# Ukraine

> Ukraine (NSSMC · National Bank of Ukraine · Ombudsman): The law that passed and never commenced. Region: Europe. Regime still forming: No settled rule on confidentiality yet; the framework is in draft or newly in force.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Jurisdiction
- Region: Europe
- Subject: The law that passed and never commenced
- Authority: NSSMC · National Bank of Ukraine · Ombudsman
- Stance on on-chain confidentiality: Regime still forming. No settled rule on confidentiality yet; the framework is in draft or newly in force.
- Tags: not in force, MiCA alignment, CBDC no personal data, unsettled
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/jur-ukraine

## What it actually says

An unusual case: the virtual assets law passed in February 2022 is recorded in the official register as never having entered into force. With no operative licensing regime, there is no in-force restriction on anonymity-enhancing assets and no constraint on unhosted wallets, not as a policy choice, but because the machinery was never switched on. A MiCA-based replacement passed first reading in 2025 and would change that quickly. The detail worth carrying forward is the central bank's e-hryvnia design note, which states plainly that the regulator will not have any personal information. Explicit commitments of that kind from a central bank are rare enough to be worth citing wherever they appear.

## The instruments that matter

- **Law No. 2074-IX on Virtual Assets, 17 February 2022**: recorded in the official register as not having entered into force; Ukraine therefore has no operative service provider licensing regime
- **Draft law 10225-d**: introduced 24 April 2025 and drafted on a MiCA basis, passed first reading
- **e-hryvnia design**: the National Bank states that payments are secured by it while the regulator will not have any personal information, alongside offline payments and DLT-based wallet recovery
- **Data protection still on the 2010 law**: a GDPR-aligning draft was adopted as a basis in November 2024 and awaits second reading

## Sources

- [Law 2074-IX on the Rada register](https://zakon.rada.gov.ua/laws/show/2074-20)
- [NBU e-hryvnia](https://bank.gov.ua/en/payments/e-hryvnia)

## Related entries

- [Georgia](https://www.sodalabs.xyz/privacy-hub/regulation/jur-georgia): The one place where privacy oversight went backwards
- [Norway](https://www.sodalabs.xyz/privacy-hub/regulation/jur-norway): MiCA via the EEA, with a privacy-innovation sandbox
- [Switzerland](https://www.sodalabs.xyz/privacy-hub/regulation/jur-switzerland): Crypto-friendly and strict on anonymity at once
- [Turkey](https://www.sodalabs.xyz/privacy-hub/regulation/jur-turkey): Caps, delays and a compelled purpose description
- [United Kingdom](https://www.sodalabs.xyz/privacy-hub/regulation/jur-united-kingdom): Risk-based, with an explicit central bank no-access pledge
- [CJEU on identifiability](https://www.sodalabs.xyz/privacy-hub/regulation/reg-cjeu-identifiability): Case law · is a wallet address personal data
