VinFunPark
VinFunPark
ISSN 2617-4162 e-ISSN 2617-4170

Social and Legal Studios

Current

Social and Legal Studios

Vol. 9, No. 2, 2026

Social and Legal Studios

ISSN 2617-4162

e-ISSN 2617-4170

Publisher: Lviv State University of Internal Affairs

Received 12.01.2026, Revised 17.04.2026, Accepted 27.05.2026 Published 01.06.2026
Article

The responsibility of business entities for breaches of data protection legislation in process management


Abstract

The aim of this study was to offer a comprehensive theoretical analysis of the development of the system of liability of business entities for violations of the legislation on personal data protection at the stages of collection, storage and processing. The methodology was based on the use of the systemic approach and the comparative legal method to the regulatory frameworks of Ukraine, the United States of America and the Federal Republic of Germany. Research showed that the legal responsibility of business has moved from a strategy of formal compliance to a concept of comprehensive accountability. Under this new paradigm, entities had to demonstrate the practical effectiveness of the protection algorithms they have implemented. In the Ukrainian legal field, it was found that the most critical offences arise at the stages of obtaining consent, inconsistency between the purpose of further use of information and the original purpose, and disregard for the duty to distinguish between business and personal data in personnel processes. Neglecting to identify roles in writing when engaging information processors was found to create conditions for the uncontrolled transfer of data, leading to joint and several liability for counterparties. The study revealed a fundamental difference between the German vertical system of sanctions, which prioritises technical system integrity, and the American sectoral decentralisation model, which is characterised by a strong punitive enforcement approach. It was found that European case law permits compensation for non-material damage in cases of breach of personal data protection legislation, provided an individual has experienced psychological distress or fear of unlawful data use. It was determined that institutional fragmentation in Ukraine, coupled with the absence of an autonomous supervisory authority, reduces the level of legal protection for processing operations, compared to the German model. The study confirmed the necessity of integrating the three-part public interest test into all internal regulations governing access to confidential information, with the aim of preventing mass offences in the municipal sector. The practical significance of the results lies in their potential application by legal departments and enterprise management to implement the concept of data protection by design and conduct security audits to minimise legal risks in the context of digital transformation


Keywords: personal information; data holder; processor; information leaks; institutional fragmentation; confidentiality assurance


Suggested citation

Sakaly, M. (2026). The responsibility of business entities for breaches of data protection legislation in process management. Social and Legal Studios, 9(2), 43-55. https://doi.org/10.32518/sals2.2026.43
References
  1. Alok, T., & Ram, A. (2026). Balancing privacy and practicality in the age of technology: A comparative analysis of the EU general data protection regulation and India’s digital personal data protection act. In A. Sharma, A. Sehrawat & T.K. Chandola (Eds.), Humanities and social sciences: A multidisciplinary approach (pp. 135-143). London: Routledge.
  2. American Data Privacy and Protection Act (ADPPA). (2022). Retrieved from https://www.consumerprivacyact.com/americandata-privacy-and-protection-act-adppa/.
  3. Anbarasi, G., & Sankar, D. (2026). Data protection challenges in AI-driven criminal justice in the EU and India. International Journal of Computational Intelligence Systems, 19, article number 20. doi: 10.1007/s44196-025-01037-6.
  4. Balatska, O.R., & Kushnir, I.M. (2026). Right to be forgotten in digital space: Implementation of European standards into Ukrainian legislation. Analytical and Comparative Jurisprudence, 1(1), 11-15. doi: 10.24144/2788-6018.2026.01.1.1.
  5. Banisar, D. (2026). National comprehensive data protection/Privacy laws and bills 2026. SSRN. doi: 10.2139/ssrn.1951416.
  6. Belli, L. (2026). Understanding the Brics countries, their digital cooperation, and their emerging data protection architectures. In L. Belli & W.B. Gaspar (Eds.), Personal data architectures in the BRICS countries (pp. 1-32). Oxford: Oxford University Press. doi: 10.1093/9780198974468.003.0001.
  7. Berisha, I.S., Kerka, E.P., & Andersons, A. (2026). Personal data protection and privacy. European Journal of Economics, Law and Social Sciences, 10(1), 84-94. doi: 10.2478/ejels-2026-0009.
  8. Bykov, O.M., & Savchenko, V.V. (2024). Personal data protection in modern legislation. Legal Bulletin, 14(4), 67-72. doi: 10.31732/2708-339X-2024-14-A9.
  9. California Consumer Privacy Act (CCPA). (2024, March). Retrieved from https://oag.ca.gov/privacy/ccpa#sectiona.
  10. California Privacy Rights Act of 2020. (2020, November). Retrieved from https://thecpra.org/.
  11. Chanysheva, G.I. (2026). The right of an employee to the protection of personal data: ILO standards and the legislation of Ukraine. Academic Visions, 51.
  12. Children’s Online Privacy Protection Rule. (2013, July). Retrieved from https://www.ftc.gov/system/files/2012-31341.pdf.
  13. Code of Ukraine on Administrative Offences. (2017, June). Retrieved from https://zakon.rada.gov.ua/laws/show/807310#Text.
  14. Colorado Privacy Act. (2021, July). Retrieved from https://www.consumerprivacyact.com/colorado-privacy-act-cpa/.
  15. Commission Staff Working Document: Ukraine 2025 Report. Accompanying the Document Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions: 2025 Communication on EU enlargement policy. (2025, November). Retrieved from https://eur-lex.europa.eu/ legal-content/EN/TXT/?uri=celex:52025SC0759.
  16. Commissioner for Human Rights of the Verkhovna Rada of Ukraine. (n.d.). Annual report of the Commissioner for Human Rights of the Verkhovna Rada of Ukraine on the state of observance and protection of human and civil rights and freedoms in Ukraine in 2024. Retrieved from https://www.ombudsman.gov.ua/storage/app/media/uploaded-files.
  17. Constitution of Ukraine. (1996, June). Retrieved from https://zakon.rada.gov.ua/laws/show/en/254%D0%BA/96%D0%B2%D1%80#Text.
  18. Council of Europe. (n.d.). Supporting the implementation of European human rights standards in Ukraine: Phase IІ. Retrieved from https://www.coe.int/uk/web/kyiv/supporting-implementation-of-the-european-human-rights-standards-in-ukraine/.
  19. Criminal Code of Ukraine. (2001, April). Retrieved from https://zakon.rada.gov.ua/laws/show/2341-14#Text.
  20. Cura, M., Loureiro, R., Marcelino, P., Rodrigues, V., & Andrade, J.P. (2026). General data protection regulation: An algorithmic proposal for forensic photography. International Journal of Legal Medicine, 140, 1689-1697. doi: 10.1007/s00414025-03640-w.
  21. Darmayanti, E.S., & Subiyanto, A.E. (2026). Criminal liability for the sale of civil servant data based on the personal data protection law. Interdisciplinary Social Studies, 5(2), 884-894. doi: 10.55324/iss.v5i2.1011.
  22. Data Privacy Framework Program. (n.d.). Data Privacy Framework (DPF) overview. Retrieved from https://www. dataprivacyframework.gov/Program-Overview.
  23. Decision of the Constitutional Court of Ukraine No. v002p710-12 “In the Case on the Constitutional Submission of the Zhashkiv District Council of Cherkasy Region on the Official Interpretation of the Provisions of Parts One, Two of Article 32, Parts Two, Three of Article 34 of the Constitution of Ukraine”. (2012, January). Retrieved from https://zakon.rada.gov.ua/laws/show/ v002p710-12#Text.
  24. Deepanshu, & Kumar, A. (2026). Corporate liability for data breaches under the Digital Personal Data Protection Act, 2023: Legal challenges and regulatory responses. Vistas: International Journal of Multidisciplinary Studies, 1(1), 103-121. doi: 10.5281/ zenodo.18385783.
  25. DLA Piper GDPR Fines and Data Breach Survey: January 2026. (2026). Retrieved from https://www.dlapiper.com/en/insights/ publications/2026/01/dla-piper-gdpr-fines-and-data-breach-survey-january-2026.
  26. Draft Labour Code of Ukraine. (2026, January). Retrieved from https://itd.rada.gov.ua/billinfo/Bills/Card/69516.
  27. Draft Law No. 6177 “On the National Commission for Personal Data Protection and Access to Public Information”. (2021, October). Retrieved from https://itd.rada.gov.ua/billinfo/Bills/Card/27996.
  28. European Data Protection Board. (2026). Report on international data protection enforcement cooperation. Retrieved from https://www.edpb.europa.eu/our-work-tools/our-documents/support-pool-experts-projects/report-international-dataprotection_en.
  29. Faccioli, M. (2026). Liability for unlawful personal data processing. In R. Bocchini (Ed.), Digital platforms-from technical foundations to legal and economic implications: Volume 1 (pp. 745-763). Cham: Springer. doi: 10.1007/978-3-032-07978-7_34.
  30. Faisal, K. (2026). Navigating the fine line: The complex reconciliation of data protection and freedom of expression in criminal conviction and offences data. Digital Policy, Regulation and Governance, 28(1), 17-34. doi: 10.1108/DPRG-10-2024-0260.
  31. Federal Commissioner for Data Protection and Freedom of Information. (2025). Activity report 2024: 33rd activity report on data protection and freedom of information. Retrieved from https://www.bfdi.bund.de/SharedDocs/Downloads/EN/ Taetigkeitsberichte/33TB_24.pdf?__blob=publicationFile&v=2.
  32. Federal Data Protection Act. (2017, June). Retrieved from https://www.gesetze-im-internet.de/englisch_bdsg/englisch_bdsg. html.
  33. Federal Trade Commission Act. (2006, December). Retrieved from https://www.ftc.gov/sites/default/files/documents/ statutes/federal-trade-commission-act/ftc_act_incorporatingus_safe_web_act.pdf.
  34. Gatti, S. (2026). Accountability principle and its implementation in the general data protection regulation. In R. Bocchini (Ed.), Digital platforms-from technical foundations to legal and economic implications (pp. 709-729). Cham: Springer. doi: 10.1007/9783-032-07978-7_32.
  35. Health Insurance Portability and Accountability Act of 1996. (1996, August). Retrieved from https://aspe.hhs.gov/reports/ health-insurance-portability-accountability-act-1996.
  36. Hennig, A., Schulte, L., Herbold, S., Kulyk, O., & Mayer, P. (2026). The whos, whats, and whys of issues related to personal data and data protection in open-source projects on GitHub. Empirical Software Engineering, 31(1), article number 9. doi: 10.1007/ s10664-025-10742-x.
  37. Joshi, U., Baisil, S., Kini B, S., Mehta, M., & Datta, S. (2026). AI ethics in Indian healthcare: A scoping review of national and international guidelines on privacy, data protection, and security. BMC Medical Ethics, 27(1), article number 86. doi: 10.1186/ s12910-026-01435-1.
  38. Karpyn, D., Leshko, R., Karpyn, A., Leshko, O., Voytovych, K.H., & Hoyvanovych, N. (2026). Cybersecurity. Protection of personal data, digital devices and access to resources. Drohobych: Drohobych Ivan Franko State Pedagogical University.
  39. Klymchuk, O.V., & Yaremenko, O.I. (2026). Harmonization of domestic legislation to European standards of cybersecurity and personal data protection: Challenges for public authorities. Current Issues in Modern Science, 44(2), 410-423.
  40. Kristanto, A.R., & Slamet, S.R. (2026). Legal liability of financial services institutions for personal data leakage under the Personal Data Protection Act. Golden Ratio of Data in Summary, 6(1), 83-90. doi: 10.52970/grdis.v6i1.1981.
  41. Law of Ukraine No. 1089-IX “On Electronic Communications”. (2020, December). Retrieved from https://zakon.rada.gov.ua/ laws/show/1089-IX#Text.
  42. Law of Ukraine No. 2163-VIII “On the Basic Principles of Cybersecurity in Ukraine”. (2017, October). Retrieved from https:// zakon.rada.gov.ua/laws/show/en/2163-19#Text.
  43. Law of Ukraine No. 2297-VI “On Personal Data Protection”. (2010, June). Retrieved from https://zakon.rada.gov.ua/laws/ show/2297-17#Text.
  44. Law of Ukraine No. 2657-XII “On Information”. (1992, October). Retrieved from https://zakon.rada.gov.ua/laws/show/265712#Text.
  45. Law of Ukraine No. 2939-VI “On Access to Public Information”. (2011, January). Retrieved from https://zakon.rada.gov.ua/ laws/show/en/2939-17#Text.
  46. Law of Ukraine No. 80/94-VR “On Information Protection in Information and Communication Systems”. (1994, July). Retrieved from https://zakon.rada.gov.ua/laws/show/80/94-%D0%B2%D1%80#Text.
  47. Law of Ukraine No. 851-IV “On Electronic Documents and Electronic Document Management”. (2003, May). Retrieved from https://zakon.rada.gov.ua/laws/show/851-15#Text.
  48. New York Privacy Act. (2022, February). Retrieved from https://www.consumerprivacyact.com/new-york-privacy-act/.
  49. Ombudsman of Ukraine. (2014). Typical procedure for processing personal data. Retrieved from https://ombudsman.gov.ua/uk/ rekomendaciyi-ta-rozyasnennya/tipovij-poryadok-obrobki-personalnih-danih.
  50. Poscher, R., & Orrù, E. (2026). Data protection and privacy: Digitalisation, power, and the transatlantic divide. In Conceptions of data protection and privacy: Legal and philosophical perspectives (pp. 1-12). Oxford: Hart Publishing. doi: 10.5040/9781509983759.0005.
  51. Q2 2025 privacy & data protection regulatory enforcement report. (2025). Retrieved from https://compliancehub.wiki/q22025-privacy-data-protection-regulatory-enforcement-report.
  52. Qinvi, N.U., Ahmad, R.S., & Wahyunisa, H. (2026). Personal data protection in an artificial intelligence – based photo marketplace on the FotoYu Platform. Journal of Cyber Law and Technology Regulation, 1(1), 1-11.
  53. Regulation (EU) No. 2016/679 of the European Parliament and of the Council “On the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data, and Repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance)”. (2016, April). Retrieved from https://zakon.rada.gov.ua/ laws/show/984_008-16#Text.
  54. Regulation (EU) No. 2024/1689 of the European Parliament and of the Council “Laying Down Harmonised Rules on Artificial Intelligence and Amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (Text with EEA Relevance)”. (2024. June). Retrieved from https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng.
  55. Resolution of the Verkhovna Rada of Ukraine No. 4065-IX “On Adopting as a Basis the draft Law of Ukraine on Personal Data Protection”. (2024, November). Retrieved from https://zakon.rada.gov.ua/laws/show/4065-20#Text.
  56. Şakar, A.Y., & Bağce, D.H.A. (2026). Assessment of the personal data protection board’s decision on a data breach committed by an airline company. Journal of Aviation, 10(1), 71-76. doi: 10.30518/jav.1770648.
  57. Siddiqui, A. (2026). Data protection and privacy in the digital age: Comparative perspectives on India’s digital Personal Data Protection Act and the EU General Data Protection Regulation. SSRN. doi: 10.2139/ssrn.6050296.
  58. Singal, S., & Chorev, N. (2026). Free markets, high walls: Data protection and the question of post-neoliberalism. SocioEconomic Review, 2026, article number mwaf094. doi: 10.1093/ser/mwaf094.
  59. Singh, P., Kumar, S., Singh, S.K., & Singh, H. (2026). Privacy in mental healthcare by data protection: Exploring AI-powered psychological assessment and identity crisis intervention with legal provisions. In L.R. Janjua, K. Edina & B. Singh (Eds.), Imposter syndrome and AI: Navigating human identity in the age of intelligent machines (pp. 327-346). Hershey: IGI Global Scientific Publishing. doi: 10.4018/979-8-3373-6618-0.ch017.
  60. Smith, C., & Hawkins, R. (2026). Arguing conformance with data protection principles. arXiv. doi: 10.48550/arXiv.2601.15155.
  61. Strelnyk, V., & Brazhnichenko, I.E. (2022). General theoretycal aspeсts of legal regulation of personal data protecton in legislation of Ukraine. Legal Scientific Electronic Journal, 10, 215-217. doi: 10.32782/2524-0374/2022-10/50.
  62. Suciara, A., Idias, B., Siregar, N.J., Siregar, T.A.F., & Prabowo, T.W. (2026). Strict liability vs fault based: Perbandingan Indonesia dengan Jepang terhadap kebocoran data. Al-Zayn: Journal of Social Sciences & Law, 4(1), 739-749.
  63. Surzhynskyi, M. (2025). Challenges and opportunities for adapting Ukrainian legislation to European standards for personal data protection in the field of artificial intelligence. Law of Ukraine, 4, 26-37. doi: 10.33498/louu-2025-04-026.
  64. The 2025 privacy & compliance “Fines & Follies” awards: A year of record-breaking enforcement. (2025). Retrieved from https://compliancehub.wiki/the-2025-privacy-compliance-fines-follies-awards-a-year-of-record-breaking-enforcement.
  65. Thomas, L., Gondal, I., Oseni, T., & Firmin, S. (2022). A framework for data privacy and security accountability in data breach communications. Computers & Security, 116, article number 102657. doi: 10.1016/j.cose.2022.102657.
  66. Tolson, B. (2026). Compliance U.S. data privacy laws and regulations in 2026. Retrieved from https://www.smarsh.com/blog/ thought-leadership/data-privacy-laws/.
  67. Understanding data privacy laws: A 2026 compliance guide. (2026). Retrieved from https://www.tekclarion.com/cybersecurity/data-privacy-laws-2026/.