This article explores the topical issues of ensuring information security in Ukraine’s educational information systems amid digital transformation and the country’s path towards European integration. It focuses on threats of data breaches, unauthorised access, and misuse of personal data stored and processed in digital educational environments, particularly in large-scale systems such as the software and hardware complex "Automated Information Complex of Educational Management" (SHC "AICEM"). It is noted that further digitalisation of the educational process necessitates the introduction of comprehensive cybersecurity mechanisms that combine technical, organisational, and legal instruments. The paper outlines the specifics of personal data protection in the field of education, emphasising the increased sensitivity of such data. Particular attention is given to European cybersecurity approaches, based on the principles of "privacy by design and by default", systematic risk management, and defence-in-depth architecture. Key EU regulations are reviewed, such as the GDPR, NIS2, and the ePrivacy Directive, along with international standards like ISO/IEC 27001:2022 and NIST, which define the requirements for organising information security. Within the framework of the comparative analysis, the differences between the EU and Ukrainian approaches are outlined in terms of legal regulation, institutional structure, technical standards, and the rights of personal data subjects. The need to align national legislation in line with European standards is emphasised. Using the SHC "AICEM" as an example, practical aspects of personal data protection in educational information systems are demonstrated, including the implementation of cryptographic protection, multi-level authorisation, access control, and audit systems. The article concludes with recommendations for harmonising Ukrainian practices with EU norms, including the enhancement of legislation, development of educators’ digital competencies, institutionalisation of cybersecurity functions and strengthening the protection of data subjects' rights.
Lytvynchuk et al. (Wed,) studied this question.