Ukraine cross-border data flows

Ukraine's Real Data-Flow Risk Is Device Compromise, So Its Transfer Rules Should Target Security, Not Borders

Russian mobile malware moves Ukrainian data to adversary servers without consent. Data-transfer and residency policy should be built around that threat.

Ukraine's Mobile Threat and Data-Law Snapshot People of Internet Research · Ukraine 3,137 CERT-UA incidents, H1 2026 Incidents logged in the first half… +8% Rise over prior half-year Increase in CERT-UA incidents. Nov 2024 Draft Law 8153 adopted as basis Still awaiting second reading as o… peopleofinternet.com
Ukraine's Mobile Threat and Data-Law S… People of Internet Research · Ukraine 3,137 CERT-UA incidents, H1 20… +8% Rise over prior half-year Nov 2024 Draft Law 8153 adopted as basis peopleofinternet.com

Key Takeaways

Ukraine's State Service of Special Communications and Information Protection (SSSCIP) warned this week that Russian operators are increasingly targeting the smartphones of military personnel, government officials and civilians. According to The Record's report on the SSSCIP findings, the toolset includes DarkSword, an iPhone exploit kit delivered through compromised news and government websites. Once a phone is infected, the operators can steal credentials, messages, contacts and call histories within minutes. On Android, the campaigns tracked as UAC-0244 (CamelSpy) and UAC-0263 (BTMOB) used decoy sites impersonating a Ukrainian army corps, air-raid alert apps and fuel-discount apps. CERT-UA logged 3,137 incidents in the first half of 2026, up 8% on the prior six months.

This is a data-flow story as much as a malware story. Every exfiltrated contact list is a cross-border transfer that no data subject consented to and no regulator authorised. It also exposes a gap in how Ukraine, and most countries, frame transfer policy.

The case for tighter borders

The strongest argument for restricting transfers or mandating residency runs as follows. Data held abroad is harder to protect and harder to recall, and a state at war has legitimate reason to keep sensitive records under its own jurisdiction. If adversaries are systematically pulling data off Ukrainian devices, a rule that keeps data at home looks like a sensible defence. That instinct deserves respect.

It also fails on the facts of this threat. DarkSword and CamelSpy do not go through any transfer channel that a residency law could regulate. They compromise the endpoint, and the data leaves the device regardless of where the organisation's servers sit. A residency mandate would not have stopped a single incident described in the SSSCIP warning. It would, however, add compliance cost to the companies and agencies least able to bear it.

Ukraine's own wartime record argues the other way

Ukraine's experience since 2022 points toward geographic diversification. After the full-scale invasion began, the government pushed its critical data into cloud infrastructure. The Cabinet's January 2024 decision expanding the Ministry of Digital Transformation's powers over cloud services states the rationale plainly: after the invasion, "the most important data is in cloud storage," and Russian attempts to destroy archives did not cause a collapse. The Ministry shapes cloud policy and the SSSCIP acts as regulator. The underlying law, signed in March 2022, was presented as letting state bodies store data in the cloud. The lesson is that resilience came from moving data beyond the reach of Russian missiles and intrusions, not from keeping it in one place.

A strict residency rule would put that lesson at risk. Data stored only on Ukrainian soil is exposed to kinetic strikes, physical seizure and the same network intrusions that CERT-UA tracks daily. Residency should remain a risk-based choice: sovereign or in-country hosting for a narrow class of data, and trusted foreign cloud regions for the rest.

The transfer regime that does need fixing

The more pressing problem is the legal framework for lawful transfers. Under the 2010 Law on Personal Data Protection, as summarised by DLA Piper, transfers are allowed to countries providing an "appropriate level of protection" and otherwise depend on grounds such as consent or contract necessity. Ukraine, in turn, is not on the European Commission's list of adequacy decisions. Adequacy is the mechanism in Article 45 of the GDPR that lets EU personal data flow freely to a recognised country. Without it, Ukrainian firms handling EU customer data face added friction, and the country's IT services sector pays for it.

Draft Law No. 8153, submitted on 25 October 2022 to align Ukraine with the GDPR and Convention 108+, was adopted as a basis on 20 November 2024 and was awaiting a second reading as of that summary. Ukraine should finish it. A modern law with clear transfer tools, an independent supervisor and enforceable accountability rules serves two purposes: it moves Ukraine toward EU adequacy, and it gives regulators a lawful basis for going after the actors who mishandle data.

What proportionate policy looks like

The SSSCIP findings suggest three priorities.

The bottom line

Involuntary data flows are a real and growing cost of the war. But the data leaving Ukrainian phones is leaving through the endpoint, not through a policy gap in transfer law. Data localisation would cost Ukraine's economy and resilience while leaving the DarkSword problem untouched. A better response is to invest in device security, tier data by sensitivity, and pass the data protection law that would bring Ukraine closer to the EU's adequacy list. That protects citizens and preserves the open, cloud-enabled digital state that has served Ukraine well since 2022.

Sources & Citations

  1. The Record: Mobile malware warning from Ukrainian researchers
  2. Cabinet of Ministers of Ukraine: cloud services and new Ministry of Digital Transformation powers
  3. European Commission: Adequacy decisions
  4. Kyiv Independent: Zelensky signs law on cloud services
  5. DLA Piper: Data Protection in Ukraine