Bill No. 14118 dated October 13, 2025, which proposes amendments to Article 34 of the Law of Ukraine “On Public Electronic Registers,” is an important initiative aimed at strengthening the fundamental constitutional rights of citizens, in particular the right to privacy and the protection of personal data, as guaranteed by Article 32 of the Constitution of Ukraine.
The essence of the bill is to introduce a new direct obligation for registry administrators to inform the data subject—that is, the person to whom the data pertains—of every instance of use (access) of registry information concerning them. This notification must be provided no later than five days from the date such access is granted. The proposed amendments concern Part 3 of Article 34 (regarding special access used by government agencies, notaries, banks, etc.) and Part 4 (regarding access through automated electronic data exchange between registries).
Currently, citizens are in the dark, unaware of who, when, and for what purpose their data is being viewed in government databases, and typically find out about it only after the fact, often while challenging unlawful actions, such as fraudulent re-registration of property. The introduction of mandatory notification transforms the passive data subject into an active controller, providing them with a real tool for monitoring. This is a powerful preventive measure against abuse and corruption, since an official or notary, knowing that the data subject will be informed of their request, will refrain from unauthorized or excessive “interest.”
This approach aligns with European data protection standards—particularly regarding the right of access—and significantly increases the transparency of government electronic systems and public trust in them. At the same time, the devil is in the details, and there are significant risks on the path to implementation.
First, there is the technical complexity. The explanatory note states that implementation will not require additional budgetary funds and will be carried out within the framework of existing IT systems. However, this requires the creation of a single, unified notification mechanism (likely via “Diy” or the electronic portal), which must integrate correctly with dozens of disparate registries, each of which has its own architecture, and ensure reliable identification of the rights holder and delivery of the notification within a strict five-day deadline.
Second, there is a risk of “notification spam”: if the law is interpreted literally, any automatic data reconciliation between registries (for example, daily verification of lists of beneficiaries) could generate thousands of technical notifications that citizens will eventually begin to ignore, thereby undermining the very idea of oversight. The Cabinet of Ministers will have to develop very clear subordinate regulations that distinguish significant access events from routine technical operations.
Third (and this is the most critical legal risk), the draft law in its current version does not provide for any exceptions. This creates a direct conflict with legislation on operational-investigative and counterintelligence activities, as well as with the Criminal Procedure Code. If a law enforcement agency gains access to an individual’s data as part of covert investigative (search) operations, notifying that individual within five days would directly contradict the purpose of the covert investigation and could lead to its failure.
Thus, the draft law is conceptually sound and a necessary step toward building a transparent digital state, however, it requires substantial refinement in terms of defining clear implementation mechanisms and, most importantly, establishing an exhaustive list of exceptions for the purposes of national security, defense, and justice.
Author: Ruslan Gutsol, Barrister
Source: https://pravo.ua/perevahy-ta-ryzyky-zaproponovanykh-zmin-do-zakonu-pro-publichni-elektronni-reiestry-analiz-zakonoproiektu-14118/