“The government has passed Law No. 27 of 2022 on Personal Data Protection that regulates mainly on the processing of personal data, and the rights and obligations of the personal data subject and personal data controller.”
Promulgated this year, Law No. 27 of 2022 on Personal Data Protection (“UU PDP”) regulates provisions on processing of personal data by the personal data controller. This regulation is important because many web services and applications nowadays are collecting data from the users for analysing purposes. Hereinafter, this article shall discuss some important points from UU PDP.
I. Subjects of UU PDP
Based on the Article 2 paragraph (1) of UU PDP, UU PDP shall apply to several subjects from every person, public agency, to international organization that are:
a. Located within the jurisdiction of the Republic of Indonesia; and
b. Outside the jurisdiction of the Republic of Indonesia, whose legal actions bear any legal consequences that are:
- within the jurisdiction of the republic of Indonesia: and/or
- related to Personal Data Subject of Indonesian citizens outside the jurisdiction of the Republic of Indonesia
UU PDP further excluded its applicability for the processing of Personal Data by individuals in personal or household activity.
II. Types of Personal Data
UU PDP divided the type of personal data into two types; Specific Personal Data and General Personal Data. Based on the Elucidation of UU PDP, Specific Personal Data are Personal Data which, if processed, can have a greater impact on the Personal Data Subject, including acts of discrimination and greater loss to the Personal Data Subject.
Pursuant to Article 4 paragraph (2) of UU PDP, Specific Personal Data of a specific nature shall include:
a. Health data and information;
b. Biometric data;
c. Genetic data;
d. Crime records;
e. Child data;
f. Personal financial data; and/or
g. Other data in accordance with provisions of laws and regulations.
Whereas General Personal Data, based on Article 4 paragraph (3) of UU PDP, shall include:
a. Full name;
b. Gender;
c. Citizenship;
d. Religion;
e. Marital status; and/or
f. Combined Personal Data to identify a person.
III. Rights of Personal Data Subjects
Personal Data Subjects, based on Article 1 Number 6 of UU PDP, are defined as individuals with whom the Personal Data are associated. The Personal Data Subjects have the rights as stipulated in Articles 5 to 13 of UU PDP as follows:
a. Obtain information regarding identity clarity, basis of legal interest, purpose of requesting and using Personal Data, and accountability of parties that request Personal Data;
b. Complete, update and/or correct errors and/or inaccuracies in Personal Data regarding themselves in accordance with the purpose of the Personal Data processing;
c. Access and obtain a copy of Personal Data regarding themselves in accordance with the purpose of the Personal Data processing ;
d. End processing, delete, and/or destroy Personal Data regarding themselves in accordance with provisions of laws and regulations (Article 8);
e. Withdraw consent to the processing of Personal Data regarding themselves that has been given to a Personal Data Controller (Article 9);
f. Object a decision-making action that is based solely on automated processing, including profiling, which has legal consequences or have a significant impact on Personal Data Subjects (Article 10 paragraph (1));
g. Delay or limit the Personal Data processing proportionally with the purpose of Personal Data processing (Article 11);
h. Sue and receive compensation for violations of the processing of Personal Data regarding themselves in accordance with provisions of laws and regulations;
i. Obtain and/or use Personal Data regarding themselves from a Personal Data Controller in a form that is in accordance with the structure and/or format commonly used or readable by an electronic system (Article 13 paragraph (1); and
j. Use and send Personal Data regarding themselves to other Personal Data Controllers, as long as the system used can communicate with each other securely in accordance with the Personal Data Protection principles based on UU PDP (Article 13 paragraph (2) of UU PDP).
The exercise of such mentioned rights of Personal Data Subjects shall be submitted through registered application that is submitted electronically or non-electronically to a Personal Data Controller.
UU PDP excluded the rights as referred to in Article 8, Article 9, Article 10 paragraph (1), Article 11 and Article 13 paragraph (1) and paragraph (2) as mentioned above for:
a. The interests of the national defence and security;
b. The interests of law enforcement process;
c. Public interest in the context of state administration;
d. The interests of supervision of the sectors of financial services, monetary, payment system, and financial system stability carried out in the context of state administration; or
e. The interests of statistics and scientific research.
Such exception that are mentioned above, shall be implemented solely in the context of implementing the provisions of UU PDP.
IV. Personal Data Controller and Personal Data Processor in Personal Data Processing
Personal Data Controller and Personal Data Processor shall include: every person; public agency; and international organization, which have been mentioned in Article 2 of UU PDP.
Personal Data Controller, respectively and collectively, determines the goal and doing control on the processing of personal data.
a. Obligations of Personal Data Controller
Article 20 paragraph (1) of UU PDP obliges a Personal Data Controller to have a basis Personal Data Processing.
The basis of Personal Data Processing that is mentioned above, shall include:
- An explicit valid consent from Personal Data Subjects for one or several specific purposes that has been submitted by the Personal Data Controller to Personal Data Subjects;
- Fulfilment of agreement obligations in the event that a Personal Data Subject is a party or to fulfil the request of the Personal Data Subject at the time of entering into the agreement;
- Fulfilment of the legal obligations of the Personal Data Controller in accordance with provisions of laws and regulations;
- Fulfilment of the protection of vital interests of the Personal Data Subject;
- Carrying out duties in the context of public interest, public services, or exercising the authority of the Personal Data Controller based on laws and regulations; and/or
- Fulfilment of other legitimate interests by taking into account the purposes, needs, and balance of interests of the Personal Data Controller and the rights of the Personal Data Subject.
Whereas, Personal Data Processor is defined as every person, public agency, and international organization that act individually or jointly in Personal Data processing on behalf of a Personal Data Controller.
b. Obligation of Personal Data Processor
In the event that a Personal Data Controller appoints a Personal Data Processor, the Personal Data Processor must process Personal Data based on the instructions of the Personal Data Controller (Article 51 paragraph (1) of UU PDP).
Further, the Personal Data Processor must obtain a written approval from the Personal Data Controller before involving other Personal Data Processors (Article 51 paragraph (2) of UU PDP).
In the event the Personal Data Processor performs the Personal Data processing outside of the orders and purposes set by the Personal Data Controller, the Personal Data processing shall be the responsibility of the Personal Data Processor.
V. Transfer of Personal Data
a. Transfer of Personal Data within the Jurisdiction of Republic Indonesia
Based on Article 55 paragraph (1) of UU PDP, a Personal Data Controller may transfer Personal Data to other Personal Data Controllers within the jurisdiction of the Republic of Indonesia. The Personal Data Controller who transfers Personal Data and who receives the transfer of Personal Data must carry out Personal Data Protection as referred to in UU PDP.
b. Transfer of Personal Data to Outside the Jurisdiction of the Republic of Indonesia
According to Article 56 paragraph (1) of UU PDP, A Personal Data Controller may transfer Personal Data to other Personal Data Controllers and/or Personal Data Processors outside the jurisdiction of the Republic of Indonesia in accordance with the provisions stipulated under UU PDP.
In order to do so, the Personal Data Controller must ensure that the country of domicile of the Personal Data Controller and/or the Personal Data Processor that receives the transfer of Personal Data has a Personal Data Protection level that is equal to or higher than those that are regulated under UU PDP. If such requirements fail to be fulfilled, the Personal Data Controller must ensure that there is adequate and binding Personal Data Protection.
If such requirements that are mentioned in Article 56 paragraph (2) and (3) of UU PDP fail to be fulfilled, the Personal Data Controller must obtain approval from the Personal Data Subject.
VI. Personal Data Processing
In the event that the Personal Data processing is based on the approval, Article 21 paragraph (1) of UU PDP oblige that the Personal Data Controller must submit the following information, regarding:
a. legality of the Personal Data processing;
b. the purpose of Personal Data processing;
c. the type and relevance of the Personal Data to be processed;
d. the retention period of documents containing Personal Data;
e. details regarding the Information collected;
f. period of Personal Data processing; and
g. rights of the Personal Data Subject.
If there is any change in the information as referred to above, the Personal Data Controller must notify the Personal Data Subject before any change in information occurs.
The Approval for Personal Data that is mentioned in Article 14 of UU PDP shall be carried out through written or a recorded consent and both have equal legal force.
Pursuant to UU PDP, approval from the Personal Data Subject must fulfil the following requirements:
a. must be provided in writing or recorded (Article 22 paragraph (1) of UU PDP); and
b. if the approval as mentioned above contains other purposes, the request for approval must meet the following conditions (Article 22 paragraph (4) of UU PDP):
- can be clearly distinguished from other matters;
- is made in an understandable and accessible format; and
- use simple and clear language (Indonesian language).
Article 22 paragraph 5 of UU PDP later stated that approval that fails to meet the provisions as referred to in Article 22 paragraphs (1) and (4) of UU PDP shall be declared null and void.
VII. Prohibition in the Use of Personal Data
In accordance with Article 65 of UU PDP, every person is prohibited from:
a. unlawfully obtaining or collecting Personal Data that do not belong to them with the intention to benefit themselves or other persons which may result in the loss of the Personal Data Subject.
b. unlawfully disclosing Personal Data that do not belong to them.
c. unlawfully using Personal Data that do not belong to them.
Whereas based on Article 66 of UU PDP, every person is prohibited from creating false Personal Data or falsifying Personal Data with the intention to benefit themselves or other persons which may result in the loss of other persons.
Author: Krisna Murti Ardianto
Gaffar & Co., an Indonesian Boutique Law Firm specializing and focusing on commercial law areas e.g. Information Technology, Capital Market & Financial Services, Corporate Secretarial.
For further queries and information, contact us:
+62 811 877 216 | info@gaffarcolaw.com | www.gaffarcolaw.com
