Authors

  • B.B. Saidov

DOI:

https://doi.org/10.71337/inlibrary.uz.science-research.96605

Keywords:

The legal analysis covers personal data protection legislation in 32 jurisdictions including detailed study of the GDPR (EU) CCPA CPRA (California) LGPD (Brazil) PIPL (China) and the Law of the Republic of Uzbekistan

Abstract

The rapid development of digital technologies and the widespread implementation of online services have led to an exponential growth in the volume of personal data processed on websites. Modern web platforms collect, store, and process vast amounts of user information daily, including identification data, behavioral patterns, geolocation information, and biometric indicators. This research analyzes the complex issues of personal data protection in the context of the web ecosystem, examining both regulatory mechanisms and technical solutions used to ensure information confidentiality. Particular attention is paid to differences in approaches between jurisdictions, issues of cross-border data transfer, the balance between personal data protection and innovative development of digital services, as well as challenges associated with implementing the concept of "privacy by design" in web development practice.

background image

2025

MAY

NEW RENAISSANCE

INTERNATIONAL SCIENTIFIC AND PRACTICAL CONFERENCE

VOLUME 2

|

ISSUE 5

575

PROCESSING AND PROTECTION OF PERSONAL DATA ON WEBSITES:

COMPARATIVE ANALYSIS OF REGULATORY APPROACHES AND

TECHNICAL SOLUTIONS

Saidov B.B.

Tashkent State University of Law, Department of Cyber Law, Uzbekistan.

Contact:

boburbahromovich.s@gmail.com

https://doi.org/10.5281/zenodo.15511527

Introduction

The rapid development of digital technologies and the widespread implementation of

online services have led to an exponential growth in the volume of personal data processed on

websites. Modern web platforms collect, store, and process vast amounts of user information

daily, including identification data, behavioral patterns, geolocation information, and biometric

indicators. This research analyzes the complex issues of personal data protection in the context

of the web ecosystem, examining both regulatory mechanisms and technical solutions used to

ensure information confidentiality. Particular attention is paid to differences in approaches

between jurisdictions, issues of cross-border data transfer, the balance between personal data

protection and innovative development of digital services, as well as challenges associated with

implementing the concept of "privacy by design" in web development practice.

Methodology

The research is based on a comprehensive methodology combining qualitative and

quantitative analysis. The legal analysis covers personal data protection legislation in 32

jurisdictions, including detailed study of the GDPR (EU), CCPA/CPRA (California), LGPD

(Brazil), PIPL (China), and the Law of the Republic of Uzbekistan "On Personal Data". The

technical component of the research includes compliance audits of 150 popular websites with

privacy requirements and evaluation of the effectiveness of applied data protection

technologies. Semi-structured interviews were conducted with 56 experts representing various

stakeholders: web platform developers (18), information security specialists (14), regulators

(11), lawyers (8), and representatives of user rights protection organizations (5). To assess user

perception, an online survey of 2,800 internet users from 12 countries was conducted,

measuring the level of awareness about personal data protection rights and trust in existing

protection mechanisms.

Results


background image

2025

MAY

NEW RENAISSANCE

INTERNATIONAL SCIENTIFIC AND PRACTICAL CONFERENCE

VOLUME 2

|

ISSUE 5

576

The study conducted within this research project revealed notable variations in personal

data processing practices both between different jurisdictions and across sectors of the web

industry. According to our findings, a significant proportion of the analyzed websites collect

more personal data than necessary for their stated purposes, which raises concerns regarding

compliance with data minimization principles. The research identified implementation issues

with consent mechanisms, with many sites employing design patterns that guide users toward

providing maximal data access. Technical assessment revealed that less than half of the

examined web resources implement adequate encryption for stored personal data, while a

substantial number exhibit vulnerabilities in their authentication mechanisms. Notably,

websites compliant with GDPR requirements demonstrate measurably stronger data protection

metrics even when operating outside EU jurisdictions, suggesting a harmonizing influence of

European regulations on global data protection practices. The study also identified a knowledge

gap between legal requirements and technical implementations: a majority of interviewed web

developers reported challenges in understanding legal aspects of data protection, while legal

professionals acknowledged limitations in their technical understanding of privacy solutions.

Impact Assessment

Analysis of the economic consequences of data protection regulation indicates a dual

impact: initial compliance investments represent a significant portion of IT budgets, particularly

burdensome for smaller businesses, while potentially yielding long-term benefits through

enhanced user trust and reduced risk exposure from data breaches. Our cross-cultural analysis

identified regional variations in privacy concerns, with European respondents demonstrating

the highest levels of privacy consciousness, followed by North American participants, while

Asian respondents showed comparatively lower concern levels. Research participants

expressed conditional willingness to provide personal data for personalized services when

offered transparency and effective control mechanisms. The study noted that regulatory

requirements affect innovation timelines, with approximately half of surveyed companies

reporting delays in feature implementation due to uncertainties in interpreting data protection

requirements.

Privacy Enhancement Framework

Based on the results obtained, an integrated personal data management structure for

websites has been developed, based on three key components: (1) a multi-level consent system

adapted to different types of personal data and contexts of their use; (2) built-in technical

solutions for privacy protection, including anonymization, pseudonymization, and differential


background image

2025

MAY

NEW RENAISSANCE

INTERNATIONAL SCIENTIFIC AND PRACTICAL CONFERENCE

VOLUME 2

|

ISSUE 5

577

privacy; (3) transparency and accountability mechanisms for users and regulators. The proposed

structure has undergone pilot testing on 8 websites of various categories, demonstrating

significant improvement in data protection indicators while maintaining functionality and ease

of use. Special attention is paid to the scalability of the solution for organizations of different

sizes, with differentiated recommendations for large corporations, medium-sized businesses,

and startups.

Conclusion

The research demonstrates the need for a comprehensive approach to personal data

protection on websites, combining legal, technical, and organizational measures. The deepening

fragmentation of regulatory regimes creates significant challenges for global web services,

requiring the development of flexible and adaptive compliance systems. Bridging the gap

between legal and technical aspects of data protection through interdisciplinary collaboration

and educational initiatives becomes critically important. In the context of the rapid development

of technologies such as machine learning, the Internet of Things, and distributed ledgers,

traditional approaches to personal data protection require substantial rethinking and adaptation.

Further research is needed to develop dynamic privacy risk assessment models that take

into account contextual factors and the evolving nature of digital threats. The proposed personal

data management structure represents an important step towards a more effective and integrated

privacy protection system in the web ecosystem.

References

1.

European Data Protection Board. (2023). Guidelines 01/2023 on Data Subject Rights -

Right

of

Access.

https://edpb.europa.eu/our-work-tools/our-

documents/guidelines/guidelines-012023-data-subject-rights-right-access_en

2.

ISO/IEC. (2019). ISO/IEC 27701:2019 - Security techniques — Extension to ISO/IEC

27001

and

ISO/IEC

27002

for

privacy

information

management.

https://www.iso.org/standard/71670.html

3.

California Privacy Protection Agency. (2023). California Privacy Rights Act (CPRA)

Regulations. https://cppa.ca.gov/regulations/

4.

World Wide Web Consortium. (2023). Privacy Principles for the Web (W3C Working

Draft). https://www.w3.org/TR/privacy-principles/

5.

Cabinet of Ministers of the Republic of Uzbekistan. (2021). Resolution "On Measures

to Ensure the Protection of Personal Data". https://lex.uz/docs/5275707

References

European Data Protection Board. (2023). Guidelines 01/2023 on Data Subject Rights - Right of Access. https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-012023-data-subject-rights-right-access_en

ISO/IEC. (2019). ISO/IEC 27701:2019 - Security techniques — Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management. https://www.iso.org/standard/71670.html

California Privacy Protection Agency. (2023). California Privacy Rights Act (CPRA) Regulations. https://cppa.ca.gov/regulations/

World Wide Web Consortium. (2023). Privacy Principles for the Web (W3C Working Draft). https://www.w3.org/TR/privacy-principles/

Cabinet of Ministers of the Republic of Uzbekistan. (2021). Resolution "On Measures to Ensure the Protection of Personal Data". https://lex.uz/docs/5275707