Ukraine Ombudsman Data Protection Inspection: What Businesses Must Show

Protection of personal data in accordance
4.9
Based on 700 reviews in Google

Reviews of our Clients

Imagine this scenario: the Secretariat of the Ukrainian Parliament Commissioner for Human Rights contacts your company remotely and asks you to provide documents related to the processing of personal data. You have a privacy policy on your website — and nothing beyond that. A few weeks later, you receive an inspection report and a compliance order: there is no internal data processing procedure, no access log, and no one in the company knows what to do in the event of a data breach.

A telling example is a scheduled remote inspection of a municipal enterprise announced by the Commissioner’s Secretariat in March 2025. The inspection resulted in a formal report and a compliance order. The violations identified included the absence of an internal document governing personal data processing, inadequate notification of individuals, insufficiently regulated employee access, and the lack of an operations log, a data deletion procedure, and an incident response plan.

The problem is that most companies prepare for the wrong kind of inspection. They assume that the main requirement is to collect customer consents and publish a privacy policy on the website.

This text is being translated.

Publication date: 10/09/2026


Our clients



We are ready to help you!

Contact us by mail [email protected] or by filling out the form:
Edgar Simonyan

About author

Name: Edgar Simonyan

Position: Lead / Senior Attorney & Practice Development Lead

Education: Master’s Degree, East European University of Economics and Management

Knowledge of languages: Ukrainian, Russian, Armenian, English, Spanish

Email: [email protected]

Write to the author

Our other authors

Volodymyr Gurlov
Strategic Advisor
Marina Losenko
Associate
Edgar Simonyan
Lead / Senior Attorney & Practice Development Lead