Skip to content

Evidence request lists

Ukraine Law on Personal Data Protection (Law No. 2297-VI)

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Breach Response and Impact Assessment

UA-PDP-09
Breach Response and Notification

Following the 2024 amendments aligning with GDPR-style obligations, owners must notify the Ombudsperson and affected data subjects of personal data breaches likely to cause harm, within statutory timelines and with documented investigation and remediation.

Artefacts an auditor will ask for
  • Personal data breach response plan
  • Breach register
  • Ombudsperson notification submissions
  • Data subject communications
  • Root cause analysis reports
  • Post-incident review minutes
  • Tabletop exercise records
Where this commonly fails
  • No documented breach plan
  • Late notifications
  • No criteria to assess harm threshold
  • Breach register incomplete
UA-PDP-15
Data Protection Impact Assessments for High-Risk Processing

Following 2024 amendments aligning with GDPR-style requirements, owners must conduct impact assessments for processing likely to result in high risk to data subjects, particularly involving profiling, large-scale sensitive data, or systematic monitoring.

Artefacts an auditor will ask for
  • DPIA template and methodology
  • Completed DPIAs
  • Risk treatment plans
  • Stakeholder consultation records
  • Sign-off by responsible person
  • Ombudsperson consultation where required
Where this commonly fails
  • No DPIA for high-risk projects
  • DPIA performed after deployment
  • Risks identified but not treated
  • No consultation with Ombudsperson when required

Governance

UKRAINE-4
Governance and Enforcement

Per Ukraine Law: governance + Ombudsman cooperation + enforcement.

Artefacts an auditor will ask for
  • Ukraine evidence for UKRAINE-4
Where this commonly fails
  • Ombudsman + transfer partial

Governance and Supervision

UA-PDP-07
Personal Data Protection Officer or Responsible Person

Owners and processors of personal data, particularly state authorities, large processors and those handling sensitive data, must appoint a structural unit or responsible person for personal data protection.

Artefacts an auditor will ask for
  • Order or letter of appointment
  • Job description with statutory duties
  • Reporting line to management
  • Notification to Ombudsperson
  • Publication of contact details
  • Training records of responsible person
Where this commonly fails
  • No formal appointment
  • Responsible person without independence
  • Contact not communicated externally
  • No training or qualifications evidence
UA-PDP-16
Cooperation with the Ombudsperson

Owners and processors must cooperate with the Ukrainian Parliament Commissioner for Human Rights (Ombudsperson) in inspections and investigations, providing requested documents, information and access.

Artefacts an auditor will ask for
  • Ombudsperson engagement procedure
  • Inspection response playbook
  • Records of past Ombudsperson interactions
  • Document retrieval index
  • Training on Ombudsperson powers
  • Escalation flowchart
Where this commonly fails
  • No inspection procedure
  • Documents not readily retrievable
  • Past correspondence not archived
  • Staff untrained on regulator authority

Lawful Basis and Consent

UA-PDP-01
Lawful Basis for Processing Personal Data

Personal data may be processed only on a defined lawful basis such as data subject consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a public task, or pursuit of legitimate interests of the controller.

Artefacts an auditor will ask for
  • Inventory of processing operations mapped to lawful basis
  • Legitimate interests assessments where relied upon
  • Contractual clauses establishing necessity
  • Internal lawfulness policy
  • Sign-off by data protection responsible person
  • Templates for documenting basis decisions
Where this commonly fails
  • No documented basis for legacy systems
  • Consent treated as default without alternatives
  • No LIA when relying on legitimate interests
  • Public task basis used without legal source
UA-PDP-02
Consent of the Data Subject

Where consent is the lawful basis, it must be a voluntary expression of the data subject's will, given knowingly with full information about processing, and capable of being withdrawn at any time.

Artefacts an auditor will ask for
  • Consent forms with required information
  • Electronic consent logs with timestamps
  • Withdrawal workflow documentation
  • Notification of withdrawal consequences
  • Versioning of consent statements
  • Re-consent campaign records following 2024 amendments
Where this commonly fails
  • Bundled consents
  • No clear withdrawal mechanism
  • Missing log of when and how consent was given
  • Use of pre-ticked boxes

Marketing and Automated Decisions

UA-PDP-14
Direct Marketing and Communications

Use of personal data for direct marketing purposes requires a lawful basis, with data subjects able to object to such processing at any time and the controller maintaining suppression lists.

Artefacts an auditor will ask for
  • Consent records for marketing
  • Opt-out mechanism per channel
  • Suppression list maintained centrally
  • Marketing campaign sign-off including legal basis
  • Records of unsubscribe processing times
  • Cross-channel suppression evidence
Where this commonly fails
  • No clear opt-out
  • Suppression not applied across channels
  • Marketing to lists acquired without proper basis
  • No record of objections
UA-PDP-19
Automated Decision-Making and Profiling Safeguards

Where decisions producing legal effects are made solely on automated processing or profiling, data subjects must be informed, provided with safeguards, and able to request human intervention or contest the decision.

Artefacts an auditor will ask for
  • Inventory of automated decision systems
  • Privacy notice disclosures about profiling
  • Human review process
  • Model documentation and validation
  • DPIA covering automation risks
  • Records of contested decisions
Where this commonly fails
  • No inventory of automated decisions
  • No human review path
  • Insufficient transparency on logic
  • No DPIA for profiling

Records and Retention

UA-PDP-12
Records and Inventories of Processing

Owners and processors must maintain documentation describing categories of data subjects, purposes, recipients, retention and security measures, and make these available to the Ombudsperson on request.

Artefacts an auditor will ask for
  • Internal processing inventory
  • Periodic review and sign-off records
  • Mapping to data flow diagrams
  • Versioning and change log
  • Ombudsperson inspection-ready exports
  • Access controls to inventory
Where this commonly fails
  • No central inventory
  • Stale inventory not updated for new systems
  • Missing retention information
  • No accountable owner per entry
UA-PDP-13
Retention and Deletion of Personal Data

Personal data must be stored only for the period necessary for the stated purposes, after which it must be deleted or anonymised in accordance with documented retention schedules.

Artefacts an auditor will ask for
  • Records retention schedule
  • Automated deletion logs
  • Anonymisation methodology
  • Disposal certificates for physical media
  • Backup retention alignment
  • Annual retention review records
Where this commonly fails
  • Indefinite retention
  • No verification of deletion
  • Anonymisation not robust against reidentification
  • Backups outside retention scope

Rights

UKRAINE-2
Rights and Notice

Per Ukraine Law: data subject rights + notice.

Artefacts an auditor will ask for
  • Ukraine evidence for UKRAINE-2
Where this commonly fails
  • Ombudsman + transfer partial

Scope

UKRAINE-1
Scope, Lawful Basis (Ukraine)

Per Ukraine Law 2297-VI: scope + lawful basis. Align with Ombudsman.

Artefacts an auditor will ask for
  • Ukraine evidence for UKRAINE-1
Where this commonly fails
  • Ombudsman + transfer partial

Security

UKRAINE-3
Security and Cross-Border

Per Ukraine Law: security + cross-border transfer.

Artefacts an auditor will ask for
  • Ukraine evidence for UKRAINE-3
Where this commonly fails
  • Ombudsman + transfer partial

Security and Confidentiality

UA-PDP-08
Security of Personal Data

Owners and processors must take organisational and technical measures to protect personal data from unlawful processing, accidental loss, destruction or damage and must comply with requirements established by law and the Ombudsperson.

Artefacts an auditor will ask for
  • Information security policy
  • Risk assessment and treatment plan
  • Access control matrices
  • Encryption inventory
  • Cryptographic protection compliance evidence
  • Logging and monitoring configurations
  • Backup procedures
Where this commonly fails
  • No risk-based control selection
  • Cryptographic measures not aligned with Ukrainian standards
  • Logs not retained
  • Backups unencrypted
UA-PDP-18
Staff Confidentiality and Authorisation

Personnel with access to personal data must be subject to obligations of confidentiality and act only on documented instructions of the owner, with formal authorisation and access on a need-to-know basis.

Artefacts an auditor will ask for
  • Confidentiality undertakings signed by staff
  • Access authorisation records
  • Role-based access matrix
  • Training records on data protection
  • Onboarding and offboarding checklists
  • Disciplinary policy referencing breaches
Where this commonly fails
  • No signed confidentiality undertakings
  • Excessive access privileges
  • No offboarding access revocation
  • Lack of role-based access controls

Sensitive and Children's Data

UA-PDP-06
Sensitive Data Processing Conditions

Processing of personal data revealing racial or ethnic origin, political, religious or worldview beliefs, party or trade union membership, criminal convictions, health, sex life or biometric data is prohibited unless specific conditions are met.

Artefacts an auditor will ask for
  • Inventory of sensitive data sets
  • Documented condition under Article 7 relied on
  • Explicit consent records where applicable
  • Access controls and encryption evidence
  • DPIA for sensitive processing
  • Notification to Ombudsperson where required
Where this commonly fails
  • Sensitive data processed without explicit basis
  • No additional safeguards beyond standard controls
  • Missing notification to Ombudsperson where required
  • No DPIA for sensitive processing
UA-PDP-20
Children's Personal Data Protection

Processing of children's personal data requires the consent of a parent or legal guardian and additional safeguards proportionate to the risks, including age-appropriate transparency and content controls.

Artefacts an auditor will ask for
  • Age verification design
  • Parental consent capture records
  • Child-friendly notices
  • DPIA covering children's services
  • Staff training on children's data
  • Procedures where consent not provided
Where this commonly fails
  • No age gate
  • Adult consent treated as default for minors
  • No DPIA for child-facing services
  • Inappropriate processing despite consent refusal

Transfers and Processors

UA-PDP-10
Cross-Border Transfer of Personal Data

Transfers of personal data to foreign subjects are permitted only where the receiving state provides adequate protection, where data subject consent is obtained, or where other legal bases including contractual safeguards apply.

Artefacts an auditor will ask for
  • Transfer register
  • Adequacy assessments per destination
  • Standard contractual clauses or equivalent
  • Consent records for transfer-specific consent
  • Information to data subjects about transfers
  • Risk assessment of foreign legal regime
Where this commonly fails
  • Transfers without assessment
  • No safeguards with foreign processors
  • Transfers to non-adequate states without explicit consent
  • Lack of transparency to data subjects
UA-PDP-11
Processor Engagement and Contracts

Where processing is delegated to a processor, the owner must put in place a written agreement defining the scope, duration, security obligations, confidentiality, sub-processing rules and audit rights.

Artefacts an auditor will ask for
  • Processor inventory
  • Signed data processing agreements
  • Due diligence questionnaires
  • Sub-processor approvals
  • Audit reports of processors
  • Termination and return or deletion evidence
Where this commonly fails
  • Verbal arrangements with processors
  • No audit rights
  • Sub-processors used without controller consent
  • No termination evidence of data return or deletion

Transparency and Data Subject Rights

UA-PDP-03
Notification to Data Subjects

Owners of personal data must inform data subjects at the time of collection about the owner's identity, the purposes of processing, the recipients and the rights available to the data subject.

Artefacts an auditor will ask for
  • Published privacy notices in Ukrainian
  • Just-in-time notices at collection points
  • Records of notice delivery
  • Version control of notices
  • Update logs reflecting 2024 amendments
  • Notices for indirect collection
Where this commonly fails
  • Notices only in English on Ukrainian-facing sites
  • No notice for indirect collection within 30 days
  • Outdated notices missing rights expanded by amendments
  • No record of which notice version applied
UA-PDP-04
Data Subject Rights of Access and Rectification

Data subjects have the right to know what personal data about them is processed, to receive copies, and to have inaccurate or incomplete data corrected without delay.

Artefacts an auditor will ask for
  • Rights request log
  • Identity verification procedure
  • Standard response templates
  • Track of statutory response timelines
  • Records of corrections applied to source systems
  • Ombudsperson referral records
Where this commonly fails
  • No tracking of requests
  • Late responses
  • Inadequate identity checks
  • Corrections not propagated to backups and downstream systems
UA-PDP-05
Rights of Objection, Erasure and Restriction

Data subjects may object to processing, request erasure of their data where conditions are met, and require restriction of processing pending verification, with controllers documenting decisions on each request.

Artefacts an auditor will ask for
  • Erasure procedure and approvals
  • Objection register with outcomes
  • Restriction flags applied in systems
  • Backup handling guidance
  • Justification for refusals
  • Audit trail of erasure across systems
Where this commonly fails
  • No process for erasure across backups
  • Objections not actioned within timeframe
  • No restriction mechanism in systems
  • Inconsistent refusal grounds
UA-PDP-17
Complaints Handling by Data Subjects

Owners must provide accessible internal complaints channels and respond to data subject grievances within statutory timelines, with escalation to the Ombudsperson where issues remain unresolved.

Artefacts an auditor will ask for
  • Published complaints procedure
  • Complaints register
  • Investigation case files
  • Response letters
  • Ombudsperson referral records
  • Trend analysis and management reporting
Where this commonly fails
  • No published complaints process
  • No SLA on responses
  • No escalation when warranted
  • No trend reporting to management
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.