Ukraine Ombudsman Data Protection Inspection: What Businesses Must Show
Reviews of our Clients
... our work on joint projects assured us of your high level of professionalism
Imagine this scenario: the Secretariat of the Ukrainian Parliament Commissioner for Human Rights contacts your company remotely and asks you to provide documents related to the processing of personal data. You have a privacy policy on your website — and nothing beyond that. A few weeks later, you receive an inspection report and a compliance order: there is no internal data processing procedure, no access log, and no one in the company knows what to do in the event of a data breach.
A telling example is a scheduled remote inspection of a municipal enterprise announced by the Commissioner’s Secretariat in March 2025. The inspection resulted in a formal report and a compliance order. The violations identified included the absence of an internal document governing personal data processing, inadequate notification of individuals, insufficiently regulated employee access, and the lack of an operations log, a data deletion procedure, and an incident response plan.
The problem is that most companies prepare for the wrong kind of inspection. They assume that the main requirement is to collect customer consents and publish a privacy policy on the website.
This text is being translated.
Our clients







