Several aspects related to the recent cyberattack on an NDC facility raises serious questions about the communications ministry in its capacity as a personal data controller, especially considering that it led the drafting of the Personal Data Protection Law.
uring the House of Representatives meeting on June 27 with Communications and Information Minister Budi Ari Setiadi and National Cyber and Encryption Agency chief Hinsa Siburian, it was revealed that the cyberattack compromising the temporary National Data Centre (NDC) in Surabaya was caused by malicious software called Brain Cipher Ransomware.
The attack began with the deactivation of Windows Defender, followed by the installation of malicious files, the deletion of important file systems and finally, the deactivation of ongoing service operations at the NDC.
It turned out that the NDC did not have complete backups of the data it kept, which is unforgivable to many, as we are talking about a national database on which Rp 700 billion (US$42.7 million) of the state budget has been spent thus far, though this comes as no surprise.
Given that the comprised data can be deemed personal data, let us examine the incident through the lens of the Personal Data Protection (PDP) Law.
Cyberattacks are a constant threat in the digital era, but the issue is whether we have an adequate security system that is reliable and secure. In a case of data protection failure, which will likely happen, it is whether we have the procedures for handling and recovering from such a failure. These are the essence of the PDP Law.
Unfortunately, we cannot help but point our finger at the Communications and Information Ministry over this incident. Despite Telkomsigna being the NDC’s operator, the PDP Law would categorize the ministry as the personal data controller (PDC) responsible for building the NDC and which exercises control over data processing.
The PDP Law imposes obligations on PDCs, including that they must protect personal data from unauthorized processing and prevent illegal access to personal data by adopting a security system that is reliable, secure and responsible.
Share your experiences, suggestions, and any issues you've encountered on The Jakarta Post. We're here to listen.
Thank you for sharing your thoughts. We appreciate your feedback.
Quickly share this news with your network—keep everyone informed with just a single click!
Share the best of The Jakarta Post with friends, family, or colleagues. As a subscriber, you can gift 3 to 5 articles each month that anyone can read—no subscription needed!
Get the best experience—faster access, exclusive features, and a seamless way to stay updated.