2025
MAY
NEW RENAISSANCE
INTERNATIONAL SCIENTIFIC AND PRACTICAL CONFERENCE
VOLUME 2
|
ISSUE 5
575
PROCESSING AND PROTECTION OF PERSONAL DATA ON WEBSITES:
COMPARATIVE ANALYSIS OF REGULATORY APPROACHES AND
TECHNICAL SOLUTIONS
Saidov B.B.
Tashkent State University of Law, Department of Cyber Law, Uzbekistan.
Contact:
boburbahromovich.s@gmail.com
https://doi.org/10.5281/zenodo.15511527
Introduction
The rapid development of digital technologies and the widespread implementation of
online services have led to an exponential growth in the volume of personal data processed on
websites. Modern web platforms collect, store, and process vast amounts of user information
daily, including identification data, behavioral patterns, geolocation information, and biometric
indicators. This research analyzes the complex issues of personal data protection in the context
of the web ecosystem, examining both regulatory mechanisms and technical solutions used to
ensure information confidentiality. Particular attention is paid to differences in approaches
between jurisdictions, issues of cross-border data transfer, the balance between personal data
protection and innovative development of digital services, as well as challenges associated with
implementing the concept of "privacy by design" in web development practice.
Methodology
The research is based on a comprehensive methodology combining qualitative and
quantitative analysis. The legal analysis covers personal data protection legislation in 32
jurisdictions, including detailed study of the GDPR (EU), CCPA/CPRA (California), LGPD
(Brazil), PIPL (China), and the Law of the Republic of Uzbekistan "On Personal Data". The
technical component of the research includes compliance audits of 150 popular websites with
privacy requirements and evaluation of the effectiveness of applied data protection
technologies. Semi-structured interviews were conducted with 56 experts representing various
stakeholders: web platform developers (18), information security specialists (14), regulators
(11), lawyers (8), and representatives of user rights protection organizations (5). To assess user
perception, an online survey of 2,800 internet users from 12 countries was conducted,
measuring the level of awareness about personal data protection rights and trust in existing
protection mechanisms.
Results
2025
MAY
NEW RENAISSANCE
INTERNATIONAL SCIENTIFIC AND PRACTICAL CONFERENCE
VOLUME 2
|
ISSUE 5
576
The study conducted within this research project revealed notable variations in personal
data processing practices both between different jurisdictions and across sectors of the web
industry. According to our findings, a significant proportion of the analyzed websites collect
more personal data than necessary for their stated purposes, which raises concerns regarding
compliance with data minimization principles. The research identified implementation issues
with consent mechanisms, with many sites employing design patterns that guide users toward
providing maximal data access. Technical assessment revealed that less than half of the
examined web resources implement adequate encryption for stored personal data, while a
substantial number exhibit vulnerabilities in their authentication mechanisms. Notably,
websites compliant with GDPR requirements demonstrate measurably stronger data protection
metrics even when operating outside EU jurisdictions, suggesting a harmonizing influence of
European regulations on global data protection practices. The study also identified a knowledge
gap between legal requirements and technical implementations: a majority of interviewed web
developers reported challenges in understanding legal aspects of data protection, while legal
professionals acknowledged limitations in their technical understanding of privacy solutions.
Impact Assessment
Analysis of the economic consequences of data protection regulation indicates a dual
impact: initial compliance investments represent a significant portion of IT budgets, particularly
burdensome for smaller businesses, while potentially yielding long-term benefits through
enhanced user trust and reduced risk exposure from data breaches. Our cross-cultural analysis
identified regional variations in privacy concerns, with European respondents demonstrating
the highest levels of privacy consciousness, followed by North American participants, while
Asian respondents showed comparatively lower concern levels. Research participants
expressed conditional willingness to provide personal data for personalized services when
offered transparency and effective control mechanisms. The study noted that regulatory
requirements affect innovation timelines, with approximately half of surveyed companies
reporting delays in feature implementation due to uncertainties in interpreting data protection
requirements.
Privacy Enhancement Framework
Based on the results obtained, an integrated personal data management structure for
websites has been developed, based on three key components: (1) a multi-level consent system
adapted to different types of personal data and contexts of their use; (2) built-in technical
solutions for privacy protection, including anonymization, pseudonymization, and differential
2025
MAY
NEW RENAISSANCE
INTERNATIONAL SCIENTIFIC AND PRACTICAL CONFERENCE
VOLUME 2
|
ISSUE 5
577
privacy; (3) transparency and accountability mechanisms for users and regulators. The proposed
structure has undergone pilot testing on 8 websites of various categories, demonstrating
significant improvement in data protection indicators while maintaining functionality and ease
of use. Special attention is paid to the scalability of the solution for organizations of different
sizes, with differentiated recommendations for large corporations, medium-sized businesses,
and startups.
Conclusion
The research demonstrates the need for a comprehensive approach to personal data
protection on websites, combining legal, technical, and organizational measures. The deepening
fragmentation of regulatory regimes creates significant challenges for global web services,
requiring the development of flexible and adaptive compliance systems. Bridging the gap
between legal and technical aspects of data protection through interdisciplinary collaboration
and educational initiatives becomes critically important. In the context of the rapid development
of technologies such as machine learning, the Internet of Things, and distributed ledgers,
traditional approaches to personal data protection require substantial rethinking and adaptation.
Further research is needed to develop dynamic privacy risk assessment models that take
into account contextual factors and the evolving nature of digital threats. The proposed personal
data management structure represents an important step towards a more effective and integrated
privacy protection system in the web ecosystem.
References
1.
European Data Protection Board. (2023). Guidelines 01/2023 on Data Subject Rights -
Right
of
Access.
https://edpb.europa.eu/our-work-tools/our-
documents/guidelines/guidelines-012023-data-subject-rights-right-access_en
2.
ISO/IEC. (2019). ISO/IEC 27701:2019 - Security techniques — Extension to ISO/IEC
27001
and
ISO/IEC
27002
for
privacy
information
management.
https://www.iso.org/standard/71670.html
3.
California Privacy Protection Agency. (2023). California Privacy Rights Act (CPRA)
Regulations. https://cppa.ca.gov/regulations/
4.
World Wide Web Consortium. (2023). Privacy Principles for the Web (W3C Working
Draft). https://www.w3.org/TR/privacy-principles/
5.
Cabinet of Ministers of the Republic of Uzbekistan. (2021). Resolution "On Measures
to Ensure the Protection of Personal Data". https://lex.uz/docs/5275707