УКР | ENG
logo
  • About
  • Projects
    • Compensation for Damages Caused by Russia’s Military Aggression
    • Security Agreements of Ukraine
    • Artificial intelligence and justice
    • Post-War Reconstruction
    • Others
  • Team
  • Contacts
  • Dnistrianskyi Center
  • /
  • Updates
  • /
  • Personal Data Protection and AI: Draft Law No. 8153, the GDPR, and the EU AI Act in the Context of Artificial Intelligence Technologies

January 15, 2025

Personal Data Protection and AI: Draft Law No. 8153, the GDPR, and the EU AI Act in the Context of Artificial Intelligence Technologies

Author: Daryna Boyko

The White Paper on the Regulation of Artificial Intelligence (AI) in Ukraine highlights the relevance of existing Ukrainian legislation, particularly the Law of Ukraine “On the Protection of Personal Data,” to the regulation of AI. However, the provisions of the current law are insufficient to adequately address the use of AI, especially in the context of data protection. Notably, there are no clear standards governing liability in cases of confidentiality breaches or unauthorized access to personal information through the use of AI.

Draft Law No. 8153, “On the Protection of Personal Data” (hereinafter – Data Protection Draft Law) adopted in its first reading by the Verkhovna Rada (Ukrainian Parliament), introduces broader rules for the automated processing of personal data, modeled after the EU General Data Protection Regulation (hereinafter referred to as the GDPR). This Data Protection Draft Law has the potential to directly regulate AI technologies. In this context, it is crucial to assess how the proposed legislation may impact the use of AI systems for automated personal data processing in Ukraine and its alignment with European legislation, particularly regarding AI regulation.

Harmonization of Ukrainian Legislation with EU Regulation

The Data Protection Draft Law, introduces new rules regarding the regulation of personal data processing, particularly automated processing.

According to the explanatory note accompanying the draft law, the current Ukrainian legislation fails to adequately address legal relations arising from technological advancements. These outdated provisions create barriers to the adoption of “innovative solutions” in both the private and public sectors. Consequently, the tools for automated processing of personal data that fall under this regulation may include, among other things, AI technologies.

The draft law also aims to implement provisions of the General Data Protection Regulation (GDPR), aligning Ukrainian legislation with EU standards. This alignment is both logical and anticipated within the broader context of European integration.

The GDPR, which came into force on May 25, 2018, imposes strict obligations on organizations that process the personal data of citizens and residents of EU member states.

In addition, the EU AI Act, which entered into force on August 1, 2024, includes provisions that regulate the use of artificial intelligence in the processing of personal data. According to Article 2 of the Act, its provisions do not interfere with the operation of the GDPR. However, recognizing that the development and use of AI systems inherently involve the processing of personal data, the Act aims to establish “harmonized rules” to safeguard the rights of data subjects.

The EU AI Act imposes obligations on various entities, including developers, providers, and users of AI systems. These entities may also act as controllers (referred to as "volodil`tsi" under current Ukrainian terminology) or operators („rozporyadnyky”) if they process personal data during AI development, handle data of personal data subjects, or use AI systems to process personal data.

 

Profiling 

While the Data Protection Draft Law does not introduce standards specifically for AI, it does propose new concepts for the automated processing of personal data. Notably, it introduces the term “profiling,” which involves automated data processing to analyze the individual characteristics of personal data subjects.

The draft law defines profiling as “a form of automated processing of personal data consisting of evaluating certain individual characteristics, particularly analyzing and predicting behavior patterns (models), professional activity, financial situation, health, personal preferences, interests, reliability, location, or movements of the personal data subject.” This definition aligns with that of the GDPR.

The EU AI Act also incorporates the GDPR's definition of profiling but adds specific prohibitions and restrictions on certain AI practices related to profiling. For instance, it prohibits the use of AI for assessing or predicting the likelihood of a natural person committing a criminal offense based on profiling.

Additionally, AI systems performing profiling in critical sectors—such as infrastructure, education, employment, law enforcement, migration management, and justice—are classified as high-risk systems. Developers of such systems are required to manage data responsibly, verify its relevance, and implement a comprehensive risk management framework.

 

Right to Protection Against Automated Decision-Making 

Article 25 of Data Protection Draft Law grants individuals the right to protection against decisions made solely through automated processing. Under this provision, decisions based solely on automated processing are prohibited, particularly in areas where AI tools are commonly applied, such as predictive analytics and decision-making systems.

In contrast, the GDPR emphasizes profiling as one form of automated decision-making. This distinction is significant, as not all automated decision-making involves profiling. For example, automated classification of data based on certain characteristics for statistical purposes would not qualify as profiling.

Excluding profiling as a form of automated decision-making in the draft law could create regulatory gaps and lead to the misuse of personal data. However, Article 18 of the draft law requires controllers (owners) to disclose the existence of automated decision-making mechanisms, including profiling, when processing personal data. This aligns with Articles 13 and 14 of the GDPR.

The EU AI Act sets additional requirements for automated decision-making and prohibits specific AI applications that:

  • Use manipulative methods to distort behavior or impair decision-making.
  • Classify individuals or groups based on characteristics or behaviors to assign social scores.
  • Use biometric categorization.
  • Infer emotions in employment and education contexts.

Both the EU AI Act and the GDPR emphasize human supervision as a safeguard for protecting personal data during automated decision-making. The GDPR, under Article 25, obliges controllers to implement necessary measures to uphold data protection principles. Similarly, Article 29 of Data Protection Draft Law proposes provisions to ensure personal data protection by controllers.

 

Transparency

The GDPR requires controllers to disclose information about the logic, significance, and foreseeable consequences of automated processing to personal data subjects. Similarly, the Ukrainian draft law obliges controllers to inform data subjects about the algorithms used in automated decision-making, including those employing AI technologies.

Following the GDPR's example, Article 39 of Data Protection Draft Law requires controllers conducting systematic automated analysis of individuals’ personal characteristics -particularly when using profiling - to assess the impact of such processing on individuals' rights and freedoms. Controllers must prepare a conclusion based on this assessment, which should detail the grounds necessary for such processing.

When using AI tools to make automated decisions that have legal or other serious consequences for individuals, data controllers (owners) are required to explain the logic behind these technologies and inform individuals about measures taken to mitigate associated risks.

While the EU AI Act does not impose additional transparency obligations specifically on controllers or processors of personal data, it does establish strict requirements for deploying AI systems. These include maintaining documentation, records, and information that adhere to transparency standards. Additionally, developers are obligated to inform individuals when they are interacting with an AI system.

 

What Does the Adoption of a Draft Law to Regulate AI Mean?

The White Paper on AI Regulation in Ukraine emphasizes a “bottom-up” approach to AI regulation over the next 2–3 years, prioritizing industry self-regulation over the adoption of standalone AI legislation. Under this approach, the Ukrainian government plans to provide tools and recommendations for the responsible development and use of AI systems in alignment with the EU AI Act. This strategy also necessitates leveraging existing legislation in related areas, such as data processing and protection, to guide AI governance.

In this context, the GDPR serves as a foundational framework for enhancing Ukraine’s national legislation on personal data protection. As Ukraine progresses toward European integration, compliance with GDPR standards will become a critical requirement.

Although Data Protection Draft Law proposes many key GDPR principles for automated data processing, it lacks the specificity required for effective application in the context of AI technologies. The GDPR strikes a balance between data protection and fostering innovation but provides only limited, non-specific standards directly applicable to AI. Experts from the European Parliamentary Research Service have noted that the GDPR’s vague provisions and open-ended standards often require balancing competing interests, making it insufficient for the unique challenges posed by AI.

To address these gaps, the EU AI Act introduces expanded rules tailored to the development and use of AI technologies. It categorizes AI systems by risk levels and establishes specific requirements for their regulation—not only during data processing but also in their development and deployment. This creates a more precise and comprehensive framework for AI governance in the EU by focusing on the risks unique to these technologies.

In contrast, Ukraine’s current flexible and adaptive approach to AI regulation falls short of adequately addressing the risks associated with AI, particularly in protecting personal data. Therefore, it is crucial to develop additional norms and standards for AI as part of the ongoing reform of Ukraine’s personal data protection legislation.

 

Conclusions and Recommendations

While Ukraine’s legislative initiatives in personal data protection are a positive step toward establishing basic safeguards amid the rapid development of AI technologies, they are insufficient for comprehensive regulation of this sector. Data Protection Draft Law introduces general principles for personal data processing but fails to address the specific challenges posed by AI technologies.

For effective regulation, separate provisions must be developed to account for the unique aspects of AI development and application. Relying solely on existing personal data protection standards cannot ensure sufficient safeguards when using AI. To align AI standards with Ukrainian legislation, it is necessary to establish clearer and more detailed data protection rules, particularly in the areas of ethics, algorithmic transparency, and oversight of AI use in sensitive sectors. For this purpose, it is advisable to take into account, in particular, the following:

  1. Improvement of certain provisions of the draft law that partially relate to AI. In order to avoid abuse and unfair use of AI technologies, it is necessary, in particular, to clarify certain provisions regarding automated decision-making. It is important to clearly distinguish between different forms of automated decision-making, particularly profiling, which involves predicting and assessing the behavior of individuals, and less risky methods such as statistical analysis or classification. In the context of the use of the use of AI for automated decision-making, clear and understandable wording can help minimize risks to the rights of subjects AI for automated decision-making, clear and understandable wording can help minimize risks to the rights of subjects.
  2. Defining ethical and legal principles for the AI ​​sector. Improving certain provisions of the draft law may not be sufficient to ensure adequate data protection in the development and use of AI. It is important to consider the possibility of creating additional standards that oblige AI developers and users to adhere to the principles of transparency, impartiality, respect for human rights and the prevention of discrimination. In addition, it is necessary to introduce specific requirements for data processing in the context of AI, in particular regarding data security and their anonymization, where possible.
  3. International cooperation in the field of AI regulation. Given that Ukraine plans to implement the EU AI Act at the next stage of regulation, it is necessary to actively cooperate with international partners, especially with EU countries, to adapt practices in the field of AI regulation, as well as to exchange experience in building effective standards in this area. International cooperation will allow the introduction of effective oversight and monitoring mechanisms and ensure the consistency of national legislation with international requirements.

 

 

 

Last updates
  • Strengthening Ukraine’s Defense Capabilities, Building Long-Term Partnership, and Increasing Sanctions Pressure on Russia: Results of the Second Year of Implementing the Ukraine–Canada Security Agreement
    Strengthening Ukraine’s Defense Capabilities, Building Long-Term Partnership, and Increasing Sanctions Pressure on Russia: Results of the Second Year of Implementing the Ukraine–Canada Security Agreement
    June 30, 2026
  • Compensation for Ukraine: Results of the Fourth Year of Work on Establishing Compensation Mechanisms
    Compensation for Ukraine: Results of the Fourth Year of Work on Establishing Compensation Mechanisms
    June 19, 2026
  • Expansion of Defense Industry Cooperation, Pressure on Russia, and Contributions to Ukraine’s Reconstruction: Results of the Second Year of Implementing the Security Agreement with France
    Expansion of Defense Industry Cooperation, Pressure on Russia, and Contributions to Ukraine’s Reconstruction: Results of the Second Year of Implementing the Security Agreement with France
    June 4, 2026
  • Transition to global leadership in supporting Ukraine: results of the second year of implementation of the security agreement with Germany
    Transition to global leadership in supporting Ukraine: results of the second year of implementation of the security agreement with Germany
    April 23, 2026

logo
  • Privacy policy
  • Intellectual property protection policy
  • Support us
  • Contacts

© 2026. Dnistrianskyi Center