VinFunPark
VinFunPark
ISSN 2617-4162 e-ISSN 2617-4170

Соціально-правові студії

Поточний випуск

Соціально-правові студії

Том 9, № 2, 2026

Соціально-правові студії

ISSN 2617-4162 

e-ISSN 2617-4170

Видавець: Львівський державний університет внутрішніх справ

Отримано 12.01.2026, Доопрацьовано 17.04.2026, Прийнято 27.05.2026 Опубліковано 01.06.2026
Стаття

Відповідальність суб’єктів господарювання за порушення законодавства про захист даних у процесному управлінні


Анотація

Метою дослідження був комплексний теоретичний аналіз трансформації системи відповідальності суб’єктів господарювання за порушення законодавства про захист персональних даних на етапах їх збирання, зберігання та опрацювання. Методологія базувалась на застосуванні системного підходу та порівняльноправового методу до нормативних масивів України, Сполучених Штатів Америки та Федеративної Республіки Німеччина. У ході роботи встановлено, що юридична відповідальність бізнесу змістилася від стратегії формального дотримання інструкцій до концепції повної підзвітності, де суб’єкти зобов’язані демонструвати реальну результативність впроваджених алгоритмів захисту. Виявлено, що в українському правовому полі найбільш критичні правопорушення виникають на стадіях отримання згоди, невідповідності мети подальшого використання відомостей та ігнорування обов’язку розмежування ділових і особистих даних у кадрових процесах. З’ясовано, що нехтування письмовою ідентифікацією ролей при залученні розпорядників інформації створює умови для неконтрольованої передачі даних, що призводить до солідарної відповідальності контрагентів. Доведено фундаментальну відмінність між німецькою вертикаллю санкцій, де пріоритетом є технічна цілісність систем, та американською секторною децентралізацією з вираженою каральною спрямованістю правозастосовчої практики. Встановлено, що європейська судова практика допускає відшкодування нематеріальної шкоди у справах про порушення законодавства про захист персональних даних, якщо особа зазнала психологічного дискомфорту або страху неправомірного використання її даних. Визначено, що інституційна фрагментарність в Україні та відсутність автономного наглядового органу знижують рівень правової захищеності процесних операцій порівняно з німецькою моделлю. Обґрунтовано необхідність інтеграції трискладового тесту суспільного інтересу в усі внутрішні регламенти доступу до конфіденційної інформації для уникнення масових правопорушень у комунальному секторі. Практична значимість результатів полягає у можливості їх використання юридичними службами та менеджментом підприємств для впровадження концепції захисту за призначенням і проведення аудитів безпеки з метою мінімізації юридичних ризиків в умовах цифрової трансформації


Ключові слова: персональні відомості; володілець; розпорядник; витоки інформації; інституційна фрагментарність; забезпечення конфіденційності


Цитувати

Sakaly, M. (2026). The responsibility of business entities for breaches of data protection legislation in process management. Social and Legal Studios, 9(2), 43-55. https://doi.org/10.32518/sals2.2026.43
Використані джерела
  1. Alok, T., & Ram, A. (2026). Balancing privacy and practicality in the age of technology: A comparative analysis of the EU general data protection regulation and India’s digital personal data protection act. In A. Sharma, A. Sehrawat & T.K. Chandola (Eds.), Humanities and social sciences: A multidisciplinary approach (pp. 135-143). London: Routledge.
  2. American Data Privacy and Protection Act (ADPPA). (2022). Retrieved from https://www.consumerprivacyact.com/americandata-privacy-and-protection-act-adppa/.
  3. Anbarasi, G., & Sankar, D. (2026). Data protection challenges in AI-driven criminal justice in the EU and India. International Journal of Computational Intelligence Systems, 19, article number 20. doi: 10.1007/s44196-025-01037-6.
  4. Balatska, O.R., & Kushnir, I.M. (2026). Right to be forgotten in digital space: Implementation of European standards into Ukrainian legislation. Analytical and Comparative Jurisprudence, 1(1), 11-15. doi: 10.24144/2788-6018.2026.01.1.1.
  5. Banisar, D. (2026). National comprehensive data protection/Privacy laws and bills 2026. SSRN. doi: 10.2139/ssrn.1951416.
  6. Belli, L. (2026). Understanding the Brics countries, their digital cooperation, and their emerging data protection architectures. In L. Belli & W.B. Gaspar (Eds.), Personal data architectures in the BRICS countries (pp. 1-32). Oxford: Oxford University Press. doi: 10.1093/9780198974468.003.0001.
  7. Berisha, I.S., Kerka, E.P., & Andersons, A. (2026). Personal data protection and privacy. European Journal of Economics, Law and Social Sciences, 10(1), 84-94. doi: 10.2478/ejels-2026-0009.
  8. Bykov, O.M., & Savchenko, V.V. (2024). Personal data protection in modern legislation. Legal Bulletin, 14(4), 67-72. doi: 10.31732/2708-339X-2024-14-A9.
  9. California Consumer Privacy Act (CCPA). (2024, March). Retrieved from https://oag.ca.gov/privacy/ccpa#sectiona.
  10. California Privacy Rights Act of 2020. (2020, November). Retrieved from https://thecpra.org/.
  11. Chanysheva, G.I. (2026). The right of an employee to the protection of personal data: ILO standards and the legislation of Ukraine. Academic Visions, 51.
  12. Children’s Online Privacy Protection Rule. (2013, July). Retrieved from https://www.ftc.gov/system/files/2012-31341.pdf.
  13. Code of Ukraine on Administrative Offences. (2017, June). Retrieved from https://zakon.rada.gov.ua/laws/show/807310#Text.
  14. Colorado Privacy Act. (2021, July). Retrieved from https://www.consumerprivacyact.com/colorado-privacy-act-cpa/.
  15. Commission Staff Working Document: Ukraine 2025 Report. Accompanying the Document Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions: 2025 Communication on EU enlargement policy. (2025, November). Retrieved from https://eur-lex.europa.eu/ legal-content/EN/TXT/?uri=celex:52025SC0759.
  16. Commissioner for Human Rights of the Verkhovna Rada of Ukraine. (n.d.). Annual report of the Commissioner for Human Rights of the Verkhovna Rada of Ukraine on the state of observance and protection of human and civil rights and freedoms in Ukraine in 2024. Retrieved from https://www.ombudsman.gov.ua/storage/app/media/uploaded-files.
  17. Constitution of Ukraine. (1996, June). Retrieved from https://zakon.rada.gov.ua/laws/show/en/254%D0%BA/96%D0%B2%D1%80#Text.
  18. Council of Europe. (n.d.). Supporting the implementation of European human rights standards in Ukraine: Phase IІ. Retrieved from https://www.coe.int/uk/web/kyiv/supporting-implementation-of-the-european-human-rights-standards-in-ukraine/.
  19. Criminal Code of Ukraine. (2001, April). Retrieved from https://zakon.rada.gov.ua/laws/show/2341-14#Text.
  20. Cura, M., Loureiro, R., Marcelino, P., Rodrigues, V., & Andrade, J.P. (2026). General data protection regulation: An algorithmic proposal for forensic photography. International Journal of Legal Medicine, 140, 1689-1697. doi: 10.1007/s00414025-03640-w.
  21. Darmayanti, E.S., & Subiyanto, A.E. (2026). Criminal liability for the sale of civil servant data based on the personal data protection law. Interdisciplinary Social Studies, 5(2), 884-894. doi: 10.55324/iss.v5i2.1011.
  22. Data Privacy Framework Program. (n.d.). Data Privacy Framework (DPF) overview. Retrieved from https://www. dataprivacyframework.gov/Program-Overview.
  23. Decision of the Constitutional Court of Ukraine No. v002p710-12 “In the Case on the Constitutional Submission of the Zhashkiv District Council of Cherkasy Region on the Official Interpretation of the Provisions of Parts One, Two of Article 32, Parts Two, Three of Article 34 of the Constitution of Ukraine”. (2012, January). Retrieved from https://zakon.rada.gov.ua/laws/show/ v002p710-12#Text.
  24. Deepanshu, & Kumar, A. (2026). Corporate liability for data breaches under the Digital Personal Data Protection Act, 2023: Legal challenges and regulatory responses. Vistas: International Journal of Multidisciplinary Studies, 1(1), 103-121. doi: 10.5281/ zenodo.18385783.
  25. DLA Piper GDPR Fines and Data Breach Survey: January 2026. (2026). Retrieved from https://www.dlapiper.com/en/insights/ publications/2026/01/dla-piper-gdpr-fines-and-data-breach-survey-january-2026.
  26. Draft Labour Code of Ukraine. (2026, January). Retrieved from https://itd.rada.gov.ua/billinfo/Bills/Card/69516.
  27. Draft Law No. 6177 “On the National Commission for Personal Data Protection and Access to Public Information”. (2021, October). Retrieved from https://itd.rada.gov.ua/billinfo/Bills/Card/27996.
  28. European Data Protection Board. (2026). Report on international data protection enforcement cooperation. Retrieved from https://www.edpb.europa.eu/our-work-tools/our-documents/support-pool-experts-projects/report-international-dataprotection_en.
  29. Faccioli, M. (2026). Liability for unlawful personal data processing. In R. Bocchini (Ed.), Digital platforms-from technical foundations to legal and economic implications: Volume 1 (pp. 745-763). Cham: Springer. doi: 10.1007/978-3-032-07978-7_34.
  30. Faisal, K. (2026). Navigating the fine line: The complex reconciliation of data protection and freedom of expression in criminal conviction and offences data. Digital Policy, Regulation and Governance, 28(1), 17-34. doi: 10.1108/DPRG-10-2024-0260.
  31. Federal Commissioner for Data Protection and Freedom of Information. (2025). Activity report 2024: 33rd activity report on data protection and freedom of information. Retrieved from https://www.bfdi.bund.de/SharedDocs/Downloads/EN/ Taetigkeitsberichte/33TB_24.pdf?__blob=publicationFile&v=2.
  32. Federal Data Protection Act. (2017, June). Retrieved from https://www.gesetze-im-internet.de/englisch_bdsg/englisch_bdsg. html.
  33. Federal Trade Commission Act. (2006, December). Retrieved from https://www.ftc.gov/sites/default/files/documents/ statutes/federal-trade-commission-act/ftc_act_incorporatingus_safe_web_act.pdf.
  34. Gatti, S. (2026). Accountability principle and its implementation in the general data protection regulation. In R. Bocchini (Ed.), Digital platforms-from technical foundations to legal and economic implications (pp. 709-729). Cham: Springer. doi: 10.1007/9783-032-07978-7_32.
  35. Health Insurance Portability and Accountability Act of 1996. (1996, August). Retrieved from https://aspe.hhs.gov/reports/ health-insurance-portability-accountability-act-1996.
  36. Hennig, A., Schulte, L., Herbold, S., Kulyk, O., & Mayer, P. (2026). The whos, whats, and whys of issues related to personal data and data protection in open-source projects on GitHub. Empirical Software Engineering, 31(1), article number 9. doi: 10.1007/ s10664-025-10742-x.
  37. Joshi, U., Baisil, S., Kini B, S., Mehta, M., & Datta, S. (2026). AI ethics in Indian healthcare: A scoping review of national and international guidelines on privacy, data protection, and security. BMC Medical Ethics, 27(1), article number 86. doi: 10.1186/ s12910-026-01435-1.
  38. Karpyn, D., Leshko, R., Karpyn, A., Leshko, O., Voytovych, K.H., & Hoyvanovych, N. (2026). Cybersecurity. Protection of personal data, digital devices and access to resources. Drohobych: Drohobych Ivan Franko State Pedagogical University.
  39. Klymchuk, O.V., & Yaremenko, O.I. (2026). Harmonization of domestic legislation to European standards of cybersecurity and personal data protection: Challenges for public authorities. Current Issues in Modern Science, 44(2), 410-423.
  40. Kristanto, A.R., & Slamet, S.R. (2026). Legal liability of financial services institutions for personal data leakage under the Personal Data Protection Act. Golden Ratio of Data in Summary, 6(1), 83-90. doi: 10.52970/grdis.v6i1.1981.
  41. Law of Ukraine No. 1089-IX “On Electronic Communications”. (2020, December). Retrieved from https://zakon.rada.gov.ua/ laws/show/1089-IX#Text.
  42. Law of Ukraine No. 2163-VIII “On the Basic Principles of Cybersecurity in Ukraine”. (2017, October). Retrieved from https:// zakon.rada.gov.ua/laws/show/en/2163-19#Text.
  43. Law of Ukraine No. 2297-VI “On Personal Data Protection”. (2010, June). Retrieved from https://zakon.rada.gov.ua/laws/ show/2297-17#Text.
  44. Law of Ukraine No. 2657-XII “On Information”. (1992, October). Retrieved from https://zakon.rada.gov.ua/laws/show/265712#Text.
  45. Law of Ukraine No. 2939-VI “On Access to Public Information”. (2011, January). Retrieved from https://zakon.rada.gov.ua/ laws/show/en/2939-17#Text.
  46. Law of Ukraine No. 80/94-VR “On Information Protection in Information and Communication Systems”. (1994, July). Retrieved from https://zakon.rada.gov.ua/laws/show/80/94-%D0%B2%D1%80#Text.
  47. Law of Ukraine No. 851-IV “On Electronic Documents and Electronic Document Management”. (2003, May). Retrieved from https://zakon.rada.gov.ua/laws/show/851-15#Text.
  48. New York Privacy Act. (2022, February). Retrieved from https://www.consumerprivacyact.com/new-york-privacy-act/.
  49. Ombudsman of Ukraine. (2014). Typical procedure for processing personal data. Retrieved from https://ombudsman.gov.ua/uk/ rekomendaciyi-ta-rozyasnennya/tipovij-poryadok-obrobki-personalnih-danih.
  50. Poscher, R., & Orrù, E. (2026). Data protection and privacy: Digitalisation, power, and the transatlantic divide. In Conceptions of data protection and privacy: Legal and philosophical perspectives (pp. 1-12). Oxford: Hart Publishing. doi: 10.5040/9781509983759.0005.
  51. Q2 2025 privacy & data protection regulatory enforcement report. (2025). Retrieved from https://compliancehub.wiki/q22025-privacy-data-protection-regulatory-enforcement-report.
  52. Qinvi, N.U., Ahmad, R.S., & Wahyunisa, H. (2026). Personal data protection in an artificial intelligence – based photo marketplace on the FotoYu Platform. Journal of Cyber Law and Technology Regulation, 1(1), 1-11.
  53. Regulation (EU) No. 2016/679 of the European Parliament and of the Council “On the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data, and Repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance)”. (2016, April). Retrieved from https://zakon.rada.gov.ua/ laws/show/984_008-16#Text.
  54. Regulation (EU) No. 2024/1689 of the European Parliament and of the Council “Laying Down Harmonised Rules on Artificial Intelligence and Amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (Text with EEA Relevance)”. (2024. June). Retrieved from https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng.
  55. Resolution of the Verkhovna Rada of Ukraine No. 4065-IX “On Adopting as a Basis the draft Law of Ukraine on Personal Data Protection”. (2024, November). Retrieved from https://zakon.rada.gov.ua/laws/show/4065-20#Text.
  56. Şakar, A.Y., & Bağce, D.H.A. (2026). Assessment of the personal data protection board’s decision on a data breach committed by an airline company. Journal of Aviation, 10(1), 71-76. doi: 10.30518/jav.1770648.
  57. Siddiqui, A. (2026). Data protection and privacy in the digital age: Comparative perspectives on India’s digital Personal Data Protection Act and the EU General Data Protection Regulation. SSRN. doi: 10.2139/ssrn.6050296.
  58. Singal, S., & Chorev, N. (2026). Free markets, high walls: Data protection and the question of post-neoliberalism. SocioEconomic Review, 2026, article number mwaf094. doi: 10.1093/ser/mwaf094.
  59. Singh, P., Kumar, S., Singh, S.K., & Singh, H. (2026). Privacy in mental healthcare by data protection: Exploring AI-powered psychological assessment and identity crisis intervention with legal provisions. In L.R. Janjua, K. Edina & B. Singh (Eds.), Imposter syndrome and AI: Navigating human identity in the age of intelligent machines (pp. 327-346). Hershey: IGI Global Scientific Publishing. doi: 10.4018/979-8-3373-6618-0.ch017.
  60. Smith, C., & Hawkins, R. (2026). Arguing conformance with data protection principles. arXiv. doi: 10.48550/arXiv.2601.15155.
  61. Strelnyk, V., & Brazhnichenko, I.E. (2022). General theoretycal aspeсts of legal regulation of personal data protecton in legislation of Ukraine. Legal Scientific Electronic Journal, 10, 215-217. doi: 10.32782/2524-0374/2022-10/50.
  62. Suciara, A., Idias, B., Siregar, N.J., Siregar, T.A.F., & Prabowo, T.W. (2026). Strict liability vs fault based: Perbandingan Indonesia dengan Jepang terhadap kebocoran data. Al-Zayn: Journal of Social Sciences & Law, 4(1), 739-749.
  63. Surzhynskyi, M. (2025). Challenges and opportunities for adapting Ukrainian legislation to European standards for personal data protection in the field of artificial intelligence. Law of Ukraine, 4, 26-37. doi: 10.33498/louu-2025-04-026.
  64. The 2025 privacy & compliance “Fines & Follies” awards: A year of record-breaking enforcement. (2025). Retrieved from https://compliancehub.wiki/the-2025-privacy-compliance-fines-follies-awards-a-year-of-record-breaking-enforcement.
  65. Thomas, L., Gondal, I., Oseni, T., & Firmin, S. (2022). A framework for data privacy and security accountability in data breach communications. Computers & Security, 116, article number 102657. doi: 10.1016/j.cose.2022.102657.
  66. Tolson, B. (2026). Compliance U.S. data privacy laws and regulations in 2026. Retrieved from https://www.smarsh.com/blog/ thought-leadership/data-privacy-laws/.
  67. Understanding data privacy laws: A 2026 compliance guide. (2026). Retrieved from https://www.tekclarion.com/cybersecurity/data-privacy-laws-2026/.