On 11 February 2025, the Ukrainian Government adopted a resolution regulating various aspects of cloud and data center services (the "Services") provision and use. In particular, the resolution introduces:
The resolution is adopted under the Law of Ukraine "On Cloud Services".
Key provisions
The resolution establishes the procedure for providing Services related to processing SIR or restricted information. In particular, such Services must be provided under a contract, the term of which may not exceed the validity period of a conformity document issued by an accredited conformity assessment body in electronic communications. The conformity document serves as a evidence of compliance with requirements for information security management, service continuity, network and information system security. Users also consider these conformity documents when comparing Services and cloud infrastructure options.
The resolution defines the obligations of Service providers, including
The requirements cover technical, organisational, and physical security measures, including the implementation of an information security management system (the "ISMS") or comprehensive information security system (the "CISS"), cybersecurity incident management and service continuity management, automated service control, monitoring, auditing, and security testing.
The Service provider shall ensure compliance with the established standards, in particular international standard ISO/IEC 27001 or a standard of a foreign country adopted under this standard, or the Ukrainian national standards ISO/IEC 27001:2023 (ISO/IEC 27001:2022, IDT), ISO/IEC 27018:2019.
To confirm compliance with the requirements, a provider must obtain: (i) a conformity document issued by a conformity assessment body or a document confirming the compliance of a CISS based on the results of a state examination in the field of technical information protection; (ii) policies and procedure for processing personal data; (iii) documents confirming the ownership or other property rights to equipment and premises used for providing Services; and (iv) a conformity document issued by a conformity assessment body in the field of electronic communications, confirming compliance with the requirements.
The resolution also regulates the procedure for forming and using electronic catalogues of Services. Key provisions include:
* Under the Law of Ukraine "On Cloud Services", a public user of cloud services is a state authority, an authority of the Autonomous Republic of Crimea, a local self-government body, a state enterprise, a state institution, a state organisation or other subject of authority or other entity to which such authority has been delegated.
The catalogue must include: (i) a description of the Service, terms and conditions of use, data protection procedures, location of cloud resources/data center, incident reporting mechanism, compliance with standards, and (ii) an identification code such as the USREOU (Ukrainian company code), LEI code (international legal entity identifier) or taxpayer identification number for individual entrepreneurs. These provisions indicate that the Service provider may be either a resident or a non-resident of Ukraine.
The model contract governs agreements between Service providers and public users and critical information infrastructure facility operators. The model contract outlines the procedures and conditions for granting access to the Services, the payment procedures, and the rights and obligations of both parties. For example, the provider is obliged to immediately notify the user of a cybersecurity incident that has or may have a significant negative impact on the provision of Services, confirming the notification to CERT-UA, and further inform the user of the measures taken to respond to the cybersecurity incident.
In terms of liability, a penalty of 20 percent of the value of the defective Services will apply for failure to provide quality Services. Additional sanctions will apply for failure to comply with time limits for fulfilling the obligation.
Early termination of the contract is allowed (i) by mutual agreement of the parties, (ii) by unilateral termination due to contract breaches, (iii) in case of termination or cancellation of the document confirming compliance with the requirements for managing information security, continuity, security of network and information systems of the providers.
Under the provisions of the model contract, the law of Ukraine applies to legal relations not regulated by the contract. Disputes fall under the jurisdiction of Ukrainian courts.
Providers and users of cloud services or data center services in Ukraine must comply with the new regulatory framework. Until 31 December 2025, public users may still procure Services from providers not included in the official List. After that date, only listed providers will be eligible for public procurement contracts.
Given this, Service providers should prepare in advance to meet the requirements for inclusion in the List to maintain the possibility of providing Services to public users after 2025.
***
For more information, please contact Asters Partner Yuriy Kotliarov or Counsel Sergiy Tsyba