This year, on 28 January, the world celebrates the Data Protection Day and the 40th anniversary of the Council of Europe's Convention 108 for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108).
Happy 40th Anniversary Convention 108! #dataprotection from Council of Europe OP Services on Vimeo.
Issues of personal data protection are constantly present in people’s daily life: at work, in their relations with public authorities, in the health field, when they buy goods or services, travel, or surf the internet. However, individuals are generally unfamiliar with their rights in this respect, which poses a threat to their privacy and creates risks of improper processing of personal data.
Experts of the Joint Project “European Union and Council of Europe working together to strengthen the Ombudsperson’s capacity to protect human rights” have prepared practical answers on what personal data is and how to protect it from attackers.
What data is personal?
Answer given by Oleksandr Shevchuk, expert of the Joint Project “European Union and Council of Europe working together to strengthen the Ombudsperson’s capacity to protect human rights”
The definition of personal data includes any information relating to a particular person. This applies not only to names, addresses, and contact details but also to anything that can help identify a person (such as IP address, location data, videos, social media posts, and photos).
You may think that a person's name is always personal information, but it's not that simple. The name “Dmytro Ivanov” itself cannot always be considered as personal data, as there are many people with such a name. However, when a name is combined with other information, such as a home address, work address, or phone number, this will usually be sufficient to identify the individual.
In certain circumstances, a person's hair color, place of work, or political views may be considered as personal data. Information that can be personal data is often considered in the context in which the data is collected.
How to protect your personal data?
Answer provided by Oleg Zayarnyi, expert of the Joint Project “European Union and Council of Europe working together to strengthen the Ombudsperson’s capacity to protect human rights”
- Before giving consent to the processing of personal data it is important to read the purpose, procedures of personal data processing, as well as the privacy policy regarding such processing.
- Avoid any processing of personal data if you are required to give irrevocable or unconditional consent to the processing of personal data, or if you are refused to communicate the purpose and procedures of personal data processing.
- Do not allow the processing of personal data if you are required to provide more personal information than is required to fulfill the purpose of the personal data processing communicated to you. Exceptions to this rule may be determined only by law.
- Do not share personal information with people you are not planning to enter into a legal transaction, as well as provide for digital services that you use the minimum necessary set of data to use these services.
- After you have terminated your relationship with the owner of the personal data, i.e. the person authorized by law or contract to determine the purpose and grounds for the processing of personal data, request the removal or destruction of information about yourself.
How to protect personal data when surfing the Internet?
Answer given by Borys Kormych, expert of the Joint Project “European Union and Council of Europe working together to strengthen the Ombudsperson’s capacity to protect human rights”
- “Once online - always online”. Pay attention to personal data that you post on social networks or other publicly available resources. Even after deleting them, you cannot guarantee that this data has not been saved by other persons or resources.
- "Review privacy policies". Please note that just one click on a button or checkbox equates to consent to the processing of personal data. It is important to read the user agreements or privacy policies of the sites or applications. Or at least try to determine what data the site or application is requesting. Are you satisfied with the provision of such information? Is this information needed for the purpose you use this site or application?
- “Check settings”. Your computer or smartphone, accounts, and applications have privacy settings. You can limit the categories and the amount of data they are allowed to collect. Pay special attention to the settings for online payment methods, geolocation, images, phone number.
- “Delete accounts”. Deleting an application from your smartphone or computer does not mean deleting your data. If you wish to discontinue the processing of personal data, make sure that you have followed the rules of the site owner or application regarding the complete deletion of your account.
- “Dispose of devices securely”. Before disposing of or selling your computer or smartphone, make sure that all personal data on it is securely removed. Do this according to the manufacturer's recommendations or use appropriate programs.
What legislation regulates the protection of personal data in Ukraine?
Answer given by Oleg Zayarnyi, expert of the Joint Project “European Union and Council of Europe working together to strengthen the Ombudsperson’s capacity to protect human rights”
In Ukraine, the standards of legal regulation of relations concerning the processing and protection of personal data are laid down in such acts of the Council of Europe as the Convention for the Protection of Human Rights and Fundamental Freedoms and the Convention 108.
In addition to the above-mentioned international legal acts, in our country, the relation concerning the processing and protection of personal data are regulated by the Constitution of Ukraine, in particular Article 32, the Law of Ukraine “On Personal Data Protection”, other laws of Ukraine and bylaws in certain areas of social activity.
Which body in Ukraine is responsible for the protection of personal data?
Answer given by Oleg Zayarnyi, expert of the Joint Project “European Union and Council of Europe working together to strengthen the Ombudsperson’s capacity to protect human rights”
The state body responsible for ensuring the protection of personal data in Ukraine is the Ukrainian Parliament Commissioner for Human Rights.
Complaints against decisions, actions, or omissions of owners and controllers of personal data, notification of the start of processing of personal data, which poses a special risk to the rights of personal data subjects, are submitted to the Commissioner.
The Ukrainian Parliament Commissioner for Human Rights is empowered to inspect the activities of owners and controllers of personal data, draw up reports on administrative offenses in the field of personal data processing, send relevant materials to court to bring the perpetrators to administrative responsibility.
This state body exercises not only control and supervisory powers. The Ukrainian Parliament Commissioner for Human Rights also monitors compliance with the legislation on personal data protection throughout Ukraine, conducts a broad educational campaign in this area, and cooperates with supervisory authorities of other states on the processing and protection of personal data
The publication was created in the framework of the Joint Project “EU and Council of Europe working together to strengthen the Ombudsperson’s capacity to protect human rights”. The project is aimed at ensuring better protection of human rights in Ukraine and enhancing operational capacities of the Ombudsperson’s Office in particular in the area of ensuring the protection of the right to privacy and personal data.
The views expressed herein can in no way be taken to reflect the official opinion of the European Union or Council of Europe.



