Liability for a database leak: what you face for leaking personal data

A leaked customer base, distribution of internal documents or a dump of employee personal data – all of this can have serious legal consequences both for a company and for individuals. Attorney Vitalii Petryk explains what liability exists in Ukraine and what to do if you are suspected of a data leak.

Key points

  • Unlawful collection, storage or distribution of personal data without consent is punishable under Article 182 of the Criminal Code (up to 3 years imprisonment).
  • Unauthorised access to computer systems in order to obtain data is a separate offence under Article 361.
  • A company that allowed a leak bears administrative liability under the Law on Personal Data Protection.
  • Liability may fall on the direct perpetrator of the leak as well as on a manager or system administrator for negligence.
  • If suspected of a leak, give no statements without a lawyer and do not voluntarily hand over access to your devices.

What criminal liability applies to leaking personal data?

In Ukraine several articles of the Criminal Code may apply depending on the method and circumstances of the leak:

  • Article 182 – breach of the inviolability of private life: unlawful collection, storage, use or distribution of confidential information about a person without their consent. The sanction is a fine of up to 850 tax-free minimum incomes, corrective labour or imprisonment of up to 3 years. Where committed by an official or using computer systems, up to 5 years.
  • Article 361 – unauthorised interference with computer systems: where the leak occurred through hacking systems or an account. The sanction is up to 5 years imprisonment, and up to 10 years in aggravated circumstances.
  • Article 364 – abuse of authority or official position: where an official who had access to the data by virtue of their post was involved in the leak.

Who can be held liable?

Criminal liability may attach to:

  • The direct perpetrator – the person who actually copied the data and passed it to third parties.
  • A system administrator or IT specialist – where the leak resulted from negligent configuration of protection systems or from deliberate access.
  • A company manager or data protection officer – for granting unrestricted access to a database or failing to provide adequate protection.
  • An outsider – a hacker or intermediary who obtained and used the leaked data.

What administrative liability does a company bear?

Besides the criminal liability of individuals, a company bears administrative liability under the Law on Personal Data Protection. The Ukrainian Parliament Commissioner for Human Rights (the Ombudsman) has powers to inspect compliance and issue orders. Where a leak affects the personal data of customers or employees, the company must notify the Ombudsman and the affected individuals.

What to do if you are suspected of a data leak

  1. Give no statements without a lawyer – any explanation given before consulting a lawyer may be used against you.
  2. Do not voluntarily provide access to devices – a laptop, phone or corporate computer may be handed over only on the basis of a court decision.
  3. Do not discuss the situation with colleagues – they may be questioned as witnesses.
  4. Preserve your logs and correspondence that may confirm the absence of intent or of access to the relevant systems.
  5. Contact a lawyer as early as possible – defence tactics are shaped in the first hours.

What should a company do after discovering a leak?

  • Record the fact and circumstances of the leak: date, volume, type of data, source.
  • Isolate the affected system and preserve logs.
  • Involve a lawyer in any public statements.
  • Notify the Ombudsman and affected individuals within a reasonable time.
  • File a report with the police or cyber police if the leak resulted from an external breach.

Frequently asked questions

Is there a difference between an accidental and a deliberate leak?

Yes, a significant one. Criminal liability under Article 182 requires intent. Where a leak occurs accidentally through negligence, liability is usually administrative rather than criminal – though this depends on the circumstances and the position of the investigation.

Can an affected individual bring a civil claim?

Yes. A person whose personal data was unlawfully distributed has the right to compensation for moral and material damage in a civil court (Article 23 of the Law on Personal Data Protection).

Can a dismissed employee leak the customer base?

This is a common breach. If it happens, record the evidence, file a police report and consult a lawyer about a civil claim for damages.

Does liability extend to foreign companies processing Ukrainians data?

Ukrainian personal data protection law applies to everyone who processes the data of Ukrainian citizens, regardless of where the company is registered.


Read also: Unauthorised interference with systems (Article 361): defence | Corporate cyber incident: legal steps after a breach | Legal services


Suspected of leaking a database or personal data?

Attorney Vitalii Petryk provides legal assistance in cybercrime cases, personal data protection and criminal defence in the IT field.

  • Phone: +38 (096) 878-07-36
  • Email: info@advokat-petrik.com
  • Address: Kyiv, Holosiivskyi Avenue 132, RELE Business Centre

This article is informational and is not legal advice. To assess your specific situation, contact an attorney.

Prev PostSeizure of cryptocurrency during a search: what to do and how to protect your assets
Next PostYou are suspected of a cybercrime: what to do in the first 24 hours?

Коментувати

ENG
Передзвоню за 50 секунд×