Kostiuk D. Administrative and legal protection of personal data in the context of digitalization of public administration

Українська версія

Thesis for the degree of Doctor of Philosophy (PhD)

State registration number

0826U004250

Applicant for

Specialization

  • 081 - Право

Specialized Academic Board

PhD 16783

Academician FG Burchak Research Institute of Private Law and Entrepreneurship of the National Academy of Legal Sciences of Ukraine

Essay

The dissertation is devoted to a comprehensive study of the administrative and legal protection of personal data in the context of the digitalization of public administration. In the first section "General characteristics of the administrative and legal protection of personal data in the sphere of public administration" the conceptual foundations of the protection of personal data as an object of administrative and legal protection are investigated, the impact of digitalization on the transformation of legal relations in this sphere is revealed and the mechanisms of influence of international standards on national administrative legislation are determined. It is substantiated that personal data is a specific object of administrative and legal protection, different from the objects of constitutional and civil law regulation. The author's definition of personal data in the context of public administration is proposed, which takes into account the specifics of the subjects of processing, the legal basis and the dual purpose of exercising public authority powers and ensuring the rights of the individual, and also reflects the reality of processing through digital technologies and integrated information systems. The digitalization of public administration is considered as a factor of qualitative transformation of legal relations in the field of personal data protection, which includes a change in the subject composition of legal relations, the nature of their object, the content of the rights and obligations of the parties and the nature of the legal relationship between the state and the citizen. The architecture of international and supranational standards for the protection of personal data is studied, which includes Convention 108+ as an instrument of international law and acts of secondary EU law - GDPR, Directive 2016/680, Data Governance Act and EU AI Act - as interconnected instruments. The second section, “The content of administrative and legal support for personal data protection in the context of digitalization of public administration,” examines the regulatory and legal basis, subject composition, and procedural elements of the mechanism for protecting personal data in the field of digital public administration. The regulatory and legal regulation of personal data protection in the field of digital public administration is characterized and its structural imbalance between the rapid development of legislation on digital public services and registers and the chronic lag of special legislation on personal data protection is established. The system of subjects for ensuring personal data protection in the field of public administration is studied and their classification is carried out according to functional criteria, taking into account the specifics of digital public administration. The content of administrative procedures for processing personal data in digital public administration systems is disclosed and their qualitative difference from traditional administrative procedures is established. It was determined that the legal regulation of such procedures should be based on the requirements of transparency of algorithmic decisions, accountability of all processing entities and real accessibility of mechanisms for protecting the rights of personal data subjects in accordance with the standards of the GDPR and the practice of the ECHR. The third section, “Improving the administrative and legal support for the protection of personal data in the context of the digitalization of public administration,” examines practical problems of law enforcement in the field of personal data protection, identifies systemic legal gaps in the regulation of electronic public services, and identifies mechanisms and priorities for harmonizing Ukrainian legislation with European Union law. The state of law enforcement in the field of administrative liability for violations of personal data protection legislation is analyzed and the phenomenon of a “dead norm” is established, which consists in the fact that with thousands of appeals from personal data subjects, real prosecution is rare. Proposals for reforming the administrative liability system based on the model of the two-tier structure of the GDPR with differentiation of sanctions depending on the severity of the violation and the simultaneous introduction of simplified proceedings and a special procedure for collecting digital evidence are substantiated. The legal regime for the protection of personal data in electronic public service systems is characterized and it is established that the problems of the "Diia" platform, the "Trembita" system and the "Oberig" registry have a common systemic cause - the lack of preventive legal instruments at the stage of designing and launching public digital services.

Research papers

Костюк Д. І. Адміністративні процедури обробки персональних даних у системах міжвідомчого електронного обміну. Приватне право і підприємництво. 2026. Вип. 26. С. 178–185. DOI: https://doi.org/10.32849/2409-9201.2026.26.19. URL: https://ppp-journal.kiev.ua/index.php/26-2026

Костюк Д. І. Нормативно-правове регулювання обробки персональних даних у публічних електронних реєстрах України. Актуальні проблеми правознавства. 2026. № 1 (45). С. 98–105. DOI: https://doi.org/10.35774/app2026.01.098. URL: https://appj.wunu.edu.ua/index.php/appj/article/view/2265

Костюк Д. І. Правовий статус платформи «Дія» як суб’єкта обробки персональних даних. Журнал східноєвропейського права. 2026. № 145. С. 321–328. DOI: https://doi.org/10.71404/2409-6415.145.36. URL: https://easternlaw.com.ua/wp-content/uploads/2026/04/kostiuk_145.pdf

Костюк Д. І. Імплементація стандартів конвенції 108+ та GDPR в адміністративне законодавство України. Україна в умовах реформування правової системи: сучасні реалії та міжнародний досвід: матеріали IX Міжнародної науково-практичної конференції (м. Тернопіль, 2–3 травня 2025 р.). Тернопіль: ЗУНУ, 2025. С. 346–348. URL: https://confuf.wunu.edu.ua/index.php/confuf/article/view/1732/1711

Костюк Д. І. Наглядовий орган у сфері захисту персональних даних: стандарти незалежності та перспективи інституційної реформи в Україні. Людина, суспільство, держава: актуальні питання правового регулювання взаємодії: тези доп. учасників. ІІ наук.-практ. конф. (Київ, 21 лист. 2025 р.). Київ: 2025. С. 65–67. DOI: https://doi.org/10.71404/PPSS.2025.3.18. URL: https://library.pp-ss.pro/index.php/ndippsn_20251121/article/view/kostiuk/pdf

Костюк Д. І. Персональні дані як об’єкт адміністративно-правової охорони. Актуальні проблеми приватного та публічного права : матеріали VІІI Міжнародної науково-практичної конференції присвяченої 97-річчю від дня народження члена-кореспондента НАПрН України, академіка Міжнародної кадрової академії, заслуженого діяча науки України, доктора юридичних наук, професора О. І. Процевського, Харків, 27 березня 2026 року. Харківський національний педагогічний університет імені Г. С. Сковороди, Україна. Видавництво: ХНПУ імені Г. С. Сковороди, 2026. С. 505–507.

Files

Similar theses