Overseeing the Regulation of Personal Data Protection in Indonesia
ELSAM, Jakarta –The developing usage of unlimited internet technology has caused the vulnerability in privacy protection of citizen. The data owner has no longer has the control over themselves for the data is easily exposed and arbitrarily transferred. The loss the citizen suffered has gained because of the emerging misuse of the personal data. The party collecting personal data of citizen has also raised in number, without the control and adequate protection mechanism.
So far the enactment of regulation of personal data protection was spread in several regulations based on each sector yet less comprehensive. Thus, it urges the government to propose the specific regulation on personal data protection. Until today, the effort to unify the personal data regulation in Indonesia has been at the stage of the enactment of Ministerial Regulation, especially Ministry of Communication and Informatics, and also the Bill.
Even though the draft of Ministerial Regulation as the regulation of personal data protection is considered as inadequate due to its level being unequal with the law, Mariam Barata as Directorate General of Informatics Application of Kominfo (Ministry of Communication and Informatics) mentioned that the mandate to enact the Ministerial Regulation on Personal Data was derived from the Government Regulation No 82/2012 (PSTE). Specified on Article 15 paragraph (3), the electronic system providers shall protect the secrecy of the managed personal data, including to guarantee the usage and use being subject to the approval of the personal data owner. Moreover, the further provision on this guidance should be regulated by Ministerial Regulation.
Until today, there are two phases of formulation of the draft of Ministerial Regulation. “The first phase will discuss the paradigm of personal data regulation in several countries. Next, the discussion of personal data protection will begin by inviting the institutions which administer and monitor the related sectors,” Mariam explained in the meeting entitled the Urgency of Personal Data Protection and Dynamics of Internet Governance in Indonesia, held by ICT Watch in Ibis Hotel, Menteng Jakarta on 10 August 2016.
On the other side, Bill on Personal Data Protection is still on the formulation process by a number of law academicians. Sinta Dewi from Universitas Padjajaran who is also involved in the formulation of the Bill explained that the regulatory model in Indonesia is referred to the regulatory mechanism in England. It can be seen from the clarity in regulating the definition of personal data and sensitive data.
Other than regulating the definition of personal data, Bill on Personal Data Protection also regulates the independent agency to ensure the effectiveness of the law. “Commission mentioned is Central Information Commission (KIP). It is pursuant to the Article 30 of Law on Public Information Disclosure,” Sinta explained. Law No 14 Year 2008 particularly Article 30 specified that one of the functions of Central Information Commission is to promote all parties to respect the personal data privacy and ensure the personal data providers subject to the provision of Law.
Moreover, the data transfer to the third countries is also specified in this Bill. According to Sinta, it cannot be detached from global development. Therefore, it needs the regulation to protect personal data which meets the international standard so that there will be a regulation of transnational data transfer. In Article 35 of the Bill. The personal data transfer to other areas outside Indonesia shall first require the approval from the data owner.
Meanwhile, in relation with provision of sanction, the regulation still gives sanction to the parties which steal and forge the personal data. In addition to the prison fine, the individual violates the regulation will be fined for three hundred millions Rupiahs. Meanwhile, for the legal entity, the principal criminal sentenced is for one billion Rupiahsfine at the maximum.