Abstract
The aim of this study was to offer a comprehensive theoretical analysis of the development of the system of liability of business entities for violations of the legislation on personal data protection at the stages of collection, storage and processing. The methodology was based on the use of the systemic approach and the comparative legal method to the regulatory frameworks of Ukraine, the United States of America and the Federal Republic of Germany. Research showed that the legal responsibility of business has moved from a strategy of formal compliance to a concept of comprehensive accountability. Under this new paradigm, entities had to demonstrate the practical effectiveness of the protection algorithms they have implemented. In the Ukrainian legal field, it was found that the most critical offences arise at the stages of obtaining consent, inconsistency between the purpose of further use of information and the original purpose, and disregard for the duty to distinguish between business and personal data in personnel processes. Neglecting to identify roles in writing when engaging information processors was found to create conditions for the uncontrolled transfer of data, leading to joint and several liability for counterparties. The study revealed a fundamental difference between the German vertical system of sanctions, which prioritises technical system integrity, and the American sectoral decentralisation model, which is characterised by a strong punitive enforcement approach. It was found that European case law permits compensation for non-material damage in cases of breach of personal data protection legislation, provided an individual has experienced psychological distress or fear of unlawful data use. It was determined that institutional fragmentation in Ukraine, coupled with the absence of an autonomous supervisory authority, reduces the level of legal protection for processing operations, compared to the German model. The study confirmed the necessity of integrating the three-part public interest test into all internal regulations governing access to confidential information, with the aim of preventing mass offences in the municipal sector. The practical significance of the results lies in their potential application by legal departments and enterprise management to implement the concept of data protection by design and conduct security audits to minimise legal risks in the context of digital transformation
Keywords: personal information; data holder; processor; information leaks; institutional fragmentation; confidentiality assurance
Suggested citation