Bill No. 12207 “On Amendments to Certain Laws of Ukraine Regarding the Improvement of Cybersecurity Oversight Procedures and the Introduction of European Cybersecurity Certification Schemes” is important and beneficial for national legislation in light of trends in the development of digital technologies; the amendments to certain laws of Ukraine are aimed at bringing national legislation into line with Ukraine’s obligations under European cybersecurity initiatives.
At the same time, an analysis of the draft law in its current version reveals a number of conceptual, terminological, and practical shortcomings; unless these are addressed, there are risks that could hinder its effective implementation.
First, attention should be drawn to the inconsistency of terminology and legal constructs with the EU acquis. The proposed definitions of certain terms are inconsistent with European legal acts, which makes it impossible to implement the provisions of the European Union directive aimed at enhancing cybersecurity in EU member states into national legislation.
Second, the current version contains legal ambiguities, as some provisions of the draft law are not sufficiently specific, which could lead to conflicts in legal application.
For example, the definition of the competencies of various cybersecurity agencies is not clearly delineated, which could lead to overlapping functions or legal conflicts.
Third, due to the vague definition of the authorities responsible for implementing cybersecurity policy, the bill does not contain a specific mechanism for coordination between government agencies and cybersecurity entities.
In particular, it is not specified how the proposed National Center for Electronic Resource Backup will function, and there is no clear framework for interaction with existing structures.
Fourth, the introduction of administrative and economic sanctions without clear mechanisms for their enforcement. The bill provides for significant fines for violations of cybersecurity regulations, but there are no specific mechanisms for their application or a methodology for calculating fines. This creates risks of selective law enforcement and potential abuse.
Fifth, the lack of a comprehensive approach to legislative changes is also a significant shortcoming.
Some provisions of the draft are inconsistent with the Law of Ukraine “On National Security of Ukraine,” the Criminal Procedure Code, and other regulatory acts.
For example, the bill provides for an expansion of the Security Service of Ukraine’s (SBU) authority to investigate cybercrimes, which requires amendments to the Criminal Procedure Code.
Despite the importance of this draft law for strengthening cybersecurity in our country and its focus on alignment with EU standards, the proposed text contains a number of shortcomings that require further refinement. I consider it necessary to:
- Conduct an additional terminological analysis to resolve discrepancies with NIS2 regulations and the EU acquis.
- Clarify the competencies of the authorities responsible for cybersecurity oversight to avoid duplication of functions.
- Establish a clear mechanism for determining liability for cybersecurity violations to ensure transparency in law enforcement.
- Establish a clear methodology for calculating fines, specifying concrete sanctions.
- Bring the provisions on cybersecurity into line with Ukraine’s current legislation, in particular the Criminal Code and national security legislation.
In our view, once these priority amendments are incorporated, the draft law will be able to be gradually implemented, fulfill its intended objectives, and meet European standards.
Author: Yuriy Zhovtan, Attorney and Partner at Barristers
Source: https://pravo.ua/kontseptualni-nedoliky-zakonoproiektu-12207-bloh-iuriia-zhovtana/?fbclid=IwY2xjawJE8oZleHRuA2FlbQIxMAABHUyQTd9PkedysjAe-VITRF9lMUcM4OcSrzCb4cbl1QhGpKB5kXnoaeGo0w_aem_hDI3hxuKv7eVpQisrGzsGw