On 14 May 2021, the first Law “On Personal Data Protection” (the Law) in Belarusian history was officially published. It started the 6-month term for the preparation of the companies to its entering into force and provision of compliance with this law.
We discussed with Veronika Pavlovskaya, senior associate, the influence of the Law on the companies in different spheres.
Passing the special law in the sphere of personal data protection is a significant event for Belarus, as the work on its development has started in 2017, and the developers have analyzed the foreign personal data protection legislation and practice based on it. Therefore, it is not surprising that it is possible to see a lot in common between the Law and the General Data Protection Regulation (GDPR): the latter has divided the life of many companies into “before” and “after” regarding the seriousness of their attitude to processing of personal data.
However, the Law is not a copy of the GDPR, it is also based on the Russian practice, and also on the history of the regulation of personal data in Belarus. In particular, the key concept of the Belarusian personal data regulation, consent, remains the same. The consent shall be given by the data subject whose data are processed, i.e. by each of us. The Law introduces the opportunity to obtain not only written consent but also consent in the electronic form, including via the SMS code or the code sent to the email, as well as by ticking the box on the website.
The term “personal data operator” is introduced. It means the person who collects and processes (or assigns processing to the authorized person), i.e. the companies. However, the companies are not the only subjects that carry out the processing of personal data: state bodies and individuals (including the individual entrepreneurs) are the personal data operators too. This term is an analogue to the “controller” under the GDPR. The Law does not apply to the processing of personal data within processing purely for personal, family, household and other similar purposes not related to professional or commercial activities; neither it applies to state secrets. The general requirements regarding the necessity to impose legal, organizational and technical means for the protection of personal data remain in force. They include, inter alia, the obligation of the company to appoint a division or officer responsible for internal control of personal data processing (the analogue of the DPO under the GDPR). However, this requirement has earlier been set by the legislation as well. Within the next 3 months, the special state body for personal data protection shall be established.
There are a few pieces of advice to some spheres which feel the impact of the Law.
Banks and IT
International transfer of data plays an important role in these spheres. Under the Law, as a general rule, such transfer is allowed only to the countries which provide a sufficient level of personal data protection (the list of such countries has not been published yet). Please do not be afraid of this requirement, there are several exemptions from this rule, including consent of the data subject. Therefore, you can add the information about international transfers to your consent forms. However, in this case, your company is required to explain to the data subject the risks connected to such transfer.
Another important moment relates to storing personal data for undefined future use (for example, for the development of new products or services). It is not acceptable under the Law: you are required to receive the consent of the data subject for processing of the particular data for particular purposes for a period when the data are necessary (and not longer). Each new purpose requires new consent if it does not fall under the exemptions.
If you use biometric data in your products, such data are considered as special personal data under the Law. There is a special legal regime for their processing. Generally, it requires consent from the data subject and the obligation of the operator to impose measures for the prevention of risks to the data subjects’ rights and liberties when their data are processed. The particular means and measures are not provided by the Law.
Medical services
The rules for the processing of special personal data described above are also applicable to data processing related to rendering medical services.
However, there are several exemptions from the general rules provided specifically for medical services:
- Consent for processing is not required if personal data are processed for the organization of medical care. It is allowed provided that the processing is carried out by the medical, pharmaceutical or other healthcare workers who bears the obligation to provide personal data protection and who falls under the requirements of the medical secrecy;
- Processing of personal data without consent is allowed for the protection of the life, health or any other vital interests of the data subject or other people.
Journalists and photographers
The general requirement to obtain the consent of the data subject applies to the journalists and photographers as well.
The photographers are required to receive consent for the processing of an image of the person, including, transfer of the image to the third parties, as the image constitutes biometric (i.e. special) personal data.
There is an exemption for the journalists: it is allowed to process personal data without consent when carrying out the lawful professional activity as a journalist, mass-media or publishing activity if such activity aims to the protection of the public interest. The public interest means the necessity of the society to find and disclose the information on risks to the national security, public order, public health and environment, information which has an influence on the fulfilment of their obligations by the state officials and public figures. These cases do not include cases provided by the civil procedural, commercial procedural, criminal procedural legislation and legislation on administrative procedure.
The examples and recommendations given above are not exhaustive. There are 6 months before the key provisions of the Law enter into force; therefore, we recommend the companies to carry out the internal audit of personal data processing mechanisms and to develop the plan of actions to provide compliance of these mechanisms with the Law.



