IMPACT OF GDPR ON UKRAINIAN PERSONAL DATA PROTECTION LEGISLATION
B.-P. O. Koshovyi — Pravo ta nauki
How it connects
Related across sources
Full text
The article examines the impact of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation – GDPR), which entered into force on 25 May 2018, on Ukrainian personal data protection legislation. The main novelties of GDPR are analyzed, including the principle of accountability, the right to erasure (right to be forgotten), the right to data portability, the obligation to notify about personal data breaches (data breach notification), the institute of data protection impact assessment and the institute of data protection officer. The provisions of the Law of Ukraine "On Personal Data Protection" of June 1, 2010, No. 2297-VI, are examined and the degree of its compliance with GDPR requirements is determined, in particular regarding the grounds for processing personal data, the rights of data subjects, control mechanisms and liability for violations. The extraterritorial application of GDPR to Ukrainian companies processing personal data of EU citizens is considered, and the legal consequences of the non-compliance of domestic legislation with European standards for the prospects of Ukraine's European integration are identified. The necessity of comprehensive reform of the Law of Ukraine "On Personal Data Protection" taking into account GDPR requirements is substantiated, in particular the introduction of the accountability principle, the enshrinement of the right to erasure and the right to data portability, the establishment of the obligation to notify about personal data breaches, the creation of a specialized supervisory authority for data protection, and proposals regarding priority directions for such reform in the context of the state's European integration course are formulated.