Ukraine Law on Personal Data Protection (Law No. 2297-VI)
Ukraine's Law on Personal Data Protection (Law No. 2297-VI of 2010) establishes the framework for personal data processing. The Ukrainian Parliament Commissioner for Human Rights oversees data protection. Ukraine committed to aligning its data protection framework with EU GDPR as part of its EU accession process. A new draft law aligning with GDPR was under development. The current law establishes basic processing principles, consent requirements, and data subject rights.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (25)
Automated Processing
| Code | Title |
|---|---|
| UA-PDP-19 | Automated Decision-Making and Profiling Safeguards |
Awareness
| Code | Title |
|---|---|
| UA-PDP-18 | Staff Confidentiality and Authorisation |
Breach Management
| Code | Title |
|---|---|
| UA-PDP-09 | Breach Response and Notification |
Children's Data
| Code | Title |
|---|---|
| UA-PDP-20 | Children's Personal Data Protection |
Complaints
| Code | Title |
|---|---|
| UA-PDP-17 | Complaints Handling by Data Subjects |
Consent
| Code | Title |
|---|---|
| UA-PDP-02 | Consent of the Data Subject |
Data Subject Rights
| Code | Title |
|---|---|
| UA-PDP-04 | Data Subject Rights of Access and Rectification |
| UA-PDP-05 | Rights of Objection, Erasure and Restriction |
Documentation
| Code | Title |
|---|---|
| UA-PDP-12 | Records and Inventories of Processing |
Governance
| Code | Title |
|---|---|
| UA-PDP-07 | Personal Data Protection Officer or Responsible Person |
International Transfers
| Code | Title |
|---|---|
| UA-PDP-10 | Cross-Border Transfer of Personal Data |
Lawful Processing
| Code | Title |
|---|---|
| UA-PDP-01 | Lawful Basis for Processing Personal Data |
Marketing
| Code | Title |
|---|---|
| UA-PDP-14 | Direct Marketing and Communications |
Regulatory Engagement
| Code | Title |
|---|---|
| UA-PDP-16 | Cooperation with the Ombudsperson |
Retention
| Code | Title |
|---|---|
| UA-PDP-13 | Retention and Deletion of Personal Data |
Risk Management
| Code | Title |
|---|---|
| UA-PDP-15 | Data Protection Impact Assessments for High-Risk Processing |
Section I - General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
Section II - Rights and Obligations
| Code | Title |
|---|---|
| Art. 10 | Data and Data Governance |
| Art. 6 | Writing |
| Art. 7 | Minimum Standards |
| Art. 8 | Compliance with the Requirements |
| Art. 9 | Risk Management System |
Section III - Registration and Notification
| Code | Title |
|---|---|
| Art. 11 | Technical Documentation |
| Art. 12 | Record-Keeping |
| Art. 13 | Transparency and Provision of Information to Deployers |
Section IV - Data Security
| Code | Title |
|---|---|
| Art. 14 | Human Oversight |
| Art. 15 | Accuracy, Robustness and Cybersecurity |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
Section V - Supervisory Authority
| Code | Title |
|---|---|
| Art. 22 | Authorised Representatives of Providers of High-Risk AI Systems |
| Art. 23 | Transitional Provisions |
Section VI - Liability and Final Provisions
| Code | Title |
|---|---|
| Art. 28 | Notifying Authorities |
| Art. 29 | Application of a Conformity Assessment Body for Notification |
| Art. 30 | Privacy Policy |
Security
| Code | Title |
|---|---|
| UA-PDP-08 | Security of Personal Data |
Sensitive Data
| Code | Title |
|---|---|
| UA-PDP-06 | Sensitive Data Processing Conditions |
Third Party Management
| Code | Title |
|---|---|
| UA-PDP-11 | Processor Engagement and Contracts |
Transparency
| Code | Title |
|---|---|
| UA-PDP-03 | Notification to Data Subjects |
Your Compliance Coverage
If you comply with Ukraine Law on Personal Data Protection (Law No. 2297-VI), you already cover:
EU AI Act
29%
12 controls mapped
Compare →BS 65000:2014 — Guidance on Organizational Resilience
29%
12 controls mapped
Compare →ILO Nursing Personnel Convention C149 (1977)
27%
11 controls mapped
Compare →+ 605 more: 6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673) (27%), ISO 8000 — Data Quality (27%)
See all 608 mapped frameworks ↓Maps to 608 other frameworks
Frequently Asked Questions
What is Ukraine Law on Personal Data Protection (Law No. 2297-VI)?
Ukraine Law on Personal Data Protection (Law No. 2297-VI) is a compliance framework from Ukraine with 25 domains and 41 controls. Ukraine's Law on Personal Data Protection (Law No. 2297-VI of 2010) establishes the framework for personal data processing. The Ukrainian Parliament Commissioner for Human Rights oversees data protection. Ukraine committed to aligning its data protection framework with EU GDPR as part of its EU accession process. A new draft law aligning with GDPR was under development. The current law establishes basic processing principles, consent requirements, and data subject rights. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Ukraine Law on Personal Data Protection (Law No. 2297-VI) have?
Ukraine Law on Personal Data Protection (Law No. 2297-VI) has 41 controls organised across 25 domains. The largest domains are Section I - General Provisions (5 controls), Section II - Rights and Obligations (5 controls), Section III - Registration and Notification (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Ukraine Law on Personal Data Protection (Law No. 2297-VI) map to?
Ukraine Law on Personal Data Protection (Law No. 2297-VI) maps to 608 other compliance frameworks. The top mapping partners are EU AI Act (29% coverage), BS 65000:2014 — Guidance on Organizational Resilience (29% coverage), ILO Nursing Personnel Convention C149 (1977) (27% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Ukraine Law on Personal Data Protection (Law No. 2297-VI) compliance?
Start your Ukraine Law on Personal Data Protection (Law No. 2297-VI) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Ukraine Law on Personal Data Protection (Law No. 2297-VI) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 41 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required