The Bill Kyiv Can't Pass
On July 23, 2026, the Institute of International Relations at Taras Shevchenko National University convened lawmakers, business representatives, and data protection experts in Kyiv to ask why Ukraine still doesn't have a modern privacy law. The round table, organized with the Secretariat of the Verkhovna Rada's Human Rights Commissioner and the UNESCO "Information for All" national committee, centered on two bills: Draft Law No. 8153, "On Personal Data Protection," and Draft Law No. 6177, which would create an independent National Commission for Personal Data Protection and Access to Public Information. Panelist Oleksandr Shevchuk told the room that aligning Ukrainian law with EU standards on data protection, cybersecurity, AI, and digital services is essential groundwork for EU integration.
The timeline explains the urgency. Draft Law 8153 was registered on October 25, 2022, cleared its first reading on November 20, 2024, and has sat awaiting a second reading ever since — nearly four years from introduction with no enacted statute. Draft Law 6177, which would replace the Parliamentary Commissioner for Human Rights as data protection regulator with a dedicated, independent commission, has moved even more slowly since its October 2021 registration. Ukraine is still governed by a 2010 data protection law that predates the GDPR entirely.
What EU Accession Actually Requires
Ukraine is not free to leave this indefinitely. On June 15, 2026, the European Commission and Ukraine opened negotiations on the accession process's first "fundamentals" cluster, which bundles five chapters — including Chapter 23, Judiciary and Fundamental Rights, where data protection sits within the EU's broader human-rights acquis. The Commission has set interim benchmarks specific to the rule-of-law chapters (23 and 24) that Ukraine must clear before those chapters can be provisionally closed. A GDPR-equivalent statute and a functioning independent regulator are not optional extras layered onto accession; they are load-bearing pieces of the fundamentals cluster Ukraine just opened.
There's a second, separate prize at stake beyond membership itself: a formal EU adequacy decision under GDPR Article 45, which would let personal data flow between Ukrainian and EU companies without contract-by-contract safeguards. The European Commission's own criteria for adequacy require a country to have an independent supervisory authority with genuine investigative and enforcement powers, free of political interference — precisely what Draft Law 6177 is designed to establish, and precisely what does not yet exist. A statute without an empowered regulator behind it satisfies neither Chapter 23 nor an adequacy application.
Steelmanning the Slow Road
There's a real case for caution here, and it deserves stating plainly. Ukraine is legislating a comprehensive data protection regime, complete with 72-hour breach notification and penalties reaching 8% of annual turnover, in the middle of a full-scale war — while simultaneously running population registries, war-crimes documentation, and internally displaced persons databases at wartime scale and under wartime risk. Getting the balance between citizen protection and administrative capacity wrong, in either direction, has real consequences: rushed rules could criminalize routine wartime data-sharing between ministries, while a captured or underfunded regulator would be worse than no regulator at all, since it forces Ukrainian firms to build to a GDPR-standard cost base without a genuine enforcement or adequacy payoff. Careful drafting and sequencing are not the same as delay for its own sake.
The Proportionate Alternative
But four years of first-reading purgatory isn't careful sequencing — it's institutional drift, and it comes with a cost that compounds. Every year without Draft Law 6177's commission is a year Ukrainian exporters transact with EU counterparts on the EU's terms rather than under mutual adequacy, and a year further from provisional closure on Chapter 23. The fix is not to write a more elaborate statute; both bills are already substantively GDPR-aligned, according to the Council of Europe's own technical input during drafting. The fix is to pass what's drafted, fund the commission Draft Law 6177 creates, and let it spend its first year on the boring, unglamorous work — hiring, procedure, guidance — before enforcement teeth activate, exactly as the bill's own transition design anticipates.
Worth noting for contrast: Ukraine isn't the only jurisdiction writing cross-border data rules this year. ASEAN concluded negotiations on its Digital Economy Framework Agreement in late May 2026 and is targeting a signature at the November 2026 ASEAN Summit — a lighter-touch, trade-facilitation model for cross-border data flows rather than the EU's rights-based adequacy architecture. That's a legitimate alternative design philosophy for regions without a single dominant trade partner to align with. Ukraine doesn't have that luxury, or that choice: its accession path runs through Brussels, and Brussels' bar is the GDPR standard, not a softer regional compromise. Given that reality, slow-walking a law that is already substantively drafted doesn't buy Ukraine flexibility — it just buys delay.
The pro-innovation case here isn't opposition to data protection; it's that a credible, independent regulator with clear enforcement rules is itself pro-business, because it's the only thing standing between Ukrainian companies and permanent second-class access to the EU's data economy. Kyiv should pass both bills, fund the commission properly, and stop letting institutional inertia masquerade as prudence.