CyberPeople

Ukraine's Law on Information Protection in Information and Telecommunication Systems: A Full Breakdown

Ukraine's Law on Information Protection in Information and Telecommunication Systems

Ukraine's Law No. 80/94-VR on information protection in information and telecommunication systems: KSI, security authorization, and Derzhspetszviazok requirements.

Ukraine's law on information protection in information and telecommunication systems is the foundational legal act that for over three decades has defined how the state and business must protect data processed in computer, telecommunication, and information-telecommunication systems. Its official name is the Law of Ukraine "On Information Protection in Information and Telecommunication Systems" No. 80/94-VR, adopted on July 5, 1994, and published in the Bulletin of the Verkhovna Rada of Ukraine (1994, No. 31, Art. 286).

Over three decades the document has gone through several major revisions. In 2005 it was set out in a new wording (Law No. 2594-IV of May 31, 2005), which took effect on January 1, 2006. After the 2020 electronic-communications reform, the title was clarified — officially the document is now called "On Information Protection in Information and Communication Systems." And in 2025 the law was substantially updated again: a "security authorization" mechanism and security profiles appeared, gradually replacing the classic attestation of the comprehensive information protection system.

In this article we break down what exactly the law regulates, whom it addresses, what a comprehensive information protection system (KSI) is, how the new security authorization works, and what practical steps are needed to comply.

Legal documents and information protection law

What the law on information protection in telecommunication systems regulates

The Law of Ukraine on information protection in information and telecommunication systems regulates relations in the field of protecting information in information, telecommunication, and information-telecommunication systems. After the 2020 revision these concepts were refined: the law speaks of information, electronic communication, and information-communication systems.

The law's key principle is simple: any information processed in a system must be protected from unauthorized access, leakage, destruction, blocking, and integrity violations. The law is not limited to state systems — it applies to all systems that process information, including private companies, banks, communication operators, and other business entities.

It is important to understand that this law is the foundation on which Ukraine's entire information-protection system is built. It works together with other acts: the Law "On Information," the Law "On Personal Data Protection," the Law "On the Basic Principles of Ensuring Cybersecurity of Ukraine" (2017), the Law "On Electronic Communications" (2020), and the Law "On State Secrets." Together they form the legal field in which both state bodies and the commercial sector operate.

Key terms: protection, KSI, technical and cryptographic protection

Article 1 of the law defines the basic terms, which are worth knowing to navigate the regulator's requirements.

Information protection in a system is the activity aimed at preventing unauthorized actions regarding information in a system. That is, it is not a one-time action but a continuous process.

Comprehensive information protection system (KSI) is an interconnected set of organizational and engineering-technical measures, means, and methods of information protection. This is the main practical mechanism that system owners must build to comply with the law.

Technical information protection is a type of protection aimed at preventing leakage, destruction, and blocking of information, as well as violations of integrity and access regime, through engineering-technical measures and hardware-software tools.

Cryptographic information protection is a type of protection implemented by transforming information using special (key) data to conceal or restore the content of information, confirm its authenticity, integrity, and authorship.

The law also defines concepts such as information leakage (the result of actions by which information becomes known to persons without access rights), blocking of information, destruction of information, integrity violations, and unauthorized actions regarding information. Understanding these terms is critical, because the regulator's requirements and court decisions rest on them.

Objects of protection and subjects of relations

Under Article 2 of the law, the objects of protection in a system are two elements: the information itself processed in the system, and the software designed to process it. In other words, you must protect not only the data but also the means by which it is processed.

The subjects of relations (Article 3) are:

  • information holders — individuals or legal entities that own rights to information;
  • system owners — persons who own the system;
  • users — persons who have lawfully obtained the right to access information in the system;
  • the specially authorized central body for special communications and information protection — the State Service of Special Communications and Information Protection of Ukraine (Derzhspetszviazok) and its regional bodies.

The law separately regulates relations between these subjects: between the information holder and the system owner (Article 5), between the system owner and the user (Article 6), and between system owners (Article 7). The system owner must ensure information protection on the terms defined by the agreement with the information holder, and provide users with information about the rules and operating mode of the system.

Comprehensive information protection system

Comprehensive information protection system (KSI): how it works

Practical compliance with the law has traditionally been implemented by creating a comprehensive information protection system (KSI). The procedure for building it was long defined by the Rules for ensuring information protection in information, telecommunication, and information-telecommunication systems, approved by Resolution of the Cabinet of Ministers of Ukraine No. 373 of March 29, 2006.

KSI covers both organizational measures (security policies, regulations, appointing responsible persons) and engineering-technical solutions (access-separation tools, antivirus protection, cryptographic protection, intrusion-detection systems, etc.). After creation, the system was subject to state expertise and conformity attestation carried out by Derzhspetszviazok bodies or structures accredited by them.

For systems processing state secrets or restricted information, the requirements were the strictest. For business working with open information, the law provided a more flexible approach: the conditions under which KSI may not be applied are defined in the law itself.

A separate layer of requirements concerns critical information infrastructure facilities. For them, the General Requirements for Cyber Protection of Critical Infrastructure Facilities apply (CMU Resolution No. 518 of June 19, 2019), as well as the cyber-protection model approved by CMU Resolution No. 1426 of December 29, 2021.

The 2025 reform: security authorization and security profiles

The biggest changes in recent years came with the 2025 reform. Law No. 4336-IX of March 27, 2025 introduced a new model that gradually replaces the classic KSI attestation.

Key innovations:

  1. Security profiles of three levels. The basic profile is developed depending on the type of restricted information and the functional purpose of the system and is approved by the Administration of Derzhspetszviazok. The sectoral profile takes the basic one into account for the relevant category of systems. The target profile is developed for a specific system subject to security authorization.
  2. Security authorization is a new procedure that grants the right to operate a system. It is carried out for systems processing state information resources or restricted information of critical information infrastructure facilities whose owners or administrators are state authorities, state enterprises, institutions, organizations, and local self-government bodies.
  3. Information security standard conformity certificate — an alternative path: a system can be protected by obtaining a conformity certificate issued by a conformity-assessment body.

These mechanisms are detailed by CMU Resolution No. 712 of June 18, 2025, which approved the Procedure for developing and approving security profiles and the Procedure for security authorization.

For the private sector, the reform means a gradual transition from rigid attestation to a risk-oriented approach with security profiles, bringing Ukrainian practice closer to international standards and easing harmonization with EU requirements.

The role of Derzhspetszviazok and liability for violations

Derzhspetszviazok is the specially authorized central executive body for special communications and information protection. The law entrusts it with key functions:

  • developing proposals on state policy in information protection and its implementation;
  • defining requirements and the procedure for creating KSI for state information resources and restricted information;
  • organizing state expertise of comprehensive protection systems, expertise, and conformity confirmation of technical and cryptographic protection tools;
  • control over the protection of state information resources;
  • measures to detect threats to state information resources from unauthorized actions.

Regarding liability, Article 11 of the law formulates it succinctly: persons guilty of violating legislation on information protection in systems bear liability according to law. Specific sanctions are set by other acts — the Code of Ukraine on Administrative Offenses and the Criminal Code of Ukraine, which provide both administrative and criminal liability for illegal access to information, its leakage, or unauthorized modification.

Separately, the law (Article 12) establishes the priority of international treaties: if an international treaty ratified by the Verkhovna Rada establishes other rules, the norms of the international treaty apply.

Business compliance and data protection

What business should do: practical steps to compliance

Although the strictest requirements concern state systems and critical infrastructure, private companies should also approach information protection systematically. The practical minimum looks like this.

First, conduct an inventory: determine what information is processed in your systems, whether it includes personal data, restricted information, or other restricted-access data. The required level of protection depends on this.

Second, implement organizational measures: appoint a responsible person (security administrator), approve information-security policies, separate access rights, and train personnel. According to the logic of the law, the organizational level is the foundation of any KSI.

Third, ensure technical and cryptographic protection: use modern access-separation tools, antivirus protection, encryption, and backups. Prefer proven non-Russian solutions — for example, from ESET, Cloudflare, CrowdStrike, or Microsoft, which meet international standards.

Fourth, regularly check whether your data has leaked out. The free Breach Check tool helps identify compromised credentials — a quick way to assess whether your corporate addresses have appeared in known breach databases.

Fifth, follow legislative changes and industry events. The security-authorization reform is still rolling out, and requirements are being refined. Current trends and Ukrainian cyber-community events are convenient to track in our overviews — for example, the piece on NATO Cyber Coalition 2026, which analyzes state-level information-system defense practices.

Conclusion

Ukraine's law on information protection in information and telecommunication systems remains the foundation on which the country's entire data-protection system rests. Despite its solid age — the document was adopted back in 1994 — it is constantly updated and today is undergoing a large-scale transformation: rigid KSI attestation is being replaced by risk-oriented security authorization with security profiles.

For business, the main conclusion is simple: information protection is not a one-time certification but a continuous process that combines organizational measures, technical tools, and constant monitoring. Understanding the law's basic concepts — objects of protection, subjects of relations, KSI, and the new security authorization — allows a company to build its protection system consciously rather than merely fulfilling formal requirements.

Follow updates on cyberpeople.tech so you don't miss legislative changes and practical breakdowns of new information-protection mechanisms.

Stay ahead of threats

Weekly cybersecurity intelligence in your inbox. No spam.

CyberPeople contributor