Skip to content

Protecting Ukrainian Business Personal Data in Global Clouds: Architectural Solutions and Legal Risks

In today's world, global cloud infrastructures offer Ukrainian businesses unprecedented opportunities for scaling, enhancing resilience, and optimizing costs. However, these benefits are inextricably linked to the imperative of strict compliance with Ukrainian personal data protection legislation. This balance between innovation and regulatory requirements creates significant tension for IT department leaders and architects, demanding a deep understanding of both technical and legal aspects.

Regulatory Framework: Law of Ukraine "On Personal Data Protection" and "On Cloud Services"

The foundation of personal data protection regulation in Ukraine is the Law of Ukraine "On Personal Data Protection" No. 2297-VI of June 1, 2010. This Law governs relations related to the protection of personal data during their processing, applying to both automated and non-automated processing. It defines personal data as any information about a natural person by which they can be identified, including full name, date of birth, address, phone number, passport details, identification code, email, IP address, photos, as well as information about financial transactions. The processing of such data must be open, transparent, and correspond to clearly defined purposes, and must not be retained longer than necessary for legitimate purposes.

A key aspect for Ukrainian businesses using global clouds is the cross-border transfer of personal data. Law No. 2297-VI allows for such transfers, but requires ensuring an adequate level of data protection in the recipient country or obtaining explicit consent from the data subject. The dissemination of personal data is permitted only with the consent of the individual or in cases expressly provided for by law.

The Law of Ukraine "On Cloud Services" No. 2075-IX of February 17, 2022, although primarily focused on regulating the use of cloud services by government bodies and public users, also has an indirect impact on private businesses. It explicitly states that the protection of personal data when using cloud computing is carried out in accordance with the requirements of the Law of Ukraine "On Personal Data Protection." For public users, the law imposes strict data residency requirements, prohibiting the processing of state secrets, official information, and state registries outside of Ukraine. This underscores a general trend towards localizing sensitive data, which is an important guideline for the private sector as well.

Architectural Strategies for Ensuring Compliance

To effectively protect personal data in global clouds and minimize legal risks, Ukrainian enterprises must implement thoughtful architectural solutions:

  • Hybrid and Multicloud Models. Utilizing a combination of on-premises infrastructure and multiple cloud providers allows for flexible data placement management. Particularly sensitive data can be stored in Ukrainian data centers or private clouds, while less sensitive data can be hosted in global clouds, optimizing costs and performance.
  • Data Segmentation and Classification. Developing a clear data classification policy based on sensitivity levels is a primary step. This allows for determining which data requires the strictest protection and localization measures, and which can be processed in global environments with appropriate controls.
  • Encryption and Key Management. Implementing end-to-end data encryption during both transit and rest is critical. Control over encryption keys, preferably stored within Ukraine or in independent, securely protected repositories, provides an additional layer of security and compliance.
  • Pseudonymization and Anonymization. These techniques reduce the identifiability of personal data. Pseudonymized data can still be linked to an individual if additional information is available, whereas anonymized data does not allow for individual identification. Applying these methods to data processed in global clouds significantly reduces the risks of confidentiality breaches.

Legal Aspects and Minimizing Cross-Border Transfer Risks

Cross-border transfer of personal data is one of the most complex legal challenges. Ukrainian businesses must ensure that such transfers comply with the requirements of Law No. 2297-VI. This includes obtaining data subjects' consent for transferring their data to countries that do not provide an adequate level of protection, or implementing appropriate contractual mechanisms.

Particular attention should be paid to contractual relationships with cloud providers. Contracts must include Data Processing Addendums (DPAs) that clearly define the roles and responsibilities of the parties, security measures, the right to audit, and incident notification mechanisms. It is advisable to use Standard Contractual Clauses (SCCs) adapted to Ukrainian legislation, or to verify their availability with the provider if they are oriented towards international standards like GDPR.

Non-compliance with personal data protection legislation entails significant legal and reputational risks. Violations are subject to administrative liability in the form of fines, which can reach up to UAH 34,000 for repeated offenses. In cases of illegal collection, storage, use, destruction, dissemination, or alteration of confidential information about a person, criminal liability may arise, involving fines, correctional labor, arrest, or imprisonment for up to five years, especially if substantial harm is caused.

Data Classification and Architecture Selection Framework

To make informed decisions regarding data placement, the following classification framework is proposed:

  • Highly Sensitive Data: Information requiring the highest level of protection (e.g., special categories of data, medical records, biometric data, financial information). Recommended to store and process in Ukrainian data centers or private clouds with full control, applying robust encryption.
  • Sensitive Data: Personal data that allows for the identification of an individual (full name, contact information, identification numbers). Hybrid or multicloud solutions may be used with mandatory data localization in regions compliant with Ukrainian legislation, and the application of client-side encryption.
  • Non-Sensitive Data: Information that is not personal data or has been anonymized/pseudonymized in a way that prevents individual identification. Can be placed in global cloud environments with standard security measures.

Checklist for Evaluating Cloud Providers

When selecting a global cloud provider for Ukrainian businesses, a thorough evaluation of its capabilities and contractual terms is critical:

  • Does the provider offer data residency options in regions compliant with Ukrainian legislation or that allow for ensuring an adequate level of protection?
  • Does the provider have relevant security certifications (e.g., ISO 27001) and/or confirmation of compliance with international data protection standards (e.g., GDPR readiness)?
  • Does the provider provide detailed Data Processing Addendums (DPAs) that clearly define its obligations as a data processor?
  • Do the contract terms include audit rights for the client or independent third parties to verify compliance with security and data protection requirements?
  • What data incident response mechanisms does the provider offer, and how quickly does it notify clients of such incidents?
  • Is there a clear exit strategy that allows for easy migration of data to another provider or its return to the client's own infrastructure?

Successfully integrating global cloud services into a Ukrainian enterprise's architecture requires not only technical expertise but also a deep understanding of the legal nuances of personal data protection. A proactive approach to architectural planning and contractual relationships will minimize risks, ensure legal compliance, and fully leverage the benefits of global cloud infrastructure.

Sources

  1. 01coe.int«Захист персональних даних: правове регулювання та практичні аспекти» - Спільний проєкт ЄС та Ради Європи підготував новий посібник - Офіс Ради Європи в Україні
  2. 02jusch.com.uaРегулювання персональних даних у 2025 році: ключові зміни
  3. 03gl.uaGDPR та захист персональних даних у 2025 році: як захистити персональні дані в новій цифровій реальності
  4. 04it-ukraine.com.uaData compliance: як узгодити GDPR, Закон про персональні дані та AI ACT

Does any of this match your situation?

Tell us where you are now — we will suggest a practical route for infrastructure, cloud or security.

Discuss a project