Preview

Kutafin Law Review

Advanced search

Comparative Analysis of Personal Data Protection Laws: The Case of Azerbaijan and the European Union’s General Data Protection Regulation (GDPR)

https://doi.org/10.17803/27130533.2026.2.36.296-333

Abstract

The paper is dedicated to the comparative analysis of legal regulations on the protection of personal data in the Republic of Azerbaijan, with reference to the European Union framework. The purpose of this research is to identify the gaps and shortcomings in the legislative framework of the Republic of Azerbaijan by comparatively analyzing the key concepts and principles in the field of personal data protection, the area of application of normative acts, the rights of data subjects, applicable administrative and legal sanctions for data protection breaches, and the effectiveness of institutional control mechanisms. For this purpose, formal legal and comparative analysis, as well as various scientific research methods, including the doctrinal method are used. The Constitution of the Republic of Azerbaijan, the Law of the Republic of Azerbaijan “On Personal Data” and other related normative documents have been analyzed. By using this approach, the research achieved its principal goal, specifically to conduct a comparative analysis between the two legal systems. Although the normative framework for the protection of personal data in Azerbaijan meets modern requirements, reforms are needed to increase data subjects’ rights, deepen legal compliance, tighten sanctions, and establish a central control mechanism to enhance regulatory coherence with reference to the GDPR as a comprehensive and functionally developed regulatory framework. In this context, the paper emphasizes the obligation to ensure full compliance of the legislation on the protection of personal data in the Republic of Azerbaijan with the GDPR and presents recommendations and conclusions for its development by using the experience of the European Union. The proposals prepared based on the results obtained have practical importance for increasing the effectiveness of the personal data protection mechanism.

About the Authors

F. M. Abbasova
Baku State University
Azerbaijan

Firuza M. Abbasova, Doctor of Law, Professor, Department of Criminal Procedure, Faculty of Law

Baku



K. I. Khalilov
Baku State University
Azerbaijan

Kamran I. Khalilov , PhD Student, Department of Criminal Procedure, Faculty of Law

Baku



References

1. Aljeraisy, A., Barati, M., Rana, O. and Perera, C., (2021). Privacy Laws and Privacy by Design Schemes for the Internet of Things. Acm Computing Surveys, 54(5), pp. 1–38, doi: 10.1145/3450965.

2. Anderson, C., Baskerville, R. and Kaul, M., (2021). The Travel of Privacy Standards and Regulations in Healthcare. Proceedings of the 54th Hawaii International Conference on System Sciences (2021), pp. 3859–3868, doi: 10.24251/hicss.2021.467.

3. Brown, I. and Korff, D., (2021). Exchanges of Personal Data After the Schrems II Judgment and the Role of DPAs. Study for the LIBE Committee, European Parliament, pp. 1–119, doi: 10.2139/ssrn.3884896.

4. Buckley, G., Caul¿eld, T. and Becker, I., (2024). How might the GDPR evolve? A question of politics, pace and punishment. Computer Law and Security Review, 54(106033), pp. 1–14, doi: 10.1016/j.clsr.2024.106033.

5. Bygrave, L.A., (2002). Data Protection Law: Approaching its Rationale, Logic and Limits. The Hague, New York: Kluwer Law International.

6. De Hert, P. and Papakonstantinou, V., (2012). The Proposed Data Protection Regulation Replacing Directive 95/46/EC: A Sound System for the Protection of Individuals. Computer Law and Security Review, 28(2), pp. 130–142, doi: 10.2139/ssrn.3447095.

7. Ducato, R., (2020). Data protection, scienti¿c research, and the role of information. Computer Law and Security Review, 37(105412), pp. 1–16, doi: 10.1016/j.clsr.2020.105412.

8. Fenwick, D.M., Kaal, W.A. and Vermeulen, E.P.M., (2017). Regulation Tomorrow: What Happens When Technology is Faster than the Law? American University Business Law Review, 6(3), pp. 1–29, doi: 10.2139/ssrn.2834531.

9. Fuster, G., (2013). The emergence of personal data protection as a fundamental right of the European Union. PhD Thesis. Brussels: Vrije Universiteit Brussel.

10. Greenleaf, G. and Kaldani, T., (2025). Data Privacy Laws in Central Asia: Between ex-SSR and “Belt and Road”. International Data Privacy Law, 15(1), pp. 67–90, doi: 10.1093/idpl/ipaf001.

11. Greenleaf, G., (2021). Global Data Privacy Laws 2021: Despite COVID Delays, 145 Laws Show GDPR Dominance. 169 Privacy Laws and Business International Report, 1, 3–5, UNSW Law Research Paper No. 21-60, doi: 10.2139/ssrn.3836348.

12. Greenleaf, G., (2014). “The Philippines and Thailand — ASEAN’s Incomplete Comprehensive Laws,” Asian Data Privacy Laws: Trade and Human Rights Perspectives. UNSW Law Research Paper No. 17-47, doi: 10.2139/ssrn.3000766.

13. Gstrein, O.J. and Beaulieu, A., (2022). How to protect privacy in a data¿ed society? A presentation of multiple legal and conceptual approaches. Philosophy and Technology, 35(1), p. 3, doi: 10.1007/s13347-022-00497-4.

14. Hajduk, P., (2021). The Powers of the Supervisory Body in the GDPR as a Basis for Shaping the Practices of Personal Data Processing. Review of European and Comparative Law, 45(2), pp. 57–75, doi: 10.31743/recl.10733.

15. Häuselmann, A. and Custers, B., (2024). Substantive fairness in the GDPR: Fairness elements for Article 5.1a GDPR. Computer Law and Security Review, 52(105942), pp. 1–12, doi: 10.1016/j.clsr.2024.105942.

16. Kasirzadeh, A. and Clifford, D., (2021). Fairness and Data Protection Impact Assessments. Proceedings of the 2021 AAAI/ACM Conference on AI, Ethics, and Society (AIES’21), May 19–21, 2021, pp. 1–8, doi: 10.1145/3461702.3462528.

17. Kinikoglu, B., (2023). Implementing a new data protection law: lessons from the Turkey experience. International Data Privacy law, 13(1), pp. 25–46, doi: 10.1093/idpl/ipad001.

18. Kuner, C.B., Bygrave, L., Docksey, C. and Drechsler, L., (eds), (2020). Data Protection Regulation: A Commentary. Brussels; Oslo: Oxford University Press. DOI: 10.2139/ssrn.3839645.

19. Labadie, C. and Legner, C., (2019). Understanding data protection regulations from a data management perspective: a capability-based approach to EU-GDPR. Proceedings of the 14th International Conference on Wirtschaftsinformatik, pp. 1–15. Siegen.

20. Lim, S. and Oh. J., (2025). Navigating Privacy: A Global Comparative Analysis of Data Protection Laws. IET Information Security, pp. 1–18, doi: 10.1049/ise2/5536763.

21. Nakashima, M., (2022). Comparison of Legal Systems for Data Portability in the EU, the U.S. and Japan and the Direction of Legislation in Japan. Proceedings of 15th IFIP International Conference on Human Choice and Computers (HCC), pp. 159–169, doi: 10.1007/978-3-031-15688-5_14.

22. Newman, A.L., (2015). What the “Right to Be Forgotten” Means for Privacy in a Digital Age. Science, 347(6221), pp. 507–508, doi: 10.1126/science.aaa4603.

23. Pichlak, M. and Gaczol, K., (2023). Simple and advanced reflexivity in GDPR enforcement: empirical evidence from DPA activity. International Data Privacy Law, 13(4), pp. 267–283, doi: 10.1093/idpl/ipad018.

24. Purtova, N., (2022). From knowing by name to targeting: the meaning of identification under the GDPR. International Data Privacy Law, 12(3), pp. 163–183, doi: 10.1093/idpl/ipac013.

25. Shehu, V.P. and Shehu, V., (2023). Human rights in the technology era — Protection of data rights. European Journal of Economics, Law and Social Sciences, 7(2), pp. 1–10, doi: 10.2478/ejels-2023-0001.

26. Solove, D.J. and Schwartz, P.M., (2024). Information Privacy Law. (8th Edition). Burlington: Aspen Publishing.

27. Solvak, M. and Vassil, K., (2016). E-voting in Estonia: Technological Diffusion and Other Developments Over Ten Years (2005–2015). Tallinn: Johan Skytte Institute of Political Studies, University of Tartu.

28. Voigt, P. and von dem Bussche, A., (2017). The EU General Data Protection Regulation (GDPR): A practical guide. Heidelberg: Springer. DOI: 10.1007/978-3-319-57959- 7.

29. Walsh, R., (2013). Extraterritorial confusion: The complex relationship between Bowman and Morrison and a revised approach to extraterritoriality. Valparaiso University Law Review, 47(2), p. 629. Available at: https://scholar.valpo.edu/vulr/vol47/iss2/27/ [Accessed 20.06.2025].

30. Wodi, A., (2023). The EU General Data Protection Regulation (GDPR): Five Years After and the Future of Data Privacy Protection in Review. SSRN Electronic Journal, doi: 10.2139/ssrn.4601142.

31. Yeung, K. and Bygrave, L.A., (2022). Demystifying the modernized European data protection regime: Cross-disciplinary insights from legal and regulatory governance scholarship. Regulation and Governance, 16(1), pp. 137–155, doi: 10.1111/rego.12401.

32. Zuboff, S., (2019). The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power. New York: Public Affairs.


Review

For citations:


Abbasova F.M., Khalilov K.I. Comparative Analysis of Personal Data Protection Laws: The Case of Azerbaijan and the European Union’s General Data Protection Regulation (GDPR). Kutafin Law Review. 2026;13(2):296-333. https://doi.org/10.17803/27130533.2026.2.36.296-333

Views: 664

JATS XML


Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 License.


ISSN 2713-0525 (Print)
ISSN 2713-0533 (Online)