rada.gov.ua/laws/show/2163-19

In force since 9 May 2018. Binds public and private bodies.

What this law does

Article 6(4) of Law No. 2163-VIII places responsibility for ensuring the cyber-defense of the communication and technological systems of a critical infrastructure object, and for protecting its technological information in accordance with legislative requirements, on the owners and/or managers of the enterprise, institution or organization that object belongs to.

The same sentence places responsibility for organizing an independent information-security audit of that object on the same owners and/or managers. Article 6(1) defers which enterprise, institution or organization counts as a critical infrastructure object, and the Register of Critical Infrastructure Objects that records that designation, to the separate Law No. 1882-IX "On Critical Infrastructure".

Article 6(2) and Article 5(3) split who sets the general cyber-defense requirements and the independent-audit rules an owner must follow: the Cabinet of Ministers of Ukraine for a critical infrastructure object generally, and the National Bank of Ukraine for a bank, another participant in the financial-services markets the National Bank regulates and supervises, a payment-system operator or participant, or a payment-services technology operator.

Article 12 does not set its own fine or custodial penalty for a breach of Article 6(4): it is a generic cross-reference stating that a person guilty of violating legislation in the fields of national security, electronic communications or information protection bears whatever civil, administrative or criminal liability the underlying conduct already carries under other law.

The Law took effect six months after its official publication, under its own final and transitional provisions, and remains in force.

What it requires

Vulnerability and incident reporting

Law on the Basic Principles of Ensuring Cybersecurity, CERT-UA Incident Notification Duty

Закон України "Про основні засади забезпечення кібербезпеки України" № 2163-VIII від 05.10.2017 (редакція від 03.04.2025, підстава -… 4070-IX), ст. 6(4)-(5), ст. 9(2)Internet Archive Wayback Machine snapshot (20250419072232) of the official consolidated text, zakon.rada.gov.ua, Law No. 2163-VIII

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived April 19, 2025. Publisher's page: https://zakon.rada.gov.ua/laws/show/2163-19

In force since 9 May 2018. Binds public and private bodies.

What this law does

The same Article 6(4) sentence that places the cyber-defense and audit duties on a critical infrastructure owner also places responsibility for immediately informing CERT-UA, Ukraine's governmental Computer Emergency Response Team, of a cybersecurity incident on the owners and/or managers of the enterprise, institution or organization the affected object belongs to.

Article 6(5) requires that an exchange of cybersecurity-incident information containing personal data comply with the Law on the Protection of Personal Data. Article 9(2) assigns operation of CERT-UA to the State Service of Special Communications and Information Protection of Ukraine.

Article 9(1) lists CERT-UA's own tasks, including maintaining the state register of cyber incidents and giving practical assistance to an owner of a cyber-defense object on preventing, detecting and remedying a cyber incident's consequences. The statute sets no fixed numeric notification clock: it requires the owner or manager to inform CERT-UA "невідкладно" (immediately, without delay), rather than within a stated number of hours.

Article 12 does not set its own fine or custodial penalty for a breach of this notification duty: it is the same generic cross-reference described on this jurisdiction's companion cyber-defense-and-audit row.

What it requires

Age gating law1 instrument, 1 in force

Research summary (106 words)

Ukraine's age-gating law sits in its general media statute rather than a dedicated age-verification act.

Law No. 2849-IX "On Media" (in force since 31 March 2023) requires a video-sharing platform provider to verify a user's age before granting access to content that may harm a child's physical, mental or moral development and to make a parental-control system available, and separately restricts audiovisual programming rated for an audience of at least 16 or 18 to fixed broadcast windows unless a conditional-access system is used instead.

Ukraine has no freestanding social-media minor-access statute, no app-store or device-level age-verification law, and no age-appropriate design code outside this media-sector scheme.

Age-appropriate design code

Law on Media, Video-Sharing Platform and Child-Protection Duties

Law of Ukraine No. 2849-IX "On Media", 13 December 2022, arts. 18, 23, 42Official consolidated text of Law No. 2849-IX "On Media" on the Verkhovna Rada legislative database (zakon.rada.gov.ua)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived January 24, 2023. Publisher's page: https://zakon.rada.gov.ua/laws/show/2849-20

In force since 31 March 2023. Binds public and private bodies.

What this law does

Article 18 defines a provider of a video-sharing platform as a person supplying a service, whether a website or another form, built on a publicly accessible information repository under the provider's control and client software giving access to it.

Article 23(1)(3) obliges that provider to verify a user's age before granting access to information that may harm a child's physical, mental or moral development, and to make available a parental-control system to protect children from such information. Article 42 separately restricts a linear or on-demand audiovisual program rated for an audience of at least 16 to the period between 22:00 and 06:00, and a program rated for an audience of at least 18 to the period between 24:00 and 05:00.

A provider may instead use a conditional-access system in place of those broadcast windows. Article 42 also lists the categories of content that trigger the child-protection restriction, including violence, self-harm, cruelty to animals, glorification of crime, promotion of substance abuse, profanity, gambling inducement and graphic depiction of the dead or dying.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (237 words)

Ukraine has no press-publisher neighbouring right transposing the kind the European Union's Digital Single Market Directive article 15 creates, and no mandatory platform-to-publisher bargaining code; the related-rights chapter of the Law on Copyright and Related Rights (No. 2811-IX) covers only performers, phonogram and videogram producers and broadcasting organisations, and no provision anywhere in that Law names a press publisher as a rightsholder.

The general copyright framework instead reaches an aggregator's reproduction through two free-use exceptions: article 22(2)(1) permits quotation, including from newspaper and journal articles in the form of press reviews, subject to a fair-practice-style test tied to the quoting work's critical, polemical, scholarly or informational character, and article 22(2)(5) separately permits reproducing and distributing in the press, or communicating to the public, a previously published newspaper or magazine article on a current economic, political, religious or social topic, unless the author has specifically prohibited that use.

No Ukrainian statute or reported case addresses whether a hyperlink is a communication to the public, or whether framing or inline display changes the answer, no hot-news or misappropriation doctrine distinct from this copyright framework has been located, and the Law carries no machine-readable text-and-data-mining reservation or opt-out mechanism.

None of the article 22 exceptions carries a headline-length or short-extract cap distinct from their own fair-practice or non-prohibition tests, and no reported Ukrainian decision applies article 22(2)(1) to a systematic news aggregator rather than an individual quoting a published work.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.