The issue of personal data protection in Ukraine is becoming increasingly important both for our country and for businesses focused on cooperation with the European Union. Given the ever-increasing volume of cross-border information exchange, aligning national legislation with EU standards is not only a matter of legal sovereignty but also a key factor in Ukraine’s digital integration into the European space. However, despite numerous steps taken to align with the EU, Ukraine has yet to receive an adequacy decision confirming that its personal data protection regime meets European requirements. What are the reasons for this? Let’s try to figure it out.

Lack of an Adequacy Decision Under the GDPR

As of 2025, Ukraine is not included in the list of countries that the European Commission has recognized as providing an adequate level of personal data protection in accordance with Article 45 of Regulation (EU) 2016/679 (GDPR). This means that the transfer of personal data from EU countries to Ukraine may take place only if additional legal safeguards are in place, such as Standard Contractual Clauses or the results of a Data Transfer Impact Assessment.

In effect, this situation puts Ukrainian data recipients at a disadvantage, as each transfer requires additional effort and costs. At the same time, EU companies may refuse to cooperate with Ukrainian partners precisely because of the lack of an adequacy decision, in order to avoid regulatory risks and potential sanctions. This also creates barriers to the integration of Ukrainian technology companies into European digital markets.

Systemic Shortcomings in the Regulatory and Institutional Environment

Legal regulation of personal data protection in Ukraine is based on the 2010 Law of Ukraine “On the Protection of Personal Data,” which was drafted based on Directive 95/46/EC, which is no longer in force. Although Draft Law No. 8153 was developed in 2022–2024 to implement the provisions of the GDPR, at the time of writing, the new legislation had not yet entered into force. At the institutional level, supervisory functions remain with the Verkhovna Rada Commissioner for Human Rights, who is not a specialized data protection authority, which contradicts the requirements for an independent supervisory authority established by the GDPR.

These regulatory gaps indicate a delay in data protection reforms, which not only hinders Ukraine’s integration into digital Europe but also leaves citizens’ personal data inadequately protected. The lack of a specialized supervisory authority also hinders effective monitoring and oversight of personal data processing, thereby making it impossible to ensure the principle of accountability on which the GDPR is based. In the future, the adoption of an updated law and the establishment of an independent authority are mandatory prerequisites for advancing to the status of an “adequate country.”

In recent years, Ukraine has received international technical assistance to modernize its personal data protection system. In particular, the EU4DigitalUA project, funded by the European Union with a total budget of 10 million euros, provided expert support in drafting Bill No. 8153 “On the Protection of Personal Data,” which was adopted in its first reading by the Verkhovna Rada in November 2024. Also in 2017, the Twinning Ombudsman project, with a budget of 1.5 million euros, was implemented with the aim of bringing Ukrainian legislation into line with international standards. However, despite the availability of funding and the participation of qualified experts, the effectiveness of such initiatives remains limited. Without political will, effective oversight of the implementation of regulations, and robust accountability mechanisms, even the best international practices do not lead to sustainable change.

Practical Implications for Cross-Border Data Transfers and Citizens’ Rights

The lack of “adequate country” status significantly complicates the lawful transfer of personal data from the EU to Ukraine for businesses working with European counterparties. This requires the implementation of additional contractual mechanisms and risk management procedures for data transfers, which increases the administrative burden and reduces investment attractiveness. For citizens, this means a lack of full legal safeguards for personal data protection comparable to European standards, especially under the legal regime of martial law, which allows for restrictions on a number of rights and freedoms.

In wartime, the issue of personal data protection becomes even more acute, as it concerns not only privacy but also security. The lack of effective control over access to data and limited accountability of government authorities can lead to abuses, which are perceived as particularly painful in a society under constant stress. Under such conditions, the state should, on the contrary, demonstrate a higher level of transparency and protection of personal data as a guarantee of citizens’ trust.

The Role of Case Law in Shaping Standards for Personal Data Protection

Case law is a crucial element in the development of the legal framework for personal data protection, as it allows for the clarification of legislative provisions and the establishment of consistent approaches to their application. Both in European Union countries and in Ukraine, courts are increasingly hearing cases related to violations of citizens’ digital rights.

On July 10, 2023, the European Commission adopted a new adequacy decision regarding the United States, recognizing the level of personal data protection provided in that country as adequate in relation to the level guaranteed in the European Union. This is the third adequacy decision adopted following the landmark ruling by the Court of Justice of the European Union in the Schrems case (2020), which invalidated the previous adequacy decision regarding the United States. The new decision has the potential to provide some legal certainty for personal data controllers, particularly with regard to transatlantic data transfers.

A corresponding body of case law is also developing in Ukraine. For example, in a Supreme Court ruling dated October 21, 2021, in Case No. 826/10446/16, a violation of the right to privacy was established due to the unlawful disclosure of personal data without the individual’s consent. In Case No. 640/3230/20 (ruling dated March 2, 2023), the Court required a government agency to justify the lawfulness of processing personal data, even when performing public functions.

These precedents indicate the gradual development of a practice for protecting digital rights in Ukraine; however, the current fragmentation and lack of alignment with European standards leave room for further development.

Prerequisites for Further Alignment with European Standards

For Ukraine to obtain the status of a country with an adequate level of personal data protection, the following are necessary:

  • the adoption and implementation of new legislation that meets the key requirements of the GDPR;
  • the establishment of an independent, specialized supervisory authority with sufficient powers and resources;
  • ensuring effective enforcement of the law, as well as judicial and administrative protection of the rights of data subjects;
  • implementation of a national policy to raise awareness and foster a culture of compliance in the field of personal data protection.

All of these points effectively outline a roadmap that will enable Ukraine to align with European standards in the areas of privacy and digital rights. First and foremost, a new law must be adopted that takes into account not only the literal requirements of the GDPR but also the spirit of this system—a focus on human rights, transparency, and trust in institutions. This law must not merely “comply formally” but become a genuine foundation for a qualitative change in the practice of handling personal data in Ukraine.

The creation of an independent supervisory authority is no less important. This is not just about a new title, but about a body that will have real leverage, qualified specialists, and authority. Without this, even the best law will remain merely declarative. There must also be a clear and accessible system for protecting rights—both through administrative and judicial channels. People must know where to turn when their data has been used unlawfully and have a real chance to protect their rights.

Last but not least is public education. If citizens do not understand why personal data needs to be protected in the first place, they will not demand that their rights be respected. Therefore, government policy must include information campaigns, educational programs, and support for civil society initiatives—everything that helps foster a new culture of digital security. Without active public participation, no formal changes will work in practice.

Conclusion

Ukraine’s status as a country with an inadequate level of personal data protection complicates its international legal cooperation in the digital sphere, hinders its integration into the European digital market, and reduces the competitiveness of Ukrainian businesses. To overcome this barrier, a comprehensive overhaul of the regulatory framework is needed, along with the creation of an independent supervisory authority and the consistent implementation of policies for legal education and technical modernization. Obtaining an adequacy decision from the European Commission should be a strategic goal of state policy in the field of personal data protection.

This issue is not purely technical or bureaucratic. It directly affects the country’s ability to participate in digital value chains, foster innovation, and attract investment in the IT and digital services sectors. In a globalized world, trust in how a country handles personal data is one of the markers of its legal maturity, transparency, and predictability.

For Ukraine, which aspires to full integration into the European Union, achieving the status of an “adequate” country is not merely a technical requirement, but a litmus test of genuine commitment to the principles of the rule of law and respect for human rights in the digital age. The path to this status will not be easy, but a clear strategy, political will, and cross-sectoral cooperation can make it a reality.




Author: Oleksiy Shevchuk, attorney and partner at Barristers, and Yulia Belova, PhD and attorney at Barristers, LLC

Source: https://pravo.ua/problemy-vyznannia-ukrainy-krainoiu-z-neadekvatnym-rivnem-zakhystu-personalnykh-danykh/

Write us

You need a consultation — contact us

I accept privacy policy