New rules on personal data protection: how to comply with EU standards?
Globalisation is making borders between countries increasingly permeable, whilst the exchange of data is becoming faster and more efficient. This creates both new opportunities for development and new risks to the security of personal data. International cooperation in the field of data protection is therefore an essential prerequisite for ensuring security in the digital world.
The protection of individuals with regard to the processing of personal data is a fundamental right. Article 8(1) of the Charter of Fundamental Rights of the European Union (‘the Charter’) and Article 16(1) of the Treaty on the Functioning of the European Union (TFEU) establish that every person has the right to the protection of their personal data.
The General Data Protection Regulation (GDPR) (hereinafter ‘the Regulation’), which came into force in the European Union in May 2018, has significantly raised the standards for the processing and protection of personal data. For Ukrainian businesses, particularly in the context of Ukraine’s acquisition of EU candidate status, compliance with the requirements of this Regulation is not only desirable but also a strategically important step. Given the globalisation of the market, companies that fail to adhere to high standards of data protection risk losing the trust of their customers and partners. The GDPR sets out clear standards of transparency and accountability in the processing of personal data, and compliance with it significantly enhances a company’s competitiveness, strengthens its reputation internationally and opens up new opportunities for attracting investment.
Harmonisation of Ukrainian legislation with EU legislation on the protection of personal data
Ukraine, in accordance with Article 15 of the Association Agreement with the EU, has undertaken to align its legislation on personal data protection with European standards. A number of steps have already been taken in this direction; in particular, the Draft Law on the Protection of Personal Data No. 5628 of 7 June 2021 was drawn up, which was intended to bring national regulations significantly closer to the requirements of the GDPR. However, as of August 2022, the vote on this draft law had failed.
The Law of Ukraine ‘On the Protection of Personal Data’, which was adopted in 2012, provides the legal framework for regulating the processing of personal data within the country. However, compared with the Regulation, it contains a number of important differences in both its requirements and its approaches to data protection. Here are a few key differences:
Consent to the processing of personal data
-
In the EU, obtaining consent from the data subject is a fundamental principle of personal data processing. Consent must be specific, informed, free and voluntary, and must be given prior to the start of processing. It must be clearly documented, and companies must ensure that data subjects can easily withdraw their consent at any time.
-
The Law ‘On the Protection of Personal Data’ does not require such a strict procedure for obtaining prior consent to the processing of personal data. In Ukraine, data processing may be carried out not only on the basis of the data subject’s consent, but also on other legal grounds, such as the performance of contractual obligations or the legitimate interests of the controller. Whilst consent remains an important tool, the requirements for obtaining it are less stringent than under the GDPR.
Terms and definitions
-
The Regulation introduces clear and detailed terminology, in particular the concepts of ‘personal data’, ‘processing’, ‘data controller’, ‘data processor’, ‘consent’ and so on. Each of these terms has a specific meaning and forms the basis for the correct interpretation of the provisions of the Regulation.
-
Ukrainian legislation also uses similar terms, but their definitions may differ from European standards. For example, some terms are less detailed or may have different legal meanings, which creates certain difficulties when adapting Ukrainian legislation to EU standards.
Supervisory authorities
-
The Regulation has established a unified system for supervising compliance with data processing rules across the EU. Each Member State has its own national authority responsible for monitoring compliance with the GDPR, but there is also a pan-European supervisory body that coordinates the activities of national authorities and regulates cross-border issues.
-
In Ukraine, compliance with personal data legislation is monitored by the Ukrainian Parliament Commissioner for Human Rights. Although this body has certain powers to protect citizens’ rights, its role and resources differ from those of similar bodies in the EU, which often creates gaps in oversight and enforcement.
Rights of data subjects
-
The European Regulation provides for a wide range of rights for data subjects, including the right of access to their data, the right to rectification, the right to erasure (‘the right to be forgotten’), the right to restriction of processing, the right to data portability, and the right to object to data processing based on legitimate interest.
-
The Law ‘On the Protection of Personal Data’ also grants data subjects the right to access and rectify their data, but it does not provide for such extensive rights as, for example, the right to data portability or the right to be forgotten. Ukrainian legislation regulates the interaction between data subjects and data controllers and processors in the context of these rights in less detail.
Financial penalties
-
One of the most notable features of the GDPR is the possibility of imposing substantial fines for infringements. Fines may amount to up to €20 million or 4 per cent of a company’s global turnover for the previous financial year, whichever is higher.
-
The Ukrainian Law ‘On the Protection of Personal Data’ provides for sanctions for breaches, but these are significantly lower than European standards. Fines for non-compliance in Ukraine are substantially lower and have a limited impact on large companies, which may reduce the incentive to comply fully with the law.
In order to correctly interpret and apply the provisions of the Regulation, it is necessary to understand the basic approaches set out in the General Provisions:
Material Scope
Pursuant to Article 2 of the Regulation, this Regulation applies to the processing of personal data, in whole or in part, by automated means, and to the processing of personal data by non-automated means, which form part of a filing system or are intended to be included in a filing system.
‘Processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
‘Filing system’ means any structured set of personal data, access to which is organised according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis.
Territorial Scope of the Regulation
Article 4 stipulates that this Regulation applies to the processing of personal data of data subjects who are in the Union, by a controller or processor established outside the Union, where the processing is related to the supply of goods or the provision of services to such data subjects within the Union, regardless of whether payment is sought from such data subjects.
In this context, the term ‘data subject’ refers not only to EU citizens but also to non-EU nationals who are passing through, travelling or temporarily staying in Europe.
‘Controller’ means a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or specific criteria for its designation may be laid down by Union or Member State law.
‘Processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Let us consider some practical situations in which the Regulation must be complied with:
-
A Ukrainian citizen, whilst in Estonia, used a free Ukrainian mobile app; they are protected under the GDPR.
-
A Ukrainian website selling drones collects the contact details of all its users. EU citizens wishing to purchase goods may also register on the website. These buyers are also protected by the GDPR.
Compliance with GDPR standards
As Article 1 states that the purpose of the Regulation is to lay down rules on the protection of natural persons with regard to the processing of personal data, the main requirements are set out in Article 32.
Article 32 of the GDPR sets out the criteria for the secure processing of information:
-
Anonymisation: The use of methods that make it impossible to identify a person without additional data, thereby enhancing the level of confidentiality.
-
Secure storage: The use of modern encryption methods to ensure security during the storage and transmission of data.
-
Controlled access: Granting access to information only to authorised persons, maintaining access logs and protecting against unauthorised attempts to access data.
-
Accuracy and completeness of information: Ensuring that data remains accurate and fully accessible to authorised users.
-
Reliability of processing systems: Maintaining stable system operation with a minimal likelihood of failures or malfunctions.
-
Recovery from failures: Ensuring that systems can be restored quickly, in particular through backups and redundancy of critical components.
An analysis of Ukrainian legislation in the context of the GDPR highlights the need for further harmonisation of national regulations with European standards on the protection of personal data. Despite certain steps in this direction, significant discrepancies remain, particularly in the areas of liability, data subjects’ rights and oversight mechanisms. For Ukrainian businesses, adapting to the GDPR is not only a necessity of the times but also a long-term investment, as it will help to boost customer trust, strengthen their reputation on the international market and open up new opportunities for cooperation with European partners.
Author: Maksym Kinash
Read the article on the ‘Yurydychna Gazeta’ website: here.
Read also
All publications →Synegor Law Firm is expanding its international presence: London, Warsaw, Dubai
Expand your business into global markets with local support from the specialists at Synegor. Our offices in London, Warsaw and Dubai offer turnkey solutions for corporate…
Reservation in exchange for money: liability for fictitious reservation of persons liable for military service at a company.
Schemes involving fictitious employment arrangements to secure exemption from mobilisation are increasingly coming to the attention of law enforcement agencies. We examine in detail the sections…
Mykola PushynskyiRead →Tax relief in areas of hostilities: new rulings by the Supreme Court
Following the outbreak of full-scale war, the legislature introduced measures to exempt taxpayers from certain property taxes on buildings and plots of land situated in areas…
Kostiantyn NosovRead →