Ukraine Law on Personal Data Protection (Law No. 2297-VI)
Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Breach Response and Impact Assessment
Following the 2024 amendments aligning with GDPR-style obligations, owners must notify the Ombudsperson and affected data subjects of personal data breaches likely to cause harm, within statutory timelines and with documented investigation and remediation.
- Personal data breach response plan
- Breach register
- Ombudsperson notification submissions
- Data subject communications
- Root cause analysis reports
- Post-incident review minutes
- Tabletop exercise records
- No documented breach plan
- Late notifications
- No criteria to assess harm threshold
- Breach register incomplete
Following 2024 amendments aligning with GDPR-style requirements, owners must conduct impact assessments for processing likely to result in high risk to data subjects, particularly involving profiling, large-scale sensitive data, or systematic monitoring.
- DPIA template and methodology
- Completed DPIAs
- Risk treatment plans
- Stakeholder consultation records
- Sign-off by responsible person
- Ombudsperson consultation where required
- No DPIA for high-risk projects
- DPIA performed after deployment
- Risks identified but not treated
- No consultation with Ombudsperson when required
Governance
Per Ukraine Law: governance + Ombudsman cooperation + enforcement.
- Ukraine evidence for UKRAINE-4
- Ombudsman + transfer partial
Governance and Supervision
Owners and processors of personal data, particularly state authorities, large processors and those handling sensitive data, must appoint a structural unit or responsible person for personal data protection.
- Order or letter of appointment
- Job description with statutory duties
- Reporting line to management
- Notification to Ombudsperson
- Publication of contact details
- Training records of responsible person
- No formal appointment
- Responsible person without independence
- Contact not communicated externally
- No training or qualifications evidence
Owners and processors must cooperate with the Ukrainian Parliament Commissioner for Human Rights (Ombudsperson) in inspections and investigations, providing requested documents, information and access.
- Ombudsperson engagement procedure
- Inspection response playbook
- Records of past Ombudsperson interactions
- Document retrieval index
- Training on Ombudsperson powers
- Escalation flowchart
- No inspection procedure
- Documents not readily retrievable
- Past correspondence not archived
- Staff untrained on regulator authority
Lawful Basis and Consent
Personal data may be processed only on a defined lawful basis such as data subject consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a public task, or pursuit of legitimate interests of the controller.
- Inventory of processing operations mapped to lawful basis
- Legitimate interests assessments where relied upon
- Contractual clauses establishing necessity
- Internal lawfulness policy
- Sign-off by data protection responsible person
- Templates for documenting basis decisions
- No documented basis for legacy systems
- Consent treated as default without alternatives
- No LIA when relying on legitimate interests
- Public task basis used without legal source
Where consent is the lawful basis, it must be a voluntary expression of the data subject's will, given knowingly with full information about processing, and capable of being withdrawn at any time.
- Consent forms with required information
- Electronic consent logs with timestamps
- Withdrawal workflow documentation
- Notification of withdrawal consequences
- Versioning of consent statements
- Re-consent campaign records following 2024 amendments
- Bundled consents
- No clear withdrawal mechanism
- Missing log of when and how consent was given
- Use of pre-ticked boxes
Marketing and Automated Decisions
Use of personal data for direct marketing purposes requires a lawful basis, with data subjects able to object to such processing at any time and the controller maintaining suppression lists.
- Consent records for marketing
- Opt-out mechanism per channel
- Suppression list maintained centrally
- Marketing campaign sign-off including legal basis
- Records of unsubscribe processing times
- Cross-channel suppression evidence
- No clear opt-out
- Suppression not applied across channels
- Marketing to lists acquired without proper basis
- No record of objections
Where decisions producing legal effects are made solely on automated processing or profiling, data subjects must be informed, provided with safeguards, and able to request human intervention or contest the decision.
- Inventory of automated decision systems
- Privacy notice disclosures about profiling
- Human review process
- Model documentation and validation
- DPIA covering automation risks
- Records of contested decisions
- No inventory of automated decisions
- No human review path
- Insufficient transparency on logic
- No DPIA for profiling
Records and Retention
Owners and processors must maintain documentation describing categories of data subjects, purposes, recipients, retention and security measures, and make these available to the Ombudsperson on request.
- Internal processing inventory
- Periodic review and sign-off records
- Mapping to data flow diagrams
- Versioning and change log
- Ombudsperson inspection-ready exports
- Access controls to inventory
- No central inventory
- Stale inventory not updated for new systems
- Missing retention information
- No accountable owner per entry
Personal data must be stored only for the period necessary for the stated purposes, after which it must be deleted or anonymised in accordance with documented retention schedules.
- Records retention schedule
- Automated deletion logs
- Anonymisation methodology
- Disposal certificates for physical media
- Backup retention alignment
- Annual retention review records
- Indefinite retention
- No verification of deletion
- Anonymisation not robust against reidentification
- Backups outside retention scope
Rights
Per Ukraine Law: data subject rights + notice.
- Ukraine evidence for UKRAINE-2
- Ombudsman + transfer partial
Scope
Per Ukraine Law 2297-VI: scope + lawful basis. Align with Ombudsman.
- Ukraine evidence for UKRAINE-1
- Ombudsman + transfer partial
Security
Per Ukraine Law: security + cross-border transfer.
- Ukraine evidence for UKRAINE-3
- Ombudsman + transfer partial
Security and Confidentiality
Owners and processors must take organisational and technical measures to protect personal data from unlawful processing, accidental loss, destruction or damage and must comply with requirements established by law and the Ombudsperson.
- Information security policy
- Risk assessment and treatment plan
- Access control matrices
- Encryption inventory
- Cryptographic protection compliance evidence
- Logging and monitoring configurations
- Backup procedures
- No risk-based control selection
- Cryptographic measures not aligned with Ukrainian standards
- Logs not retained
- Backups unencrypted
Personnel with access to personal data must be subject to obligations of confidentiality and act only on documented instructions of the owner, with formal authorisation and access on a need-to-know basis.
- Confidentiality undertakings signed by staff
- Access authorisation records
- Role-based access matrix
- Training records on data protection
- Onboarding and offboarding checklists
- Disciplinary policy referencing breaches
- No signed confidentiality undertakings
- Excessive access privileges
- No offboarding access revocation
- Lack of role-based access controls
Sensitive and Children's Data
Processing of personal data revealing racial or ethnic origin, political, religious or worldview beliefs, party or trade union membership, criminal convictions, health, sex life or biometric data is prohibited unless specific conditions are met.
- Inventory of sensitive data sets
- Documented condition under Article 7 relied on
- Explicit consent records where applicable
- Access controls and encryption evidence
- DPIA for sensitive processing
- Notification to Ombudsperson where required
- Sensitive data processed without explicit basis
- No additional safeguards beyond standard controls
- Missing notification to Ombudsperson where required
- No DPIA for sensitive processing
Processing of children's personal data requires the consent of a parent or legal guardian and additional safeguards proportionate to the risks, including age-appropriate transparency and content controls.
- Age verification design
- Parental consent capture records
- Child-friendly notices
- DPIA covering children's services
- Staff training on children's data
- Procedures where consent not provided
- No age gate
- Adult consent treated as default for minors
- No DPIA for child-facing services
- Inappropriate processing despite consent refusal
Transfers and Processors
Transfers of personal data to foreign subjects are permitted only where the receiving state provides adequate protection, where data subject consent is obtained, or where other legal bases including contractual safeguards apply.
- Transfer register
- Adequacy assessments per destination
- Standard contractual clauses or equivalent
- Consent records for transfer-specific consent
- Information to data subjects about transfers
- Risk assessment of foreign legal regime
- Transfers without assessment
- No safeguards with foreign processors
- Transfers to non-adequate states without explicit consent
- Lack of transparency to data subjects
Where processing is delegated to a processor, the owner must put in place a written agreement defining the scope, duration, security obligations, confidentiality, sub-processing rules and audit rights.
- Processor inventory
- Signed data processing agreements
- Due diligence questionnaires
- Sub-processor approvals
- Audit reports of processors
- Termination and return or deletion evidence
- Verbal arrangements with processors
- No audit rights
- Sub-processors used without controller consent
- No termination evidence of data return or deletion
Transparency and Data Subject Rights
Owners of personal data must inform data subjects at the time of collection about the owner's identity, the purposes of processing, the recipients and the rights available to the data subject.
- Published privacy notices in Ukrainian
- Just-in-time notices at collection points
- Records of notice delivery
- Version control of notices
- Update logs reflecting 2024 amendments
- Notices for indirect collection
- Notices only in English on Ukrainian-facing sites
- No notice for indirect collection within 30 days
- Outdated notices missing rights expanded by amendments
- No record of which notice version applied
Data subjects have the right to know what personal data about them is processed, to receive copies, and to have inaccurate or incomplete data corrected without delay.
- Rights request log
- Identity verification procedure
- Standard response templates
- Track of statutory response timelines
- Records of corrections applied to source systems
- Ombudsperson referral records
- No tracking of requests
- Late responses
- Inadequate identity checks
- Corrections not propagated to backups and downstream systems
Data subjects may object to processing, request erasure of their data where conditions are met, and require restriction of processing pending verification, with controllers documenting decisions on each request.
- Erasure procedure and approvals
- Objection register with outcomes
- Restriction flags applied in systems
- Backup handling guidance
- Justification for refusals
- Audit trail of erasure across systems
- No process for erasure across backups
- Objections not actioned within timeframe
- No restriction mechanism in systems
- Inconsistent refusal grounds
Owners must provide accessible internal complaints channels and respond to data subject grievances within statutory timelines, with escalation to the Ombudsperson where issues remain unresolved.
- Published complaints procedure
- Complaints register
- Investigation case files
- Response letters
- Ombudsperson referral records
- Trend analysis and management reporting
- No published complaints process
- No SLA on responses
- No escalation when warranted
- No trend reporting to management
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.