Section navigation

PATHWAYS TO REPARATION

Digital navigation without excessive data collection

Explaining a general application pathway does not require first obtaining a passport, medical records or a history of harm. Data protection rules support a practical conclusion: design information navigation without collecting case files, and organise individual assistance as a separate process with its own legal grounds and safeguards.

Published

Question, sources and method

This note asks what information a civil society or charitable organisation actually needs to help someone locate a rule and their next step. It compares Ukraine’s Law on Personal Data Protection, GDPR Articles 2–6, 9, 25, 28, 32, 35 and 44, and the European Data Protection Board’s territorial-scope guidance. The rules are applied to four situations: reading a library, reporting an error, individual assistance and usability assessment. [1] [2] [3]

This is document analysis, not a survey of affected people or a measurement of service effectiveness. The comparison asks whether particular data are necessary for a defined purpose, who receives them and what risks storage or transfer create.

1. Minimisation starts with purpose

Ukrainian law covers automated processing and non-automated processing of data in, or intended for, a filing system. Article 6 requires a specific lawful purpose, appropriate and non-excessive data, and retention no longer than necessary for lawful purposes. Where the GDPR applies, Article 5 establishes related principles and Article 25 requires their implementation through design and default settings. [1] [2]

The editorial conclusion is practical: selecting the general topic “damaged housing” only requires a link to the relevant page. The owner’s name, property address and ownership document are unnecessary to display the general rule. An official application’s requirements should not be copied into a form whose sole purpose is to help someone find that application.

2. A charitable purpose is not a legal basis

Every personal data operation needs an appropriate legal basis. Article 11 of Ukrainian law provides grounds beyond consent, including necessity for a transaction, a legal duty or legitimate interests subject to the priority of people’s rights. GDPR Article 6 has its own grounds. Calling an activity “research” or “assistance” does not independently permit collecting everything that might be useful later. [1] [2]

Health and sex-life data face additional restrictions under Ukrainian Article 7 and, where applicable, GDPR Article 9. Necessity to establish or defend a legal claim can be a relevant condition, but must relate to the actual processing purpose. Exceptions for particular non-profit bodies do not automatically cover every charitable foundation. Consent does not remove purpose limitation, minimisation or security requirements. [1] [2]

3. When the GDPR matters

The GDPR does not apply to every Ukrainian foundation merely because it has a website. First assess Article 2’s material scope and the connection of particular processing to Article 3: activities of an EU establishment; intentionally offering goods or services, even free ones, to people in the EU; or monitoring their behaviour within the EU. Article 3 also covers places where Member State law applies through public international law. [2]

Accessibility from the EU or an English version alone does not settle the question. The combined circumstances matter: whom the service targets, where people are, how it is offered and whether their behaviour is analysed. Assess the specific processing, not simply a reader’s nationality. For example, deliberately offering individual assistance to Ukrainians in Poland may create an Article 3(2) connection, while a general library and other activities require their own assessment. [2] [3]

4. Four situations require different minimum information

  • Reading a library. A person selects a topic without an intake questionnaire, evidence upload or personal-history field. Search should not become undisclosed collection of case narratives.
  • Reporting an error. A page address, passage and explanation allow the content to be checked; a reply contact is needed only for further correspondence. Affected people’s authentic documents should not be required by default to demonstrate an editorial error.
  • Individual assistance. First define the task, the provider and its authority. Only then request necessary information, explain processing and agree a safe channel. A general cooperation inbox should not become a case repository.
  • Usability assessment. Navigation can be assessed using fictional learning scenarios. Participants need not recount personal experiences to show whether they can locate a source and understand the next step.

These editorial design recommendations follow from comparing purposes and data necessity. They do not change the information legally required for a real application or prohibit properly organised individual assistance.

5. No questionnaire does not mean no processing

Personal data include information that can identify someone, not only documents. A log with an online identifier, email or record of visitor actions can require legal assessment. A visit to a violence-related page linked to an identifier could create a harmful inference about personal circumstances; the click does not establish that the visitor experienced that event. [1] [2]

We therefore recommend avoiding session recordings, advertising audiences built from harm-related topics, and transfer of search queries to external services without a defined need, basis and explanation. Security logs should have purpose-specific fields, access and retention. These are design criteria, not a claim that every website without an intake form is already safe.

6. What must be defined before accepting case files

For each data category, define purpose, legal basis, recipients, access, retention and how people can exercise their rights. Ukrainian Articles 8, 12, 14, 15 and 24 govern rights, information, disclosure, deletion and security; foreign transfers also require assessment under Article 29. Where the GDPR applies, relevant safeguards include Articles 28 and 32 and its international-transfer rules. An impact assessment under Article 35 is required when its high-risk conditions are met, not automatically for every information page. [1] [2]

The responsible organisation should explain in advance who receives the documents and who decides the case. Linking to an external organisation is not permission to forward a person’s email or file automatically. Even if the recipient also helps affected people, the basis and necessity of disclosure require separate assessment. [1] [2]

Conclusion and limits

For general navigation, the smallest justified input is the topic a person selects without recounting their case. Error reports, usability research and casework should not be merged into one undefined questionnaire. A practical assessment asks whether someone can find a rule and official link without unnecessarily disclosing personal circumstances.

This analysis establishes legal and organisational criteria; it does not certify server settings or GDPR compliance across the Foundation’s systems. Effects on application or refusal rates were not measured. This Foundation section does not receive personal case files; use “Prepare information and evidence for your category” for your own preparation and “Where to get legal assistance” to find individual assistance.

Sources

  1. Law of Ukraine on Personal Data Protection ↗ zakon.rada.gov.ua

    Institution / resource: Legislation of Ukraine / Verkhovna Rada of Ukraine · Language: Ukrainian

    Legal texts · Law 2297-VI of 1 June 2010; current version 14 June 2025, basis 4240-IX · Articles 1–2, 6–8, 11–12, 14–17, 20, 24, 29

  2. General Data Protection Regulation (GDPR), Regulation (EU) 2016/679 ↗ eur-lex.europa.eu

    Institution / resource: European Union / EUR-Lex · Language: English

    Legal texts · Consolidated text 02016R0679, 4 May 2016, current consolidated text shown by EUR-Lex · Articles 2–6, 9, 25, 28, 32, 35 and 44

  3. European Data Protection Board: Guidelines 3/2018 on the territorial scope of GDPR ↗ www.edpb.europa.eu

    Institution / resource: European Data Protection Board · Language: English

    Guidance and catalogues · Final version adopted 12 November 2019; version 2.1 formatting update 7 January 2020 · Introduction, pp. 4–5; targeting criterion, pp. 13–20, especially sections 2(b) and 2(c)

Corrections

Report an inaccuracy

Do not attach personal documents or a case history.

Related materials