Ukrainian Company Without an EU Office: When GDPR Applies and What to Check Before Your First European Client

Protection of personal data in accordance
4.9
Based on 700 reviews in Google

Reviews of our Clients

A typical scenario: a Ukrainian IT company or SaaS provider reaches an agreement with a client from the EU. Prior to contract execution, the counterparty requests a DPA, a list of sub-processors, a description of security measures, data retention and deletion policies, and clarification regarding the legal basis for transferring data to Ukraine. It is precisely at this stage that the company discovers that, despite having standalone policies, it lacks an understanding of which GDPR requirements genuinely apply to its business model.

For the business, the risk extends beyond potential liability for non-compliance. Unpreparedness can delay contract execution, force the team to urgently rewrite documentation, or result in accepting obligations that the product cannot technically fulfill.



This text is being translated.

Publication date: 07/09/2026


Our clients



We are ready to help you!

Contact us by mail [email protected] or by filling out the form:
Edgar Simonyan

About author

Name: Edgar Simonyan

Position: Lead / Senior Attorney & Practice Development Lead

Education: Master’s Degree, East European University of Economics and Management

Knowledge of languages: Ukrainian, Russian, Armenian, English, Spanish

Email: [email protected]

Write to the author

Our other authors

Volodymyr Gurlov
Strategic Advisor
Marina Losenko
Associate
Edgar Simonyan
Lead / Senior Attorney & Practice Development Lead