
Employee Data Protection and Privacy in Belarus: A Foreign Employer’s Obligations
If you employ people in Belarus, you’re handling their personal data — contracts, salaries, ID numbers, bank details — and…
If you employ people in Belarus, you’re handling their personal data — contracts, salaries, ID numbers, bank details — and you almost certainly assume your existing privacy programme has it covered. For a foreign employer, that assumption is where the trouble starts.
Belarus has its own data-protection law. It looks a lot like GDPR, but it isn’t a copy — the consent rules are stricter and more detailed, and there’s a cross-border-transfer regime that catches the one thing nearly every foreign employer does by default: sending employee data home.
Here’s what actually applies to you, the obligation that trips people up, and how using an Employer of Record changes who carries the load.
The law in one minute
The main framework is Law No. 99-Z on Personal Data Protection, in force since November 2021 and overseen by the National Personal Data Protection Center. It’s the country’s dedicated privacy law — GDPR-inspired, but with narrower lawful bases and unusually specific rules for what a valid consent has to say. The Labour Code sits alongside it and governs the employment relationship itself.
Two roles matter. The “operator” is the one who decides how and why data is processed — the controller, in GDPR terms. The “authorized person” processes data on the operator’s behalf — the processor. Keep those two straight, because when we get to Employers of Record, which role you occupy changes everything.
What counts as employee data — and what’s “special”
In an employment relationship you’ll handle the everyday set — name, address, ID number, salary, bank details, the contract itself — all of which is protected personal data. Processing it is normal and allowed; you just have to do it on a proper basis and keep it secure.
Some data is treated as “special” and carries stricter rules: health information, biometric and genetic data. If you collect any of it — a medical certificate, a fingerprint for building access — treat it with extra care and a clear, separate basis, not as part of the general bundle.

Your core obligations as an operator
Once you’re processing employee data, a set of duties kicks in. None is exotic, but several need doing deliberately rather than assumed — which is where local HR and compliance support earns its keep. The essentials:
- A lawful basis. Consent is the default unless another basis applies; the law lists exceptions, and some employment processing rests on the Labour Code rather than on consent.
- Consent done properly. It’s not a checkbox — a valid consent has to spell out who you are and where you’re based, the purposes, the exact data, how long it lasts, any processors, the actions and methods, and the person’s rights and the consequences of agreeing or refusing.
- Security and a named lead. You need legal, organisational and technical measures, a designated person or unit responsible for data protection, staff training, access controls, and a published processing policy.
- Data-subject rights. People can ask to see their data, correct it, or withdraw consent — you need a process to handle those requests.
- Breach notification. If personal data is breached, you notify the regulator within three working days.
If that reads like GDPR with sharper edges, that’s the right instinct — but the detail is where compliance lives, and the specifics of Belarus’s regime differ enough that a lift-and-shift from your home programme won’t quite land.
The trap for foreign employers: cross-border transfer
Now the part that catches almost everyone. The moment employee data leaves Belarus — into your global HR system, your HQ, a payroll or monitoring tool hosted abroad — it’s a cross-border transfer, and the law regulates it with an “adequate level of protection” test.
| Where the data goes | Adequate? | What you need |
|---|---|---|
| EAEU member states | Yes | A standard basis — the transfer is allowed |
| Council of Europe Convention 108 parties (much of Europe) | Yes | A standard basis — the transfer is allowed |
| US, UK, and most non-EU destinations | Not automatically | A separate basis — usually specific, informed consent naming the destination and purpose |
The catch is in the bottom row. The US, the UK, and most non-EU destinations aren’t automatically “adequate,” so if your HRIS runs on US SaaS or your systems sit in a UK data centre, you can’t lean on your standard global privacy notice. You need a separate, Belarus-specific basis — usually explicit consent that names the destination and the purpose and, where there’s no adequacy, tells the employee about the risks.
Fixing it is usually manageable. For most routine transfers the workable basis is a properly built consent — one that names each destination, the purpose, and, where the country isn’t adequate, the risks of sending data there. Where consent doesn’t fit, or the flows are large and ongoing, the law also allows a permit route through the regulator. Either way the task is to identify each flow and give it a named basis, not to stop sending data — you’re documenting reality, not blocking it.
This is easy to miss precisely because it’s invisible: nobody “decides” to export data, it just flows to wherever your tools live. If you run payroll or HR systems outside Belarus, that flow is exactly what needs a proper basis.
Employee monitoring — where it goes wrong fastest
Monitoring deserves its own flag. Watching email, corporate devices, video, or location is allowed in Belarus, but only with a written policy, clear disclosure, and consent — the rules for employee monitoring are specific and easy to breach.
And here’s the compounding problem: a monitoring stack almost always sends what it collects to a dashboard or server abroad. So monitoring doesn’t just need its own consent — it re-triggers the cross-border rule on top. It’s the single most common way foreign employers cross the line without realising it.
Who’s on the hook if you use an EOR?
This is where the operator-versus-authorized-person distinction pays off. When you hire through an Employer of Record, the EOR is the local legal employer — which makes it the operator for the employment data it processes in Belarus. The consent capture, the responsible person, the processing policy, the local security measures: those sit with a party that does them every day.
You don’t get to switch off entirely — you still have obligations for the data you receive and process abroad, and for the cross-border flow into your systems. But the local, Belarus-facing compliance burden — the part that’s hardest to get right from another country — moves off your desk.
For a company that only wants to employ a few people in Belarus, that’s a big part of the appeal of hiring without your own entity: you get the talent without personally standing up a local data-protection programme from scratch.
What non-compliance costs
It’s worth taking seriously. Penalties for getting data protection wrong in Belarus run from administrative fines up to, in severe cases, criminal liability — with reported maximums of several years’ imprisonment for the worst breaches.
Most companies will never be near that end of the scale. But there’s also the quieter cost — a regulator’s attention, a stalled deal, an employee complaint — that makes “we’ll sort it later” a poor plan. Getting the basics right up front is far cheaper than fixing a breach after the fact.
Common mistakes foreign employers make
Most problems here aren’t dramatic — they’re the same few oversights, repeated:
- Assuming a GDPR or CCPA programme transfers wholesale. It’s a strong base, but not a Belarus-compliant one on its own.
- Reusing the global privacy notice untouched, with no Belarus-specific section on transfer destinations and legal bases.
- Treating consent as a tick-box, when the law wants detailed, purpose-by-purpose disclosures.
- Overlooking the cross-border rule entirely, because the data “just” sits in the usual HR or payroll SaaS abroad.
- Rolling out monitoring tools without a written policy, disclosure, and consent — and without noticing they export data too.
- Never appointing a person responsible for data protection, or publishing a processing policy.
None of these is hard to avoid once you know to look for it. The trouble is that each one feels like a non-issue right up until a complaint, an audit, or a deal’s due diligence turns it into one.
A compliance checklist
If you want a practical starting point, work down this list:
- Map what employee data you process, and why.
- Establish a lawful basis for each purpose.
- Write compliant, detailed consents wherever consent is the basis.
- Publish a processing policy and appoint someone responsible for data protection.
- Put security measures and access controls in place.
- Screen every data flow leaving Belarus for adequacy, and add a proper transfer basis where it’s missing.
- Keep a breach playbook that meets the three-working-day rule.
- Localise your privacy notice for Belarus — don’t just reuse the EU one.
None of it is heavy on its own. The risk comes from doing none of it, because you assumed your home setup carried over.
FAQ
- We’re already GDPR-compliant. Doesn’t that cover Belarus?
No. Belarus has its own law (No. 99-Z), inspired by GDPR but not identical — the consent requirements are more prescriptive and the cross-border rules differ. A GDPR programme is a strong starting point, but you need a Belarus-specific layer, especially for consent and data transfers.
- Can we store Belarusian employee data in our US or UK HR system?
Only with a proper transfer basis. The US and UK aren’t automatically treated as providing “adequate” protection, so a transfer there generally needs explicit, specifically scoped consent that names the destination and purpose (and explains the risks), or another basis the law allows. Your standard global notice won’t do it on its own.
- Do we need employee consent, or does the employment contract cover it?
It depends on the purpose. Consent is the default basis, but some employment processing can rest on the Labour Code or other legal grounds instead. The safe approach is to map each purpose to a basis rather than assume the contract covers everything — and where you do rely on consent, make sure it meets the detailed content rules.
- Who is the “operator” if we use an EOR?
For the employment data the EOR processes as the local legal employer, the EOR is the operator and carries those obligations. You remain responsible for data you receive and process in your own systems abroad, including the cross-border transfer into them.
- Do we need someone responsible for data protection in Belarus?
Yes — the law expects a designated person or unit responsible for data protection, alongside security measures and a published processing policy. If you hire through an EOR, that responsibility for the local employment data sits with the EOR.
- What happens if there’s a data breach?
You’re expected to notify the regulator within three working days, so you need a breach plan ready in advance rather than improvised on the day. Speed matters — and so does having decided who does what before it happens.
- Can we monitor employees in Belarus?
Yes, within limits — monitoring is allowed with a written policy, clear disclosure, and consent. Remember that most monitoring tools send data abroad, which brings the cross-border rules into play as well, so treat monitoring and data-transfer compliance together.
- Does the law apply to us if we have no entity in Belarus?
If you’re processing the personal data of people in Belarus, the rules are in play regardless of where your company sits — which is part of why the cross-border-transfer question matters so much for a foreign employer. Hiring through an EOR is one clean way to keep the local processing in the hands of a Belarusian operator.
- How is this different from GDPR in practice?
The shape is familiar, but the details bite differently: consent has to carry much more prescribed information, the lawful bases are narrower, and the cross-border test treats fewer countries as automatically “adequate” — notably not the US or UK. Treat GDPR as your foundation and add a Belarus layer on top.
How eor.by helps
As the local employer under an EOR, eor.by carries the operator-side obligations for your Belarusian team’s employment data — lawful consents, the responsible person, the processing policy, local security and breach handling — and can advise on structuring the cross-border flows into your own systems.
Talk to eor.by for a data-compliance review — we’ll tell you what applies to your setup and where, if anywhere, your current handling of Belarusian employee data falls short.
Our Blog
The latest news in our blog
Employee Data Protection and Privacy in Belarus: A Foreign Employer’s Obligations
If you employ people in Belarus, you’re handling their personal data — contracts, salaries, ID numbers, bank details — and…
Losing HTP Residency: What Can Get a Company Excluded and How to Stay Compliant
Getting into the Hi-Tech Park was the hard part — the business project, the review, the Supervisory Board’s yes. So…
Scaling a Belarus Team via EOR: When to Add Headcount and When to Switch to an Entity
You put your Belarus team on an EOR, and it worked — people hired fast, no entity to stand up,…
Contact
We’re available for the new projects

