Expert View 7 min read

GDPR compliance and data strategies for Ukrainian IT during wartime

The Ukrainian IT industry, despite the challenges of full-scale war, continues to demonstrate resilience and growth, largely due to cooperation with international partners, especially from the European Union. However, this cooperation requires not only technological excellence…

The Ukrainian IT industry, despite the challenges of full-scale war, continues to demonstrate resilience and growth, largely due to cooperation with international partners, especially from the European Union. However, this cooperation requires not only technological excellence, but also impeccable compliance with strict regulatory requirements, primarily the General Data Protection Regulation (GDPR). The unique context, which combines GDPR requirements with Ukraine's martial law, creates a complex landscape for managing the personal data of EU clients. This article analyzes key legal risks and offers practical strategies for Ukrainian IT companies seeking to ensure compliance, minimize fines, and maintain the trust of European partners during these unconventional times.

Conflict of jurisdictions: Ukrainian legislation vs. GDPR under martial law

GDPR establishes high standards for the processing of personal data concerning EU citizens or residents, regardless of the processor's location. Its key principles—lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality—are cornerstones for any company working with EU data. Ukrainian legislation, in particular the Law of Ukraine "On Personal Data Protection," also provides for data protection, but there are discrepancies that are exacerbated under martial law.

One of the greatest potential contradictions is access to data by government authorities. During martial law, Ukrainian legislation may provide for expanded powers for law enforcement and military agencies to access information, including personal data, for the purpose of ensuring national security. This may conflict with GDPR requirements regarding the lawfulness of processing, necessity, and proportionality, as well as restrictions on cross-border data transfers to third countries that do not have an "adequate" level of protection. Specifics of data processing in cloud services, where physical servers may be located outside of Ukraine but accessed from within the country, also create additional challenges. Product companies and startups that process significant volumes of data from European users must carefully assess these risks and provide for protection mechanisms that comply with both jurisdictions while maintaining the ability to respond to requests from Ukrainian authorities within the framework of the law.

European DPA practice: cases and lessons for Ukrainian business

European Data Protection Authorities (DPAs) actively monitor compliance with GDPR, especially in the area of cross-border data transfers. Rulings such as Schrems II highlighted the need for additional measures when transferring data to third countries that do not have an adequacy decision. DPAs require companies not only to rely on Standard Contractual Clauses (SCCs) but also to conduct their own Transfer Impact Assessments and implement additional technical and organizational measures.

Although there are no direct DPA precedents concerning the circumstances of martial law in third countries, the general trend indicates a tightening of requirements for accountability and transparency. For example, in 2023, the total amount of fines for GDPR violations exceeded 1.7 billion euros, which demonstrates the seriousness of the regulators' approach. For Ukrainian software exporters, this means that citing force majeure circumstances may not be a sufficient excuse for violating data protection principles. Instead, it is necessary to demonstrate proactivity in minimizing risks, strengthening cybersecurity, and developing clear internal compliance policies that take into account both GDPR requirements and the realities of doing business during the war. This includes ensuring infrastructure resilience, incident recovery plans, and regular audits of data protection systems.

Compliance strategies for B2B SaaS during martial law

For Ukrainian B2B SaaS companies working with EU data, ensuring GDPR compliance during martial law requires a comprehensive approach. The first step is to review and adapt privacy policies and Data Processing Agreements (DPAs) with clients. These documents should clearly reflect the current risks associated with martial law and describe the measures taken to minimize them. It is also important to ensure that all subcontractors processing data on behalf of the Ukrainian company also adhere to high protection standards.

Data Protection Impact Assessment (DPIA) becomes even more critical. Companies should regularly conduct DPIAs for data processing operations that present high risk, considering potential threats such as cyberattacks, physical damage to infrastructure, or loss of access to data. Enhanced cybersecurity measures are absolutely essential: the use of robust encryption for data at rest and in transit, multi-factor authentication, regular data backups in geographically distributed and secure locations (preferably in the EU), and strict access control to personal data.

To ensure the legitimacy of cross-border data transfers to Ukraine, companies should actively use Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs), if possible. These mechanisms require the data exporter to implement additional safeguards. For example, a Ukrainian SaaS company that uses cloud services located in the EU but processes data from Ukraine must have clear policies for access, monitoring, and incident response. More than 60% of Ukrainian IT companies focused on exports have already implemented or are in the process of implementing international cybersecurity standards, such as ISO 27001. This certification serves as a powerful tool for demonstrating compliance and increasing the trust of European partners, confirming proper information security management.

According to Anton Marrero, the integration of enhanced cybersecurity measures and regular review of data processing agreements is an integral part of operational resilience. Ukrainian companies are demonstrating an impressive ability to adapt, but proactive GDPR compliance is key to minimizing risks and maintaining a reputation on the international stage.

Government policy and prospects for harmonization

The Ukrainian government, recognizing the importance of integration into the European digital market, is actively working on harmonizing national data protection legislation with GDPR. The Ministry of Digital Transformation and the State Service of Special Communications and Information Protection are initiating reforms aimed at adapting Ukrainian norms to European standards.

Further alignment of Ukrainian legislation with European requirements will have a significant positive impact on Ukrainian business. It will not only simplify interaction with European partners but also increase trust in Ukrainian companies as reliable data processors. Ukraine's strategic goal remains to obtain an adequacy decision from the European Commission. Such a decision would confirm that Ukraine provides an adequate level of personal data protection, which would allow for the free transfer of data from the EU without the need for additional mechanisms, such as SCCs.

Further steps toward harmonization could significantly bring Ukraine closer to deeper integration into the European digital space. This would be a powerful stimulus for software exports, the country's technological resilience, and the strengthening of the position of Ukrainian IT companies in the EU market.

Frequently asked questions

What is GDPR and why is it important for Ukrainian companies?

GDPR (General Data Protection Regulation) is an EU law that regulates the protection of personal data of EU citizens. It is important for Ukrainian companies that process data of EU clients because violations of the regulation can lead to significant fines and loss of trust from European partners.

How does martial law in Ukraine affect compliance with GDPR requirements?

Martial law can create difficulties due to potential conflicts with national legislation (e.g., access to data for law enforcement agencies) and operational risks (cybersecurity, physical security of infrastructure). This requires increased attention to risk management and the adaptation of compliance procedures.

What are the main risks for Ukrainian B2B SaaS companies in the context of GDPR during the war?

The main risks are non-compliance with requirements for cross-border data transfers, insufficient cybersecurity measures, and the absence of updated privacy policies and data processing agreements. This can lead to DPA investigations and significant financial sanctions.

What can Ukrainian companies do to minimize GDPR risks?

Companies should conduct an audit of their data processing operations, update policies and agreements, implement enhanced cybersecurity measures, use Standard Contractual Clauses (SCCs) for data transfers, and consider obtaining relevant certifications.