The Jakarta Post

Please Update your browser

Your browser is out of date, and may not be compatible with our website. A list of the most popular web browsers can be found below.
Just click on the icons to get to the download page.

Jakarta Post

How comprehensive is personal data protection bill?

With the increasing use of data in this digital age, the GDPR has tightened the liabilities of data controllers and processors through three principles of data protection by design, data protection by default and data protection impact assessment. 

Sherly Haristya and Shita Laksmi (The Jakarta Post)
Premium
Jakarta
Wed, November 18, 2020

Change text size

Gift Premium Articles
to Anyone

Share the best of The Jakarta Post with friends, family, or colleagues. As a subscriber, you can gift 3 to 5 articles each month that anyone can read—no subscription needed!

T

he House of Representatives has suspended deliberation of the bill on personal data protection (PDP), which the government claims will serve as Indonesia’s General Data Protection Regulation (GDPR). Abdul Kharis Almasyhari, chairman of House Commission I overseeing defense and information said it would be impossible for the lawmakers to conclude the debate before the final sitting session of the year ends on Dec. 15.

Notwithstanding the suspension, Tifa Foundation has studied the comprehensiveness of the bill to see whether the bill stipulates: 1) a set of data protection principles in line with the relevant international standards, and 2) mechanisms to enforce those principles in the law. Our study compared the bill with the two leading international PDP instruments of Europe, the Convention 108+ of the Council of Europe and the GDPR. For the purpose of this article, we focus on a comparison with the GDPR.

Article 17 (2) of the bill emulates the GDPR’s data protection principles (Article 5), namely that data processing should be fair, lawful and transparent, be conducted in accordance with specified and limited purposes, be accurate, h ave storage limitations and maintain integrity and confidentiality.

While Articles 18-21 of the bill appear to form the legal basis for processing personal data and the workability of consent mechanism as the GDPR does in Articles 6 and 7, our study found some limitations in these arrangements in the bill. First, the bill still lacks clarity with regard to the two GDPR-based legal principles (compliance with legal obligation of data controller and for public interest) and its own legal basis, “the authority of the data controller” (Article 18 (d)). Moreover, while the bill specifies the conditions of consent and the right of data subjects to withdraw consent (Article 9), it does not mention any provision that necessitates that withdrawing consent should be as easy as providing consent.

The GDPR overall arranges the rights of data subjects into two sequences of data processing. First, a data subject has the right to be informed by the data controller before his or her personal data are processed. Second, the data subject has the rights to file requests regarding the processing of his or her personal data with the data controller.

On the right to be informed, Articles 4 and 7 (2f) of the bill do not mention a timeframe for a data controller to provide the necessary information to the data subject. Moreover, Articles 4-14 combine the rights of the data subject that are the responsibility of the data controller with those (the rights of data subject on remedies) that should be fulfilled by the supervisory authority in one chapter. Meanwhile, the GDPR arranges these rights in two different chapters. Such a mixed-up arrangement of the bill creates a lack of clarity as to who should be responsible for and how to ensure the fulfillment of those rights.

With the increasing use of data in this digital age, the GDPR has tightened the liabilities of data controllers and processors through three principles of data protection by design, data protection by default and data protection impact assessment. These three latest principles are to ensure that privacy and PDP are at the heart of data collection and use, including in digital innovation, from the beginning of the development process.

to Read Full Story

  • Unlimited access to our web and app content
  • e-Post daily digital newspaper
  • No advertisements, no interruptions
  • Privileged access to our events and programs
  • Subscription to our newsletters
or

Purchase access to this article for

We accept

TJP - Visa
TJP - Mastercard
TJP - GoPay

Redirecting you to payment page

Pay per article

How comprehensive is personal data protection bill?

Rp 35,000 / article

1
Create your free account
By proceeding, you consent to the revised Terms of Use, and Privacy Policy.
Already have an account?

2
  • Palmerat Barat No. 142-143
  • Central Jakarta
  • DKI Jakarta
  • Indonesia
  • 10270
  • +6283816779933
2
Total Rp 35,000

Your Opinion Matters

Share your experiences, suggestions, and any issues you've encountered on The Jakarta Post. We're here to listen.

Enter at least 30 characters
0 / 30

Thank You

Thank you for sharing your thoughts. We appreciate your feedback.

Share options

Quickly share this news with your network—keep everyone informed with just a single click!

Change text size options

Customize your reading experience by adjusting the text size to small, medium, or large—find what’s most comfortable for you.

Gift Premium Articles
to Anyone

Share the best of The Jakarta Post with friends, family, or colleagues. As a subscriber, you can gift 3 to 5 articles each month that anyone can read—no subscription needed!

Continue in the app

Get the best experience—faster access, exclusive features, and a seamless way to stay updated.