The Department of Criminal Law Disciplines and Judicial Proceedings of the Academic and Research Institute of Law at Sumy State University summarises the outcomes of the third year of implementation of the international educational project ERASMUS-JMO-2023-MODULE – ERASMUS2027 – 101125350 – “EUEPPDC”: “EU Experience in Personal Data Protection in Cyberspace”, implemented within the framework of the Jean Monnet Module under the Erasmus+ Programme.
During the third year, the project team continued its efforts to disseminate European approaches to personal data protection, enhance digital and legal literacy among young people, integrate European Union standards into legal education, and develop practical skills for safe behaviour in the digital environment. Particular emphasis was placed on engaging university and school students, organising practice-oriented activities, and developing educational and methodological materials. These areas of activity directly correspond to the project’s objectives of promoting European expertise in personal data protection and broadening access to relevant knowledge among diverse target audiences.
Outreach Activities for School Students
One of the key areas of activity during the third year of the project was the dissemination of knowledge on digital rights and safe behaviour in cyberspace among school students.
The EUEPPDC Project Coordinator, Doctor of Law and Associate Professor at the Department of Criminal Law Disciplines and Judicial Proceedings, Mykhailo Dumchykov, delivered an educational lecture entitled “Cybercrime in the Modern World: Challenges of Personal Data Protection and Counteraction Strategies” for eighth- and ninth-grade students of Secondary School No. 4 of the Sumy City Territorial Community.
During the session, students were introduced to the most common forms of cybercrime associated with the unlawful acquisition and use of personal data, the mechanisms underlying such offences, and contemporary methods of their detection. Particular attention was devoted to European Union practices in privacy protection, principles of digital hygiene, methods for identifying cyber threats, and legal remedies available to users of digital services.
The interactive format of the lecture enabled students not only to acquire theoretical knowledge but also to analyse real-life situations related to the safe use of the Internet and the responsible handling of personal data.
Lecture and Discussion for Higher Education Students
An important component of the project’s educational activities was the organisation of a lecture and discussion entitled “Where Is the Boundary Between Ensuring Cybersecurity and Interfering with the Right to Privacy?”, attended by students enrolled in the programmes of Law, International Law, and Law Enforcement.
The discussion focused on one of the key challenges facing contemporary digital society: the need to strike an appropriate balance between the public interest of the state in ensuring cybersecurity and the fundamental human rights to privacy and personal data protection.
Participants analysed European standards of personal data protection, approaches to the application of the GDPR, and the principles of legality, necessity, and proportionality in relation to interference with privacy. The open discussion also addressed issues such as mass data collection, digital surveillance, the use of artificial intelligence, cyber-intelligence tools, and the potential risks associated with the misuse of digital technologies.
The event provided a platform for developing a critical understanding of contemporary issues in cyberspace regulation and for deepening participants’ knowledge of European human rights standards in the digital environment.
Scientific and Practical Workshops “GDPR in Your Pocket: European Practices for Data Protection on Smartphones”
A separate strand of activity during the third year of EUEPPDC implementation comprised a series of practice-oriented events dedicated to the protection of personal data when using mobile devices.
On 23 December 2025, the Department of Criminal Law Disciplines and Judicial Proceedings organised the scientific and practical workshop “GDPR in Your Pocket: European Practices for Data Protection on Smartphones.”
The event was designed for university students, school students, and academic staff and combined the legal and technical dimensions of digital security. Participants examined GDPR requirements concerning data protection on mobile devices, contemporary channels of personal and sensitive data leakage, cybersecurity challenges in wartime conditions, risks associated with mobile applications, and differences between the security approaches employed by the iOS and Android operating systems.
Members of the project team and invited experts took part in the discussion. The practical component of the workshop was aimed at developing participants’ skills in configuring smartphone security settings, identifying digital threats, and applying contemporary mechanisms for protecting personal information.
This area of activity was further developed through a scientific and practical workshop held online on 22 May 2026, which brought together experts, academic staff, university students, and prospective school-leaver applicants.
The event was moderated by the Project Coordinator, Mykhailo Dumchykov. During the workshop, the legal and technical aspects of personal data protection within mobile ecosystems were examined in a comprehensive manner. Yevheniia Lytvynenko, Assistant at the Department of Criminal Law Disciplines and Judicial Proceedings and Head of the Technology and Innovation Support Centre at Sumy State University, presented an analysis of the legal regulation of personal data and intellectual property in mobile applications and compared Ukrainian approaches with European standards.
Nazarii Holovatskyi, Senior Lecturer at Uzhhorod National University, focused on the use of biometric data, local and cloud-based authentication, the principles of data minimisation, and the concept of privacy by design. Zakhar Tovolzhanskyi, a representative of the Student Information Technology Centre at Sumy State University, addressed practical risks arising from the use of unofficial software sources, delayed device updates, phishing attacks, and malicious software.
A separate discussion was devoted to the comparison of iOS and Android security models, the protection of behavioural and biometric data, implementation of the right to be forgotten, and practical principles of digital hygiene. The event highlighted the need for further harmonisation of Ukrainian legislation with EU standards, improvement of users’ digital literacy, and continued professional dialogue in the fields of cybersecurity and digital rights.
Preparation and Publication of the Educational Handbook
One of the important outcomes of the third year of the project was the publication of an educational handbook providing a comprehensive examination of personal data protection in cyberspace.
The team of authors, comprising M. O. Dumchykov, O. S. Maletova, M. S. Utkina, and V. K. Obodiak, systematised European experience in regulating relations in the field of personal data protection and examined the specific features of its implementation within the national legal framework.
The handbook outlines the provisions of the General Data Protection Regulation (GDPR), institutional mechanisms for safeguarding the right to personal data protection, and the particularities of personal data processing in e-government, law enforcement, healthcare, and the financial sector.
Separate sections address contemporary technological challenges, including the use of Big Data and blockchain technologies, the spread of cybercrime and cyberterrorism, as well as issues relating to the development of digital legal awareness and a culture of responsible personal data handling.
The preparation of the handbook constituted an important outcome of both the research and educational components of EUEPPDC and created opportunities for the further use of materials developed within the project in the educational process and in students’ independent learning. The electronic version of the publication is available in open access through the institutional repository of Sumy State University.
Outcomes of the Third Year
Thus, during the third year of implementation of the EUEPPDC project, the project team successfully combined educational, outreach, scientific and practical, and publishing activities. The activities conducted within the project reached a wide range of target audiences, from secondary school students and prospective applicants to university students, academic staff, researchers, and practitioners.
Particular attention was devoted not only to disseminating knowledge about the GDPR and the European model of personal data protection, but also to developing practical skills for safe behaviour in the digital environment and fostering a critical understanding of issues related to digital surveillance, mobile device security, biometric data protection, and responses to contemporary cyber threats.
The results of the third year of project implementation demonstrate the consistent achievement of its key objectives: promoting the values and standards of the European Union in the field of personal data protection, integrating European experience into the educational process, developing a culture of digital legal awareness, and ensuring open access to up-to-date educational, research, and methodological materials.
The implementation of the project “EUEPPDC: EU Experience in Personal Data Protection in Cyberspace” has made an important contribution to strengthening the European dimension of legal education at Sumy State University and has laid the groundwork for the further dissemination of the practices developed within the project in the fields of digital rights, privacy, and cybersecurity.
“Funded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or the European Education and Culture Executive Agency (EACEA). Neither the European Union nor EACEA can be held responsible for them.”



