Softline IT

Cloud data residency for Ukrainian businesses: Balancing global benefits and national requirements

Ukrainian cloud services legislation: What businesses need to know

As of September 16, 2022, the Law of Ukraine "On Cloud Services" (Law No. 2075-IX) 1 came into force in Ukraine, defining the legal framework for using cloud technologies and establishing rules for interaction between providers and users of such services. This law is the first step towards implementing the Cloud First strategy in the public sector and aims to create conditions for data processing and protection, as well as more efficient use of state resources.

For government agencies, local self-government bodies, military formations, and state-owned enterprises, the Law establishes specific requirements. In particular, it prohibits processing information classified as state secrets and hosting state registries in data centers outside Ukraine or in temporarily occupied territories. The government also adopted a resolution regulating cloud storage in state institutions, allowing data to remain abroad in the cloud and not be transferred back to Ukraine after the war 2, and introduces a catalog of cloud service providers and mandatory requirements for them 2. Until December 31, 2025, state institutions can procure cloud services from companies that have not yet registered, but after this transition period, registration will become mandatory for working with state bodies and critical infrastructure facilities 2.

Private businesses have more flexibility in choosing data storage locations but are still obliged to comply with Ukrainian legislation on the protection of personal and other data. This includes the Law of Ukraine "On Personal Data Protection" 3, which is central in this area.

Cloud data residency risks for Ukrainian companies

Non-compliance with data residency and data protection requirements in the cloud can lead to significant risks for Ukrainian companies, especially in wartime:

  • Legal consequences and fines. Violations of the Law of Ukraine "On Cloud Services" and the Law of Ukraine "On Personal Data Protection" can lead to legal liability. For companies working with European partners or processing data of EU residents, the General Data Protection Regulation (GDPR) is also relevant, and non-compliance can result in severe fines.
  • Loss of data control. Placing data abroad can complicate control over it, especially in the event of requests from law enforcement agencies of other countries.
  • Operational and reputational losses. Leaks of confidential information or unauthorized data access due to improper cloud storage configuration can cause significant damage. In wartime, the number and intensity of cyberattacks increase, raising the risk of data loss.
  • Cybersecurity threats in wartime. During martial law, critical infrastructure, networks, registries, and archives are constantly under threat of cyberattacks. While cloud technologies can provide backup, encryption, and rapid data recovery, which are essential for security and guaranteed access to information, the choice of provider and cloud architecture must consider these specifics.

Compliance strategies: How to ensure data residency and security

For Ukrainian businesses seeking to leverage the benefits of cloud technologies, it is crucial to develop a strategy that combines flexibility and compliance with legal requirements.

  • Hybrid cloud. This model combines on-premises infrastructure, private cloud, and public services, allowing companies to store sensitive data locally or in a private cloud while using the public cloud for less critical data or scaling.
    • Pros: Flexibility, scalability, cost-effectiveness, phased service migration.
    • Cons: Management complexity, need for integration of different environments.
  • Using local Ukrainian providers. Hosting cloud infrastructure in Ukrainian data centers helps ensure compliance with local regulatory requirements and simplifies regulatory procedures. It also reduces service latency and increases stability. Some Ukrainian cloud providers offer clouds that have passed attestation of compliance with the comprehensive information protection system (KSZI) and other certifications.
    • Pros: Compliance with local requirements, reduced latency, increased stability.
    • Cons: Limited choice of providers, potentially higher cost, less scalability compared to global providers.
  • Data encryption and anonymization. Encrypting data at rest and in transit transforms confidential information into unreadable code, rendering it unusable to unauthorized parties even in the event of a breach. Key management is critical for centralized data protection control.
  • Data classification. It is important to identify and categorize data by sensitivity level. This allows determining which data requires strict localization and which can be placed in public clouds, possibly outside Ukraine, with appropriate protection measures.

Contractual aspects and certifications: What to demand from a cloud provider

When choosing a cloud provider, it is critically important to pay attention to its compliance with international security standards and the terms stipulated in the contract.

  • Security certifications. Look for providers with international certifications such as ISO 27017 (security of cloud services) 4, ISO 27018 (protection of personally identifiable information in public clouds) 5, and ISO 27701 (privacy information management system) [8]. These standards demonstrate the provider's adherence to international best practices in data protection. ISO 27017 describes specific cloud service risks and the division of responsibilities between the provider and the client, while ISO 27018 focuses on the confidentiality of personal data.
  • Contractual provisions. The agreement with the provider must clearly define the location of data storage and processing, access conditions, liability for data breaches, and data deletion procedures after termination of cooperation. It is important that the provider provides information regarding data protection against internal and external threats and cyberattacks.
  • Fault tolerance and business continuity. Evaluate the provider's infrastructure fault tolerance, which depends on uninterrupted access to infrastructure and data preservation in case of failures. Reliable providers use component redundancy and offer backup and disaster recovery services.

Softline IT, as a system integrator, provides expertise in designing and implementing cloud solutions, which can be beneficial for Ukrainian businesses in addressing data residency challenges. Learn more about Softline IT cloud solutions.

Practical checklist for choosing cloud services with data residency in mind

To make an informed choice of a cloud provider and ensure compliance with data residency requirements, use this checklist:

  1. Compliance with the Law of Ukraine "On Cloud Services": Ensure that the provider complies with the requirements of this law, especially if you are a government agency or work with state information. Check the provider's presence in the list of cloud service providers 2.
  2. Data center location: Determine if you need to store data exclusively in Ukraine. If so, choose providers with data centers in Ukraine.
  3. Data processing jurisdiction: Clarify in which jurisdiction your data is processed and what laws apply to it.
  4. Security certifications: Check for the provider's ISO 27017, ISO 27018, ISO 27701 certificates, as well as KSZI (for the public sector) and PCI DSS (for the financial sector).
  5. Contractual agreements: Carefully review the contract for clauses on data ownership, access, deletion procedures, liability for breaches, and service level agreements (SLAs).
  6. Disaster recovery and business continuity plans: Assess how the provider ensures fault tolerance and the ability to recover data in case of incidents.
  7. Encryption and key management policies: Find out what encryption methods are used and how access keys to your data are managed.
  8. Support for hybrid cloud architectures: If you plan a hybrid model, ensure the provider can integrate with your on-premises infrastructure.
  9. Ability to segment sensitive data: Check if the provider allows isolating and separately protecting the most sensitive data.
  10. Incident response capabilities: Clarify how the provider responds to security incidents and what client notification procedures exist.

Softline IT helps teams plan and implement cloud and hybrid solutions, from an assessment of the current environment to an agreed change plan.

Sources used

  1. 01zakon.rada.gov.uaSource: zakon.rada.gov.ua
  2. 02zakon.rada.gov.uaSource: zakon.rada.gov.ua
  3. 03zakon.rada.gov.uaSource: zakon.rada.gov.ua
  4. 04iso.orgSource: iso.org
  5. 05iso.orgSource: iso.org
Tags