Ukrainian Personal Data Protection Law in the Cloud: Fundamentals and Challenges
Digital transformation is an integral part of the development of Ukrainian business, and cloud technologies play a key role in this. However, with the expanding use of cloud services, especially for processing personal data, the responsibility for complying with national legislation also grows. The main regulatory acts in this area are the Law of Ukraine "On Personal Data Protection" and the Law of Ukraine "On Cloud Services".
The Law of Ukraine "On Personal Data Protection" establishes fundamental principles of data processing, including the need to obtain clear and informed consent from the data subject, limitations on the purpose of collection, requirements for data accuracy and relevance, and the data subject's right to access, correct, and delete their data. For cloud environments, this means the provider must ensure mechanisms that allow the data controller (business) to meet these requirements.
The Law of Ukraine "On Cloud Services", signed in March 2022 and effective from September of the same year, defines the legal relations in the field of cloud computing, particularly for the public sector. It directly obliges cloud service providers to comply with the requirements of legislation on personal data protection, information security, and cybersecurity. An important aspect is the prohibition of processing information that constitutes state secrets, official information, and data from state registries using cloud resources located outside Ukraine or in temporarily occupied territories, as well as those belonging to the aggressor state or its allies. Exceptions are provided only for the Ministry of Defense and the Armed Forces of Ukraine during martial law, allowing the processing of such information in clouds of NATO member countries.
Special attention should be paid to cross-border data transfers. Ukrainian legislation allows data transfer to foreign entities only if the respective state ensures an adequate level of personal data protection. Countries participating in the European Economic Area and states that have signed the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data are considered to provide an adequate level of protection. However, there is no official list of such countries in Ukraine, which creates some uncertainty. In case of data transfer to countries that do not provide adequate protection, unambiguous consent from the personal data subject is required.
Global Cloud Providers vs. National Requirements: Balancing Opportunities and Risks
Global public cloud providers offer Ukrainian businesses unprecedented flexibility, scalability, and cost-effectiveness. The ability to quickly deploy infrastructure, access advanced technologies, and reduce operational costs makes them an attractive choice for many companies. However, these advantages are often accompanied by the need for careful analysis of compliance with national legal norms, especially in the context of personal data processing.
The main tension arises from the location of global providers' data processing centers (DPCs), which are often located outside Ukraine. This directly affects data residency and cross-border transfer requirements. Although many providers adhere to international security standards such as GDPR, HIPAA, SOC 2, their jurisdiction may differ from Ukraine's, creating legal complexities.
For Ukrainian enterprises processing personal data, it is critically important to understand how the chosen global provider can ensure compliance with the requirements of the Law of Ukraine "On Personal Data Protection" regarding consent, data subject rights, and security measures. Additionally, potential risks associated with access by foreign law enforcement agencies to data stored on servers abroad, as well as the difficulty of obtaining real-time legal assistance in case of data leaks, must be considered.
Choosing hybrid cloud solutions or using local providers for sensitive data can be a compromise option, allowing the use of global services for less critical information while maintaining compliance with national requirements for personal data.
Course Towards Harmonization: The Role of the Ministry of Digital Transformation and GDPR Benchmarks
Ukraine is actively moving towards digital transformation, and the Ministry of Digital Transformation plays a key role in shaping regulatory policy in the field of cloud services. Recent legislative initiatives, particularly the draft law developed by the Cabinet of Ministers of Ukraine on changing the procedure for providing cloud and data center services (as of March-June 2026), aim to improve and liberalize the market.
Key changes proposed by the Ministry of Digital Transformation include:
- Consolidation of Regulation: All key powers for forming and implementing state policy in the field of cloud services are vested in the Ministry of Digital Transformation, which should eliminate duplication of functions and simplify business interaction with the state.
- Register of Cloud Service Providers: An official register of cloud service providers is being introduced, inclusion in which will be a mandatory condition for working with government agencies and critical infrastructure operators. This will require providers to submit an application, security compliance certificates, and a conclusion from the Security Service of Ukraine (SSU).
- Flexibility of Contractual Relations: The mandatory "Standard Contract" for public customers is being abolished, allowing companies and government structures to independently form commercial agreements, stipulating basic security requirements and service level agreements (SLAs).
These initiatives indicate Ukraine's aspiration to create more transparent and understandable rules of the game in the cloud services market, which will contribute to further digitalization. Furthermore, Ukraine is taking steps to harmonize its legislation with European standards, particularly with GDPR. Draft Law No. 8153, for example, aims to bring personal data processing rules closer to GDPR standards, implying stricter requirements for businesses and increased responsibility. For enterprises, this is a signal of the need to adapt their internal processes and cloud strategies to more stringent requirements.
Practical Choice: A Checklist for CIOs and CTOs
Choosing a cloud provider for personal data processing is a strategic decision that requires careful analysis. Below is a checklist to help CIOs, CTOs, CISOs, and IT operations managers assess provider compliance with Ukrainian legislation and minimize risks.
Checklist for Evaluating a Cloud Provider for Compliance with Ukrainian Personal Data Protection Legislation:
- Data Subject Consent:
- Does the provider offer tools for effective management of data subject consents (collection, storage, withdrawal) in accordance with the Law of Ukraine "On Personal Data Protection"?
- Can consent mechanisms be configured to meet the requirements for free, clear, informed, and unambiguous manifestation of will?
- Data Residency:
- Can the provider guarantee the storage of personal data on servers located within Ukraine?
- If data is stored outside Ukraine, is it located in countries that provide an "adequate level of personal data protection" in accordance with Ukrainian legislation (e.g., EEA countries, signatories to the Council of Europe Convention)?
- Is there a clear understanding of the jurisdiction to which the data is subject and its impact on the legal regime?
- Security Measures and Certifications:
- What international and national security certifications does the provider hold (ISO 27001, SOC 2, HIPAA, PCI DSS, etc.)?
- Is data encryption provided during transmission and storage?
- What access control, monitoring, and auditing mechanisms are implemented by the provider?
- Do the provider's security measures comply with the requirements of the Law of Ukraine "On Information Protection in Information and Telecommunication Systems" and other cybersecurity regulations?
- Data Subject Rights:
- Does the provider support functionality that allows the data controller to effectively implement data subject rights (access to data, correction, deletion, restriction of processing, data portability)?
- Are there clear SLAs regarding response times to data subject requests?
- Cross-Border Data Transfer:
- What mechanisms does the provider offer to ensure the legality of cross-border data transfers (e.g., standard contractual clauses, binding corporate rules)?
- Does the provider provide information about countries to which data may be transferred and their level of protection?
- Regulatory Compliance and Audits:
- Is the provider prepared for inclusion in the future official register of cloud service providers of the Ministry of Digital Transformation of Ukraine, if required for your business (especially for working with government agencies and critical infrastructure)?
- Does the provider agreement allow for independent audits of compliance with Ukrainian legislation?
- What are the procedures for notifying about data security incidents, and do they allow for compliance with Ukrainian requirements regarding deadlines and content of notifications (e.g., CERT-UA)?
- Contractual Flexibility:
- Does the provider allow for adaptation of contract terms to the specific requirements of Ukrainian legislation, particularly regarding the division of responsibility for security?
- Is it possible to discuss and include provisions in the contract that take into account future regulatory changes (e.g., approximation to GDPR)?
For effective electronic document management and business process automation, which are integral to digital transformation, Ukrainian enterprises can consider solutions offered by companies such as Intecracy Group (https://intecracy.com/) and InBase (https://inbase.com.ua/).
Successful integration of cloud technologies while complying with national personal data protection regulations is key not only to avoiding legal risks but also to building trust with clients and partners. A strategic approach to provider selection and continuous monitoring of legislative changes will allow Ukrainian companies to fully leverage the benefits of cloud solutions in a dynamic digital environment.
Related solutions: Intecracy solutions and inbase.com.ua solutions.