Personal Data Protection in Ukraine: What It Means for Your Business
Picture a simple scenario: an HR platform stores the résumés of five thousand candidates, an e-commerce store keeps order histories and delivery addresses, a SaaS startup processes emails and payment data for users in Poland and Germany. In every one of these cases, the company collects, stores, and uses personal data. That's exactly why personal data protection has stopped being a topic for lawyers to worry about "in case of an inspection" and become a matter of daily operational discipline.
In Ukraine, this isn't an abstract requirement. Processing personal data is governed by the Law of Ukraine "On Personal Data Protection" No. 2297-VI, in force since January 1, 2011, and still the baseline legal act in this field. The law defines who counts as a data controller and processor, which grounds for processing are lawful and which aren't, and what to do if a breach happens. But the law is only half the picture: it tells you what to protect and under what conditions, not how to build a system that actually delivers on that in practice. Standards, namely ISO/IEC 27001 and ISO 27701, are what usually answer the "how."
We covered the security standard itself in detail in our complete guide to ISO/IEC 27001; this piece has a narrower, more practical focus: the intersection of Ukrainian law, GDPR, and the two standards that together cover requirements specific to personal data, not just infrastructure.
The Legal Framework, in Brief
Personal data in Ukraine is governed by Law No. 2297-VI of June 1, 2010, in force since January 1, 2011, in the version current as of June 14, 2025. Oversight is handled by the Ukrainian Parliament Commissioner for Human Rights. Since November 2024, the Parliament has been reviewing draft law No. 8153, a new version of the law that aligns it with GDPR, adopted so far only at first reading. GDPR applies to Ukrainian companies extraterritorially if they offer goods or services to EU residents, regardless of the status of the Ukrainian draft law.
The Personal Data Protection Law No. 2297-VI: What Applies Today
Law No. 2297-VI was adopted on June 1, 2010, and it's been amended repeatedly since then; the current version took effect on June 14, 2025, following Law No. 4240-IX of February 12, 2025. It isn't some frozen fifteen-year-old text. It's a document regularly adjusted for new realities: martial law, the digitization of state registries, and the demands of EU integration.
Here's what the law requires of businesses today. First, a lawful basis for processing: consent, contract performance, a legal requirement, or another lawful case; processing "just in case," without a basis, is a violation. Second, notifying data subjects about the purpose of collection and their rights, including the right to access, correct, and delete their data. Third, restrictions on cross-border transfers: personal data can only be transferred abroad to countries with an adequate level of protection or under additional safeguards.
Enforcement doesn't sit with a dedicated agency. It's the Ukrainian Parliament Commissioner for Human Rights, the Ombudsman, whose secretariat includes a dedicated personal data protection department. The Ombudsman conducts planned and unplanned inspections, issues binding orders, and files administrative violation reports. For a small or mid-sized business owner, that means one simple thing: an inspection can happen not only "if someone complained," but on the Ombudsman's own initiative.
Draft Law No. 8153: The Move Toward a GDPR Standard
The current law was written in 2010, before GDPR, before cloud services in their modern form, and before Ukraine held EU candidate status. That's why draft law No. 8153, "On Personal Data Protection," has been sitting in Parliament since October 2022. It's effectively a new version of the law that brings Ukrainian regulation closer to GDPR and the modernized Council of Europe Convention 108+. The Verkhovna Rada adopted it as a basis (first reading) on November 20, 2024, via Resolution No. 4065-IX, and on December 17, 2025, lawmakers adopted a separate resolution, No. 4729-IX, on the specifics of preparing the document for its second reading. In other words, as of mid-2026 the draft law is still working its way through the parliamentary process; it isn't in force as law.
What the new version proposes, in brief: it extends the law to cover all personal data processing activities, not just those carried out in databases, closing the "we just store a file, not a database" loophole. It broadens data subjects' rights: objecting to processing, challenging automated decisions, and clearer conditions for withdrawing consent. In parallel, Parliament is reviewing draft law No. 6177, which would create a separate independent authority, the National Commission for Personal Data Protection and Access to Public Information, a seven-member collegial body meant to strengthen oversight in this area.
For businesses, the takeaway is practical, not political: waiting for final adoption is a bad strategy. Companies that already have a working system built on ISO 27001 and ISO 27701 adapt to the new requirements far faster than those with no documented data-processing processes at all.
GDPR and Ukraine: When European Law Applies Directly
GDPR (General Data Protection Regulation) is an EU regulation, and the simple fact that your company is registered in Ukraine doesn't automatically exempt you from it. Article 3 of GDPR has extraterritorial reach: if you offer goods or services to people in the EU, or monitor their behavior through analytics, retargeting, or profiling, the regulation applies, regardless of whether Ukraine has adopted its own GDPR-style law.
This is exactly where confusion gets expensive. A Ukrainian SaaS product with customers in France and the Netherlands falls under GDPR right now, not "once draft law No. 8153 passes." A company that sells exclusively to the Ukrainian market, by contrast, is governed by the current Law No. 2297-VI, and GDPR doesn't touch it directly, though EU partners often ask for GDPR-style guarantees in the contract anyway, just in case.
| Criterion | Law No. 2297-VI (Ukraine) | GDPR (EU) |
|---|---|---|
| Territorial scope | Processing of personal data within Ukraine | EU/EEA plus extraterritorial reach: any company offering goods or services to EU residents or monitoring their behavior |
| Supervisory authority | Ukrainian Parliament Commissioner for Human Rights | The national Data Protection Authority (DPA) of the relevant EU country |
| Status for Ukrainian businesses | Mandatory for any data processing carried out in Ukraine | Mandatory only where extraterritorial reach applies; not mandatory for a purely domestic Ukrainian business |
So the first practical question isn't "which law is stricter," it's "who are my users, and where are they." The answer determines whether you need GDPR compliance today, or whether you can plan around the timeline for adopting draft law No. 8153.
ISO/IEC 27001 as the Operating Framework for Personal Data Protection
The law says personal data needs to be protected. It doesn't say how many backups to keep, how to configure access control, or what to do in the first 24 hours after a breach. ISO/IEC 27001 certification covers that practical part: it's the information security management system (ISMS) standard, one we covered in detail in a dedicated guide.
The mechanism is straightforward: a company runs a risk assessment across all its information assets, including personal data stores, selects applicable controls from Annex A (access management, encryption, incident response procedures), and documents the choice in a Statement of Applicability. When a breach happens, and sooner or later something happens at almost any company, a response procedure written out in advance turns chaos into a managed process: who notifies the Ombudsman, within what deadline, which employees or customers need to be informed.
That's where the link to the law lives: ISO/IEC 27001 doesn't replace the legal obligations under No. 2297-VI, but it gives you an operating framework that makes them workable in practice instead of just declared on paper. During certification, an auditor checks exactly that: whether the system actually works, not whether a policy exists in a Word file somewhere.
ISO 27701 and PIMS: The Next Step in Personal Data Protection
ISO/IEC 27001 protects information in general, everything from financial reports to source code. Personal data is just one asset class among others for it. ISO 27701 narrows the focus specifically to privacy: it's the PIMS (Privacy Information Management System) standard, and it answers how a company processes personal data, not just how it protects that data from a breach.
And here's something worth knowing if you're choosing a standard right now: on October 14, 2025, a new edition was released, ISO/IEC 27701:2025. Until then, the standard existed strictly as an extension to ISO/IEC 27001 and ISO/IEC 27002; you couldn't get certified against it on its own. The 2025 edition changes that fundamentally: ISO 27701 is now a standalone, independently certifiable standard. A company can earn a PIMS certificate even without an ISO/IEC 27001 certification in place or planned.
The control structure changed too. Instead of more than 150 requirements scattered across clauses 6-8 of the 2019 edition, the new version consolidates 78 controls into three clear tables: for controllers, processors, and shared cases. It also added an annex mapping controls directly to GDPR articles, which simplifies the argument during an audit or in negotiations with an EU partner. Companies certified against the 2019 edition have until October 2028 to transition; it isn't urgent, but it's not a reason to put the decision off either.
ISO/IEC 27701:2025 — The Big News for Anyone Choosing a Standard
As of October 14, 2025, ISO/IEC 27701 is a standalone, independently certifiable standard, not just an extension of ISO/IEC 27001. The number of controls dropped from over 150 to 78, consolidated into three tables for controllers, processors, and shared cases. A direct mapping to GDPR articles was added. Companies holding a 2019-edition certificate have until October 2028 to transition. For businesses that haven't started certification yet, this means a wider choice: you can now start with privacy directly, without a mandatory tie to ISO/IEC 27001.
Check Your Readiness for ISO/IEC 27001 and ISO 27701
A free preliminary gap assessment against Annex A/B requirements from a Bureau Veritas partner in Ukraine.
Learn about ISO/IEC 27001 certificationISO 27001 and ISO 27701 Together: Three Implementation Scenarios
"Do we need 27001, 27701, or both" is one of the first questions we work through during a diagnostic. The answer depends not on budget, but on what actually creates the biggest risk for you.
| Scenario | What it covers | Who it fits |
|---|---|---|
| ISO/IEC 27001 only | Information security management in general: financial data, code, infrastructure | Companies without large-scale processing of EU customers' personal data |
| ISO/IEC 27001 + ISO/IEC 27701 | Information security and privacy management in a single system, built on shared clauses 4-10 | IT/SaaS and fintech companies that already hold ISO 27001 and process customer personal data |
| ISO/IEC 27701:2025 only (standalone) | Privacy management only, without a full ISMS | Companies where the main risk sits specifically in personal data, not information security overall |
The most common path for Ukrainian IT businesses is the second one: adding ISO 27701 to an existing or parallel ISO/IEC 27001 implementation, since both standards share the same clause 4-10 structure and don't duplicate the work. The third scenario, standalone PIMS certification, is still new even for the international market; the first certification bodies are only now preparing accreditation for the 2025 edition.
Who in Ukraine Critically Needs ISO 27001 and ISO 27701
Formally, neither standard is mandatory; only the law is. In practice, six types of business run into this question almost every week.
- IT and SaaS companies serving EU clients. A partner sends a security questionnaire before the contract is even signed, and without a documented system there's simply nothing to answer it with.
- Fintech and neobanks. Payment data and KYC records require proof of control, not a promise.
- HR-tech and recruitment platforms. Résumés, contacts, and candidate evaluations are personal data in its purest form, processed at scale.
- Medical and telehealth services. Health data belongs to a special category, and the reputational hit after a breach lands harder here than almost anywhere else.
- E-commerce and marketplaces. Purchase history, addresses, behavioral analytics for retargeting.
- Companies ahead of a tender or an investment round. Investor or public-buyer due diligence increasingly checks data privacy specifically, not just financials.
The common thread across all six isn't company size. It's that customer personal data is part of the business model, not a byproduct of it.
Common Mistakes That Undermine Personal Data Protection
We see the same gaps over and over again on consultations, and none of them come down to a lack of technology or budget.
A Cookie Banner Gets Passed Off as Personal Data Protection
A company installs a cookie-consent plugin and considers the matter closed. Cookie consent is one narrow element; it says nothing about how data is stored, who has access to it, or what happens when an employee with access to the customer database leaves the company.
No Processing Register Exists
Without a list of what data, from where, for what purpose, and for how long it's kept, you can't respond to a data subject's deletion request or pass an audit. This isn't bureaucracy for its own sake; without a register, a company doesn't even know how exposed it is.
Vendor Contracts Don't Cover Data Processing
An outsourced accounting firm, a CRM provider, a mailing service: all of them process personal data on your behalf. If the contract has no clause covering that, liability for their negligence falls on you.
Cross-Border Data Transfers Happen by Default
Customer data flies off to servers in the US or Singapore along with a cloud service someone connected without checking whether the law even allows it.
The most common reason behind these mistakes isn't carelessness. It's that personal data protection gets treated as a one-off project before an inspection, rather than an ongoing process.
Important: Fines Are Already Possible Under the Current Law
Waiting for draft law No. 8153 to pass isn't a reason to delay compliance. The current Law No. 2297-VI has been in force for more than fifteen years, and the Ukrainian Parliament Commissioner for Human Rights already conducts inspections and issues orders for violating it today, not after some future version takes effect. A new law will raise the bar, not erase the requirements already in place.
How Ekontrol Prepares Companies for Personal Data Protection
Ekontrol supports preparation for ISO/IEC 27001 and ISO 27701 as part of its information security practice, alongside ISO 22301 for companies that need a broader system. The approach is the same one we use for standard ISMS certification: start with a diagnostic. Within a few days, the team maps how far a company's current processes are from the requirements of Law No. 2297-VI and the Annex A/B controls of the chosen standards, with no sugarcoating on numbers or timelines.
Implementation follows: a personal data processing register, vendor agreements, an incident-response procedure, team training. For companies that already hold ISO/IEC 27001, adding ISO 27701's PIMS controls moves faster, since part of the work, risk assessment, the management cycle, documentation, is already in place.
If your company processes personal data belonging to EU customers, is preparing for a tender that requires privacy controls, or simply wants to build personal data protection sturdy enough to survive both an audit and an Ombudsman inspection, details on ISO/IEC 27001 certification and a form for a first consultation are available on the site. The Ekontrol team has worked as a Bureau Veritas partner in Ukraine since 2014.

Need a certification consultation?
Free Consultation
On This Page
- Personal Data Protection in Ukraine: What It Means for Your Business
- The Personal Data Protection Law No. 2297-VI: What Applies Today
- Draft Law No. 8153: The Move Toward a GDPR Standard
- GDPR and Ukraine: When European Law Applies Directly
- ISO/IEC 27001 as the Operating Framework for Personal Data Protection
- ISO 27701 and PIMS: The Next Step in Personal Data Protection
- ISO 27001 and ISO 27701 Together: Three Implementation Scenarios
- Who in Ukraine Critically Needs ISO 27001 and ISO 27701
- Common Mistakes That Undermine Personal Data Protection
- How Ekontrol Prepares Companies for Personal Data Protection
- FAQ — Frequently Asked Questions About Personal Data Protection
Personal Data Protection in Ukraine: What It Means for Your Business
Picture a simple scenario: an HR platform stores the résumés of five thousand candidates, an e-commerce store keeps order histories and delivery addresses, a SaaS startup processes emails and payment data for users in Poland and Germany. In every one of these cases, the company collects, stores, and uses personal data. That's exactly why personal data protection has stopped being a topic for lawyers to worry about "in case of an inspection" and become a matter of daily operational discipline.
In Ukraine, this isn't an abstract requirement. Processing personal data is governed by the Law of Ukraine "On Personal Data Protection" No. 2297-VI, in force since January 1, 2011, and still the baseline legal act in this field. The law defines who counts as a data controller and processor, which grounds for processing are lawful and which aren't, and what to do if a breach happens. But the law is only half the picture: it tells you what to protect and under what conditions, not how to build a system that actually delivers on that in practice. Standards, namely ISO/IEC 27001 and ISO 27701, are what usually answer the "how."
We covered the security standard itself in detail in our complete guide to ISO/IEC 27001; this piece has a narrower, more practical focus: the intersection of Ukrainian law, GDPR, and the two standards that together cover requirements specific to personal data, not just infrastructure.
The Legal Framework, in Brief
Personal data in Ukraine is governed by Law No. 2297-VI of June 1, 2010, in force since January 1, 2011, in the version current as of June 14, 2025. Oversight is handled by the Ukrainian Parliament Commissioner for Human Rights. Since November 2024, the Parliament has been reviewing draft law No. 8153, a new version of the law that aligns it with GDPR, adopted so far only at first reading. GDPR applies to Ukrainian companies extraterritorially if they offer goods or services to EU residents, regardless of the status of the Ukrainian draft law.
The Personal Data Protection Law No. 2297-VI: What Applies Today
Law No. 2297-VI was adopted on June 1, 2010, and it's been amended repeatedly since then; the current version took effect on June 14, 2025, following Law No. 4240-IX of February 12, 2025. It isn't some frozen fifteen-year-old text. It's a document regularly adjusted for new realities: martial law, the digitization of state registries, and the demands of EU integration.
Here's what the law requires of businesses today. First, a lawful basis for processing: consent, contract performance, a legal requirement, or another lawful case; processing "just in case," without a basis, is a violation. Second, notifying data subjects about the purpose of collection and their rights, including the right to access, correct, and delete their data. Third, restrictions on cross-border transfers: personal data can only be transferred abroad to countries with an adequate level of protection or under additional safeguards.
Enforcement doesn't sit with a dedicated agency. It's the Ukrainian Parliament Commissioner for Human Rights, the Ombudsman, whose secretariat includes a dedicated personal data protection department. The Ombudsman conducts planned and unplanned inspections, issues binding orders, and files administrative violation reports. For a small or mid-sized business owner, that means one simple thing: an inspection can happen not only "if someone complained," but on the Ombudsman's own initiative.
Draft Law No. 8153: The Move Toward a GDPR Standard
The current law was written in 2010, before GDPR, before cloud services in their modern form, and before Ukraine held EU candidate status. That's why draft law No. 8153, "On Personal Data Protection," has been sitting in Parliament since October 2022. It's effectively a new version of the law that brings Ukrainian regulation closer to GDPR and the modernized Council of Europe Convention 108+. The Verkhovna Rada adopted it as a basis (first reading) on November 20, 2024, via Resolution No. 4065-IX, and on December 17, 2025, lawmakers adopted a separate resolution, No. 4729-IX, on the specifics of preparing the document for its second reading. In other words, as of mid-2026 the draft law is still working its way through the parliamentary process; it isn't in force as law.
What the new version proposes, in brief: it extends the law to cover all personal data processing activities, not just those carried out in databases, closing the "we just store a file, not a database" loophole. It broadens data subjects' rights: objecting to processing, challenging automated decisions, and clearer conditions for withdrawing consent. In parallel, Parliament is reviewing draft law No. 6177, which would create a separate independent authority, the National Commission for Personal Data Protection and Access to Public Information, a seven-member collegial body meant to strengthen oversight in this area.
For businesses, the takeaway is practical, not political: waiting for final adoption is a bad strategy. Companies that already have a working system built on ISO 27001 and ISO 27701 adapt to the new requirements far faster than those with no documented data-processing processes at all.
GDPR and Ukraine: When European Law Applies Directly
GDPR (General Data Protection Regulation) is an EU regulation, and the simple fact that your company is registered in Ukraine doesn't automatically exempt you from it. Article 3 of GDPR has extraterritorial reach: if you offer goods or services to people in the EU, or monitor their behavior through analytics, retargeting, or profiling, the regulation applies, regardless of whether Ukraine has adopted its own GDPR-style law.
This is exactly where confusion gets expensive. A Ukrainian SaaS product with customers in France and the Netherlands falls under GDPR right now, not "once draft law No. 8153 passes." A company that sells exclusively to the Ukrainian market, by contrast, is governed by the current Law No. 2297-VI, and GDPR doesn't touch it directly, though EU partners often ask for GDPR-style guarantees in the contract anyway, just in case.
| Criterion | Law No. 2297-VI (Ukraine) | GDPR (EU) |
|---|---|---|
| Territorial scope | Processing of personal data within Ukraine | EU/EEA plus extraterritorial reach: any company offering goods or services to EU residents or monitoring their behavior |
| Supervisory authority | Ukrainian Parliament Commissioner for Human Rights | The national Data Protection Authority (DPA) of the relevant EU country |
| Status for Ukrainian businesses | Mandatory for any data processing carried out in Ukraine | Mandatory only where extraterritorial reach applies; not mandatory for a purely domestic Ukrainian business |
So the first practical question isn't "which law is stricter," it's "who are my users, and where are they." The answer determines whether you need GDPR compliance today, or whether you can plan around the timeline for adopting draft law No. 8153.
ISO/IEC 27001 as the Operating Framework for Personal Data Protection
The law says personal data needs to be protected. It doesn't say how many backups to keep, how to configure access control, or what to do in the first 24 hours after a breach. ISO/IEC 27001 certification covers that practical part: it's the information security management system (ISMS) standard, one we covered in detail in a dedicated guide.
The mechanism is straightforward: a company runs a risk assessment across all its information assets, including personal data stores, selects applicable controls from Annex A (access management, encryption, incident response procedures), and documents the choice in a Statement of Applicability. When a breach happens, and sooner or later something happens at almost any company, a response procedure written out in advance turns chaos into a managed process: who notifies the Ombudsman, within what deadline, which employees or customers need to be informed.
That's where the link to the law lives: ISO/IEC 27001 doesn't replace the legal obligations under No. 2297-VI, but it gives you an operating framework that makes them workable in practice instead of just declared on paper. During certification, an auditor checks exactly that: whether the system actually works, not whether a policy exists in a Word file somewhere.
ISO 27701 and PIMS: The Next Step in Personal Data Protection
ISO/IEC 27001 protects information in general, everything from financial reports to source code. Personal data is just one asset class among others for it. ISO 27701 narrows the focus specifically to privacy: it's the PIMS (Privacy Information Management System) standard, and it answers how a company processes personal data, not just how it protects that data from a breach.
And here's something worth knowing if you're choosing a standard right now: on October 14, 2025, a new edition was released, ISO/IEC 27701:2025. Until then, the standard existed strictly as an extension to ISO/IEC 27001 and ISO/IEC 27002; you couldn't get certified against it on its own. The 2025 edition changes that fundamentally: ISO 27701 is now a standalone, independently certifiable standard. A company can earn a PIMS certificate even without an ISO/IEC 27001 certification in place or planned.
The control structure changed too. Instead of more than 150 requirements scattered across clauses 6-8 of the 2019 edition, the new version consolidates 78 controls into three clear tables: for controllers, processors, and shared cases. It also added an annex mapping controls directly to GDPR articles, which simplifies the argument during an audit or in negotiations with an EU partner. Companies certified against the 2019 edition have until October 2028 to transition; it isn't urgent, but it's not a reason to put the decision off either.
ISO/IEC 27701:2025 — The Big News for Anyone Choosing a Standard
As of October 14, 2025, ISO/IEC 27701 is a standalone, independently certifiable standard, not just an extension of ISO/IEC 27001. The number of controls dropped from over 150 to 78, consolidated into three tables for controllers, processors, and shared cases. A direct mapping to GDPR articles was added. Companies holding a 2019-edition certificate have until October 2028 to transition. For businesses that haven't started certification yet, this means a wider choice: you can now start with privacy directly, without a mandatory tie to ISO/IEC 27001.
Check Your Readiness for ISO/IEC 27001 and ISO 27701
A free preliminary gap assessment against Annex A/B requirements from a Bureau Veritas partner in Ukraine.
Learn about ISO/IEC 27001 certificationISO 27001 and ISO 27701 Together: Three Implementation Scenarios
"Do we need 27001, 27701, or both" is one of the first questions we work through during a diagnostic. The answer depends not on budget, but on what actually creates the biggest risk for you.
| Scenario | What it covers | Who it fits |
|---|---|---|
| ISO/IEC 27001 only | Information security management in general: financial data, code, infrastructure | Companies without large-scale processing of EU customers' personal data |
| ISO/IEC 27001 + ISO/IEC 27701 | Information security and privacy management in a single system, built on shared clauses 4-10 | IT/SaaS and fintech companies that already hold ISO 27001 and process customer personal data |
| ISO/IEC 27701:2025 only (standalone) | Privacy management only, without a full ISMS | Companies where the main risk sits specifically in personal data, not information security overall |
The most common path for Ukrainian IT businesses is the second one: adding ISO 27701 to an existing or parallel ISO/IEC 27001 implementation, since both standards share the same clause 4-10 structure and don't duplicate the work. The third scenario, standalone PIMS certification, is still new even for the international market; the first certification bodies are only now preparing accreditation for the 2025 edition.
Who in Ukraine Critically Needs ISO 27001 and ISO 27701
Formally, neither standard is mandatory; only the law is. In practice, six types of business run into this question almost every week.
- IT and SaaS companies serving EU clients. A partner sends a security questionnaire before the contract is even signed, and without a documented system there's simply nothing to answer it with.
- Fintech and neobanks. Payment data and KYC records require proof of control, not a promise.
- HR-tech and recruitment platforms. Résumés, contacts, and candidate evaluations are personal data in its purest form, processed at scale.
- Medical and telehealth services. Health data belongs to a special category, and the reputational hit after a breach lands harder here than almost anywhere else.
- E-commerce and marketplaces. Purchase history, addresses, behavioral analytics for retargeting.
- Companies ahead of a tender or an investment round. Investor or public-buyer due diligence increasingly checks data privacy specifically, not just financials.
The common thread across all six isn't company size. It's that customer personal data is part of the business model, not a byproduct of it.
Common Mistakes That Undermine Personal Data Protection
We see the same gaps over and over again on consultations, and none of them come down to a lack of technology or budget.
A Cookie Banner Gets Passed Off as Personal Data Protection
A company installs a cookie-consent plugin and considers the matter closed. Cookie consent is one narrow element; it says nothing about how data is stored, who has access to it, or what happens when an employee with access to the customer database leaves the company.
No Processing Register Exists
Without a list of what data, from where, for what purpose, and for how long it's kept, you can't respond to a data subject's deletion request or pass an audit. This isn't bureaucracy for its own sake; without a register, a company doesn't even know how exposed it is.
Vendor Contracts Don't Cover Data Processing
An outsourced accounting firm, a CRM provider, a mailing service: all of them process personal data on your behalf. If the contract has no clause covering that, liability for their negligence falls on you.
Cross-Border Data Transfers Happen by Default
Customer data flies off to servers in the US or Singapore along with a cloud service someone connected without checking whether the law even allows it.
The most common reason behind these mistakes isn't carelessness. It's that personal data protection gets treated as a one-off project before an inspection, rather than an ongoing process.
Important: Fines Are Already Possible Under the Current Law
Waiting for draft law No. 8153 to pass isn't a reason to delay compliance. The current Law No. 2297-VI has been in force for more than fifteen years, and the Ukrainian Parliament Commissioner for Human Rights already conducts inspections and issues orders for violating it today, not after some future version takes effect. A new law will raise the bar, not erase the requirements already in place.
How Ekontrol Prepares Companies for Personal Data Protection
Ekontrol supports preparation for ISO/IEC 27001 and ISO 27701 as part of its information security practice, alongside ISO 22301 for companies that need a broader system. The approach is the same one we use for standard ISMS certification: start with a diagnostic. Within a few days, the team maps how far a company's current processes are from the requirements of Law No. 2297-VI and the Annex A/B controls of the chosen standards, with no sugarcoating on numbers or timelines.
Implementation follows: a personal data processing register, vendor agreements, an incident-response procedure, team training. For companies that already hold ISO/IEC 27001, adding ISO 27701's PIMS controls moves faster, since part of the work, risk assessment, the management cycle, documentation, is already in place.
If your company processes personal data belonging to EU customers, is preparing for a tender that requires privacy controls, or simply wants to build personal data protection sturdy enough to survive both an audit and an Ombudsman inspection, details on ISO/IEC 27001 certification and a form for a first consultation are available on the site. The Ekontrol team has worked as a Bureau Veritas partner in Ukraine since 2014.


