Publishing a website in Ukraine is not only the technical launch of a domain, hosting and a CMS. Depending on what the resource does, the business or other person running it may act at the same time as a seller, a provider of services, an owner of personal data, an advertiser or a user of intellectual property. Each of these roles creates separate legal obligations. That is why the legal aspects of a website are best addressed before release, rather than after the first complaint from a customer, a rights holder or a supervisory authority.

There is no single universal document entitled “requirements for a Ukrainian website”. The set of rules depends on what the resource does. An information blog, a corporate website, a SaaS service, a marketplace and an online shop handle different types of data and create different legal relationships. This is precisely why the core requirements for a website must be determined with regard to the business model, the way it interacts with users, the category of goods or services and the geography of the audience.

What does lawful publication of a website in Ukraine mean?

The notion of “lawful publication of a website” is not a separate legal term. In practice, it means that the activity carried out through the web resource complies with the applicable legislation. What matters is not merely the formal presence of a few legal pages in the footer, but the alignment of the actual processes with what the website tells the user.

For example, if a website describes one procedure for using personal data while its forms, CRM, analytics or marketing services in fact work differently, the text of the policy alone does not solve the problem. Legal documents must reflect the real technical and business logic of the resource.

For a corporate website without online sales, the main issues may be personal data, copyright, the state language, advertising, the accuracy of information and the security of forms. For an online shop, e-commerce rules, seller information, contract terms, payment, delivery, warranties, exchange and returns are added. For a service with user accounts, registration, account protection, the terms of use of the service and the processing of user data need to be thought through separately.

From a legal point of view, a website must make available the information and documents a user needs in order to understand who they are dealing with, on what terms they are submitting information or entering into a contract, and how they can exercise their rights. The specific set of such blocks is determined by the functionality of the resource and by the activity of the business.

Which laws govern the operation of websites in Ukraine?

The operation of a single website may be governed simultaneously by rules drawn from several branches of law. For an ordinary commercial resource, the basic legislative acts include:

This list is not exhaustive. Financial, medical, pharmaceutical, alcohol, tobacco, gambling and other regulated projects may face additional requirements as regards licensing, advertising, sales or the content of information. Depending on the business model, rules of civil, tax and other legislation also apply.

The Law of Ukraine “On Consumer Rights Protection” No. 3153-IX of 10 June 2023 needs to be considered separately. It is intended to replace the current Law No. 1023-XII, but as at 19 August 2026 it has not yet entered into force. Law No. 3153-IX provides that it enters into force one year after publication, but not earlier than the day on which martial law is terminated or lifted. For that reason, a legal audit of an online shop must verify the status of this law as at the actual date of the review.

Who bears legal responsibility for a website?

Liability does not arise for an abstract “website” understood as a set of pages. It is necessary to establish which natural or legal person carries out the specific activity through the resource and what role that person performs.

A seller, for example, is answerable for performing its obligations towards the buyer; an owner of personal data – for organising their processing in accordance with the legislation; an advertiser – for complying with advertising requirements within the limits of its responsibility; and a person who uses third-party content must have lawful grounds for that use.

The contractor that built the website, the hosting provider or the domain registrar do not automatically become responsible for all of the client’s business processes and content. Their responsibility is determined by the legislation, by their actual conduct and by the agreements between the parties.

Before launch, it is worth establishing clearly who the seller or provider is, who determines the purposes and means of processing personal data, who holds administrative access to the resource and who handles user enquiries. This should also be reflected in the agreements with developers, marketing agencies, CRM services, payment systems and other suppliers.

Information about the website owner and the seller

The law does not require the same volume of public identification information from every website. Special requirements apply to e-commerce entities, because the buyer must be able to understand exactly who they are entering into a contract with.

The Law of Ukraine “On Electronic Commerce” obliges a seller, provider or supplier to ensure direct, simple and stable access to the information specified by that law. Depending on the status of the entity, this includes the name of the legal entity or the details of the sole trader, its location or the information about the place of registration provided for by law, an email address, identification details and, for activities subject to licensing, information about the relevant licence. The law also requires information about the cost of goods, works or services, the inclusion of taxes and the cost of delivery.

In practice, this information is best placed so that a user can find it without having to register or place an order. Part of it may sit in the contact details, part in the terms of sale, the public offer or the company details. All of these documents must nevertheless give consistent information about one and the same party to the contract.

Protection of users’ personal data

A name, telephone number, email address, delivery address, account details and other information may constitute personal data if they relate to an identified natural person or to a person who can be specifically identified.

The Law of Ukraine “On Protection of Personal Data” requires that the purpose of processing personal data be formulated and lawful, and that the composition and content of the data be relevant, adequate and not excessive in relation to the stated purpose.

Information should therefore not be collected without a clear need. If a name, an email address and the text of the message are enough to reply to an enquiry, any additional fields must be justified by the function of the form or by another lawful task.

Whoever owns the relevant process must understand what data arrives through each form, what it is used for, where it is stored, who has access to it, to whom it is transferred and for how long it is needed.

Ukrainian legislation also requires that the data subject be informed about the owner of the personal data, the composition and content of the data collected, their rights, the purpose of collection and the persons to whom the data are transferred. A separate privacy policy is a convenient way of presenting this information to the user in a systematic manner, but its text must correspond to how the website actually works.

The policy of another resource should not be copied without adaptation. Even two online shops running on the same CMS may use different CRMs, analytics systems, delivery services, payment tools, chat services and marketing platforms.

Forms on the website and the collection of user data

Contact, registration, checkout, booking, subscription and enquiry forms are typical points at which personal data are collected. Website development requirements must therefore cover not only the design and validation of fields, but also a correct scenario for handling the information received.

The user must be given the necessary information about who processes the data and for what purpose. The specific mechanism depends on the legal basis and on the scenario. In some cases consent may be used; in others the processing rests on a different ground provided for by law. A universal “I agree to the processing of personal data” checkbox should therefore not be applied mechanically to every operation.

The data needed to fulfil a request or an order must also be kept separate from marketing communications. Providing a telephone number so that delivery can be arranged does not in itself amount to automatic consent to use that number for unlimited promotional messages.

The technical implementation matters just as much. It is necessary to check whether confidential data are being transmitted over an unprotected channel, whether field values end up in URLs or third-party logs without any need for it, and whether staff access to the enquiries received is properly restricted.

Cookies and their use

Cookies are small pieces of information that a website, or a service connected to it, may store in the user’s browser or on their device. They are used to maintain a session, for authentication, the basket, settings, analytics, advertising measurement and other functions.

Ukrainian legislation does not establish a separate universal cookie regime for every website that is fully identical to the European ePrivacy model. At the same time, data obtained through cookies and other online identifiers may, in certain scenarios, be linked to personal data. In such a case, the requirements of the legislation on their processing must be assessed.

In practical terms, it is useful to carry out an inventory of cookies, pixels, SDKs and other trackers, and to explain their purpose to the user. Particular attention should be paid to advertising and behavioural technologies.

If EU rules apply to a particular website or to particular processing operations, the requirements of the GDPR and of ePrivacy regarding access to information on the user’s device must be assessed separately. In such cases, technologies that require prior consent must not be activated before it is obtained, and the choice mechanism must allow the user to refuse the non-essential categories.

Requirements for website content are not limited to the accuracy of information. Photographs, illustrations, video, music, fonts, software code, design, infographics and original texts may be protected by copyright. The fact that material is accessible through a search engine or a social network does not automatically confer the right to use it in one’s own commercial project.

There must be a lawful basis for using third-party material: one’s own authorship, an agreement with the rights holder or the contractor, a stock service licence, an open licence or another possibility of use provided for by law.

Agreements, proof of licence purchases and documents on the transfer or grant of economic rights should be retained. This applies in particular to logos, brand identity, professional photography, video advertising, design and software components.

Naming the author or the source is not sufficient in itself where the use of a particular work requires the rights holder’s permission. Publishing photographs of customers and other user-generated content may also call for a separate assessment of copyright, of the right to a person’s image and of the rules on processing personal data.

Legal requirements for online shops

An online shop does not merely display a catalogue. It is used to conclude contracts at a distance, to obtain the buyer’s data, to process payments and to arrange delivery. There are therefore more legal requirements for it than for an ordinary information website.

Before launch, it is necessary to check the seller information, product pages, prices, the ordering procedure, the terms of the electronic contract, payment, delivery, warranties, exchange and returns. It is important to review not only the individual legal pages but the whole checkout, since it is during the ordering process that the user receives the key information and takes the steps aimed at concluding the contract.

Seller information

The Law “On Electronic Commerce” requires a seller to ensure direct, simple and stable access to the information about itself specified by that law. The buyer must be able to identify the party with which they are entering into contractual relations.

If the activity requires a licence or another special permit, the separate disclosure requirements of the relevant legislation must be checked.

Terms of sale and the public offer

A public offer is a common way of setting out the terms of distance selling, but legal compliance does not come down to having a separate document with that title. What matters is that, before concluding the contract, the buyer can review the necessary terms and understand exactly which action constitutes acceptance of the seller’s offer.

The terms of sale usually identify the seller, the subject matter of the contract, the ordering procedure, the price, payment, delivery, the procedure for concluding the contract, the rights and obligations of the parties, the complaints procedure, warranty terms, exchange and returns, and other provisions relevant to the particular business.

The documents must match the real process. If the terms of sale state one delivery period while the checkout or the support team quotes another, the information must be brought into line.

Nor should the terms include provisions that conflict with the consumer’s mandatory rights or that limit the seller’s liability without justification.

Payment, delivery and returns

Before placing an order, the buyer must receive clear information about the price and the other terms of purchase. If delivery is charged separately, depends on the carrier’s tariff or is calculated later, this must be explained before the order is confirmed.

The rules on exchange, returns, withdrawal from a distance contract and warranty service depend on the type of product, its condition, the reason for the claim and the applicable rules. The popular wording “goods may be returned within 14 days” should therefore not be used as a universal rule without explaining the conditions and the exceptions provided for by law.

The legal texts must be aligned with the actual payment and logistics arrangements. The user must understand whom they are paying, how the order is confirmed, what happens after a successful or a failed transaction and how delivery is organised.

Language requirements for Ukrainian websites

Article 27 of the Law of Ukraine “On Supporting the Functioning of the Ukrainian Language as the State Language” sets requirements for the internet presences, and in particular the websites, of the authorities and entities specified by that law.

In particular, the internet presences of business entities registered in Ukraine and selling goods or services in Ukraine must have a version in the state language. Versions in other languages may exist alongside the Ukrainian one.

The Ukrainian-language version of such an internet presence must be no less extensive in volume and content than the foreign-language versions, and for users in Ukraine it must load by default in the cases provided for by law.

For an online shop or a service website it is therefore not enough to translate only the menu and the home page. Product pages, service terms, the checkout, system messages, email templates and other elements of interaction with the user all need to be assessed.

Advertising and commercial content on the website

Advertising must comply with the requirements of the Law of Ukraine “On Advertising” and with the special rules for particular categories of goods and services. Unfair advertising, including information that misleads or is capable of misleading consumers and of affecting their economic behaviour, creates legal risk.

It is not only advertising banners that need to be checked. Promotional blocks, landing pages, service descriptions, special offers, comparisons and other content created to stimulate sales may equally be commercial in nature.

Claims such as “No. 1”, “the best”, “100% safe”, “guaranteed result” and other absolute statements call for particular caution. Where such characteristics cannot be properly substantiated, or where they create a false impression of the properties of a product or service, they are better avoided.

For the medical, financial, alcohol, tobacco, gambling and other regulated sectors, the special restrictions on the content, manner and place of dissemination of advertising must be checked in addition.

Website security and information protection

The legislation on personal data imposes a duty to protect them against unlawful processing and unlawful access. Technical security must therefore form part of the preparation of any website that handles user information.

For web resources through which personal, authentication or other confidential data are transmitted, HTTPS is the baseline technical measure. How it works is explained in more detail in Hostpark’s article on SSL certificates and HTTPS.

That said, SSL/TLS protects the data transmission channel between client and server, but it does not automatically make a website secure against every attack. It is also necessary to keep the CMS and modules up to date and to control access to the admin panel, passwords, multi-factor authentication, backups and component updates.

For public-facing services it is worth providing protection of forms against automated abuse, limits on login attempts, logging of critical actions and an incident response plan. For resources whose availability is business-critical, it is sensible to assess the risks of DDoS attacks and the approaches to protection separately.

The level of security required depends on the architecture, the type of data and the scale of the resource. A landing page with a contact form and a large system with user accounts call for different sets of measures.

Domain and hosting: the legal points worth considering

A domain name is not only the technical address of a website. Its use may overlap with rights in trade marks, trade names and other designations. The Law of Ukraine “On Protection of Rights to Marks for Goods and Services” takes account of the use of designations in domain names, so the mere technical ability to register an available domain does not guarantee the absence of a conflict with a third party’s rights.

Before launching a brand, it makes sense to check both the availability of the domain and any possible conflicts with trade marks. The technical availability of a name can be checked through Hostpark’s domain registration service, while the legal clearance of the designation should, where necessary, be analysed separately.

A hosting provider supplies the infrastructure on which the resource is hosted, but that does not automatically transfer to it responsibility for the lawfulness of the client’s business and content. Before choosing a provider, review the contract, the acceptable use policy, the complaints handling procedure, the backup terms and other parameters.

The practical technical criteria for choosing a platform are set out in Hostpark’s article on choosing hosting for a website.

If personal data are transferred or processed outside Ukraine, the rules on cross-border transfers and the requirements of the jurisdictions that apply to the specific operation must be checked separately. This concerns not only hosting but also international CRM and SaaS products, analytics systems, cloud storage, email marketing and other external services.

Does a Ukrainian website have to comply with the GDPR?

Does a Ukrainian website have to comply with the GDPR?

The GDPR does not apply automatically to every Ukrainian website merely because a user in the European Union is technically able to open it.

For a company with no establishment in the EU, the GDPR may apply where, among other things, the processing in question relates to offering goods or services to persons who are in the EU, or to monitoring their behaviour within the EU.

An occasional visitor from Europe and a deliberate push into the European market are therefore different situations. The assessment may take into account the actual geography of sales, delivery to EU countries, localisation, currencies, advertising campaigns, marketing activity and other signs that the business is directed at that audience.

The Ukrainian Law “On Protection of Personal Data” and the GDPR are different legal regimes. If specific operations of a Ukrainian business fall within the territorial scope of the GDPR, it is not only the text of the privacy policy that must be checked but the entire processing cycle: legal bases, transparency, agreements with processors, data subject rights, retention periods, security and international transfers.

Separately, the ePrivacy rules must be taken into account for technologies that store or gain access to information on a user’s device in the EU. A standard cookie banner that does not actually control the analytics and advertising scripts therefore does not in itself ensure compliance with the European rules.

What are the consequences of breaching the legislation?

There is no single universal “fine for an unlawful website”. The consequences depend on which rule has been breached, who the responsible person is, what the effects were and which special rules apply.

Depending on the situation, there may be administrative liability, civil law claims, orders to remedy the breach, compensation for damage and special sanctions in the relevant field.

The Code of Ukraine on Administrative Offences, for example, contains Article 188-39 on breaches of the legislation on the protection of personal data. Advertising legislation provides for its own liability mechanisms, and, where protected content has been used unlawfully, the rights holder may resort to the remedies for copyright infringement provided for by law.

Beyond state sanctions, there may be practical consequences: claims from customers and rights holders, restrictions on advertising or payment accounts, content takedowns, suspension of services under the provider’s rules, legal costs and reputational damage.

Exact fine amounts should not be copied into an article from generic tables without checking the wording of the specific provision currently in force. Liability and the size of a sanction must be established in accordance with the legislation in force on the date of the breach.

Checklist before publishing a website in Ukraine

Before opening the resource to users, it is worth carrying out a final review of its legal and technical logic:

  1. Establish who the seller is, who the provider is, who owns the relevant business processes and who is the owner of the personal data.
  2. Check the contact information, company details and other information that must be disclosed for the particular activity.
  3. Compare the privacy policy with the data actually collected by the forms, CRM, analytics, marketing and other external services.
  4. Review the forms, registration, checkout and marketing subscriptions, and determine the correct legal basis for each data processing scenario.
  5. Audit cookies, pixels and other trackers, and separately determine the requirements for users and markets covered by the EU rules.
  6. Make sure that texts, photographs, video, fonts, design and software components are used on lawful grounds and that the necessary rights from contractors are documented.
  7. For an online shop, check the seller information, contract terms, price, payment, delivery, warranties, exchange and returns.
  8. Check the Ukrainian-language version of the website and its compliance with the Law of Ukraine “On Supporting the Functioning of the Ukrainian Language as the State Language”.
  9. Configure HTTPS, protection of administrative accounts, CMS and module updates, access control, backups and a basic incident response plan.
  10. Check the domain for any possible conflict with trade marks and review the terms of the hosting, CRM, SaaS, payment, advertising and analytics services.

This checklist covers the basic requirements but does not replace a review of sector-specific legislation. An additional audit is needed for regulated goods and services, sensitive categories of personal data, financial transactions, services aimed at children and international activity.

Conclusion

Lawful publication of a website in Ukraine begins not with copying standard legal documents but with an analysis of how the resource actually works. You need to identify the parties to the legal relationship, review the processing of personal data, the content and the advertising, set out transparent terms of sale, meet the language requirements and ensure an appropriate level of technical protection.

The legal aspects of a website should be revisited after any significant change: connecting a new CRM or analytics tool, launching a new form, online payments or a marketing system, changing the seller, entering a new market, or substantially changing the product range and the business model.

The technical side of the launch also needs to be planned systematically: the domain, HTTPS, hosting, backups, administration and access control must match the needs of the particular resource. Hostpark provides infrastructure solutions for hosting and protecting IT systems, while the legal requirements for a particular business must be determined in the light of its activity and the applicable legislation.

This material is for information purposes only and does not constitute individual legal advice. Before launching a project with a complex or regulated business model, it is worth checking the requirements that apply to that specific activity.

How useful was this post?

Click on a star to rate it!

Average rating 5 / 5. Vote count: 196

No votes so far! Be the first to rate this post.