Safeguarding Personal Data in the Public Sector: Unveiling the Impact of the New Personal Data Protection Act in Indonesia
DOI:
https://doi.org/10.32890/uumjls2025.16.1.1Keywords:
Data protection, legal framework, personal data protection Act, public sector, supervisory authorityAbstract
Personal data protection is a significant issue that has attracted public attention in recent years due to various personal data leaks, especially those held by public sector institutions. The issue prompted lawmakers to re-open the discussion of the Personal Data Protection Bill (PDP Bill), which was finally enacted in October 2022. An essential aspect addressed in the newly enacted PDP Act was data protection by public sector institutions in Indonesia. Several studies showed that the collection of personal data by these institutions is primarily mandatory. Therefore, this study examines the laws and regulations related to personal data protection by public sector institutions and the potential implementation challenges. The challenges include the tendency to “prioritise” sectoral regulations over the PDP Act and the potential to “over-utilise” and “over-interpret” data protection exemptions. The findings indicated that the newly enacted PDP Act provided excessive leeway for public institutions to exempt data subjects’ rights despite the high standard for data processing. The findings suggested that to achieve a meaningful implementation of the PDP Act, the mandated supervisory authority must be independent in carrying out its duties and functions to ensure the just enforcement of personal data protection in the public and private sectors. In addition, the government must develop a strategy to ensure the consistency of data protection implementation through various legislations currently being drafted, as well as harmonising the PDP Act with other related Acts.
References
Agostino, D., Arnaboldi, M., & Lema, M. D. (2020). New development: COVID-19 as an accelerator of digital transformation in public service delivery. Public Money & Management, 41(1), 1-4. https://doi.org/10.1080/09540962.2020.1764206
Alibeigi, A., & Munir, A. B. (2020). Malaysian personal data protection act, a mysterious application. University of Bologna Law Review, 5(2), 362–374.
Alsenoy, B. van, Kindt, E., & Dumortier, J. (2011). Privacy and data protection aspects of e-government identity management. In S. van der Hof & M. M. Groothuis (Eds.), Innovating Government. Information Technology and Law Series Vol. 20. (T.M.C). 251-282. Asser Press.
Asimow, M. R. (2002). Administrative law. Gilberts Law Summaries.
Basyari, I., Harbowo, N., & Kustiasih, R. (2022). Nasib pembahasan RUU perlindungan data pribadi kian suram. Kompas. https://www.kompas.id/baca/polhuk/2022/03/31/pembahasan-ruu-pdp-tak-dilanjutkan
BBC Indonesia. (2021, August 31). Data eHAC milik 1,3 juta penggunanya dilaporkan bocor, ‘keamanan data tidak prioritas. BBC Indonesia. https://www.bbc.com/indonesia/indonesia-58393345
Bell, J., Aidinlis, S., Smith, H., Mourby, M., Gowans, H., Wallace, S. E., & Kaye, J. (2019). Balancing data subjects’ rights and public interest research: Examining the interplay between UK law, EU human rights law and the GDPR. European Data Protection Law Review, 5(1), 43–53. https://doi.org/10.21552/edpl/2019/1/
Bhat, P. I. (2019). Idea and Methods of Legal Research. Oxford University Press.
Black, G., & Stevens, L. (2013). Enhancing data protection and data processing in the public sector: The critical role of proportionality and the public interest. SCRIPTed, 10(1), 93–122. https://doi.org/10.2966/scrip.100113.93
Blume, P. (2004). Data protection in the private sector. Scandinavian Studies in Law, 47, 297–318.
Blume, P. (2012). The inherent contradictions in data protection law. International Data Privacy Law, 2(1), 26–34.
Blume, P. (2015). The public sector and the forthcoming EU data protection regulation. European Data Protection Law Review, 1(1), 32–38. https://doi.org/10.21552/edpl/2015/1/
Blume, P., & Svanberg, C. W. (2013). The proposed data protection regulation: The illusion of harmonisation, the private/public sector divide and the bureaucratic apparatus. Cambridge Yearbook of European Legal Studies, 15, 27–46. https://doi.org/10.5235/152888713809813639
Boehme-Neßler, V. (2016). Privacy: A matter of democracy. Why democracy needs privacy and data protection. International Data Privacy Law, 6(3), 222–229. https://doi.org/10.1093/idpl/ ipw
Brown, A., Fishenden, J., & Thompson, M. (2014). Digitizing government: Understanding and implementing new digital business models. Palgrave Macmillan.
Chik, W. B. (2013). The Singapore personal data protection act and an assessment of future trends in data privacy. Computer Law and Security Review, 29(5), 554-575.
CNN Indonesia. (2020, May 21). 2,3 Juta data KPU diduga bocor, dijual di forum hacker. CNN Indonesia. https://www.cnnindonesia.com/teknologi/20200521223601-185-505726/23-juta-data-kpu-diduga-bocor-dijual-di-forum-hacker
Djafar, W., & Syauqillah, M. (2022). Developing an equilibrium of protection of the right to privacy and national security in terrorism eradication in Indonesia. Journal of Terrorism Studies, 4(2), 1–14.
Doly, D. (2021). Pembentukan lembaga pengawas pelindungan data pribadi dalam perspektif pembentukan lembaga negara baru. Negara Hukum, 12(2), 223–244.
Eddyono, S. W., & Saptaningrum, I. D. (2007). Catatan umum atas keberadaan komisi negara di Indonesia. Jurnal Legislasi Indonesia, 4(3).
European Union Agency for Fundamental Rights. (2023). Surveillance by intelligence services: Fundamental rights safeguards and remedies in the European Union. https://www.europarl.europa.eu/meetdocs/2014_2019/plmrep/COMMITTEES/PEGA/DV/202 3/02-28/FRASubmissiontothePEGACommittee_EN.pdf
Fahmi, A. B. (2020, July 6). Data pasien Covid-19 bocor dianggap tanggung jawab kemenkes. Katadata. https://katadata.co.id/yuliawati/digital/5f02f85af052d/data-pasien-covid-19-bocor-dianggap-tanggung-jawab-kemenkes
Fuster, G. G. (2014). The emergence of personal data protection as a fundamental right of the EU. Springer International Publishing.
Galuh, P. R. (2021, May 21). Data 279 juta penduduk yang bocor identik dengan milik BPJS, kominfo panggil direksi. Kompas. https://tekno.kompas.com/read/2021/05/21/14351007/data-279-juta-penduduk-yang-bocor-identik-dengan-milik-bpjs-kominfo-panggil
Gavison, R. (1980). Privacy and the limits of law. The Yale Law Journal, 89(3), 421–471.
Greenleaf, G. (2014). Asian data privacy laws: Trade & human rights perspectives. Oxford University Press.
Hakkala, A., & Koskinen, J. (2022). Personal data protection in the age of mass surveillance. Journal of Computer Security, 30(2), 265–289. https://doi.org/10.3233/JCS-200033
Hert, P. De, & Gutwirth, S. (2006). Privacy, data protection and law enforcement. Opacity of the individual and transparency of the power. In E. Claes, S. Gutwirth, & A. Duff (Eds.), Privacy and the Criminal Law (pp. 61–104). Intersentia.
Holvast, J. (2008). History of privacy. In V. V. Matyas, S. Fischer-Hübner, D. Cvrcek, & P.Venda (Eds.), The Future of Identity in the Information Society (pp. 13–42). Springer-Verlag Berlin Heidelberg.
Islam, M. T., Sahula, M., & Karim, M. E. (2022). Understanding GDPR: Its legal implications and relevance to south asian privacy regimes. UUM Journal of Legal Studies, 13(1), 45–76. https://doi.org/10.32890/uumjls2021.13.1.
Keller, P. (2019). The reconstruction of privacy through law: A strategy of diminishing expectations. International Data Privacy Law, 9(3), 132–152.
Kokott, J., & Sobotta, C. (2013). The distinction between privacy and data protection in the jurisprudence of the CJEU and the ECtHR. 3(4), 222–228. https://doi.org/10.1093/idpl/ipt
Kompas. (2022). Sanksi bagi lembaga publik dan swasta yang langgar UU PDP dinilai tak setara. Kompas. https://nasional.kompas.com/read/2022/09/22/05090091/sanksi-bagi-lembaga-pub lik-dan-swasta-yang-langgar-uu-pdp-dinilai-tak-setara
Kuziemski, M., & Misuraca, G. (2020). AI governance in the public sector: Three tales from the frontiers of automated decision-making in democratic settings. Telecommunications Policy, 44(6).
Laurie, G., & Stevens, L. (2016). Developing a public interest mandate for the governance and use of administrative data in the United Kingdom. Journal of Law and Society, 43(3), 360–392.
Lin, J., Carter, L., & Liu, D. (2021). Privacy concerns and digital government: Exploring citizen willingness to adopt the COVIDSafe app. European Journal of Information Systems, 30(4), 389–402. https://doi.org/10.1080/0960085X.2021.1920857
Lynskey, O. (2014). Deconstructing data protection: The “added-value” of a right to data protection in the EU legal order. International and Comparative Law Quarterly, 63(3), 569–597.
Mahardika, A. G. (2021). Desain ideal pembentukan otoritas independen perlindungan data pribadi dalam sistem ketatanegaraan Indonesia. Jurnal Hukum UNISSULA, 37(2), 101–118.
Ministry of Communication and Informatics of the Republic of Indonesia. (2019, December 12). Menunggu UU perlindungan data pribadi. Indonesia.Go.Id. https://www.indonesia.go.id/ narasi/indonesia-dalam-angka/sosial/menunggu-uu-perlindungan-data-pribadi
Ministry of Communication and Informatics of the Republic of Indonesia. (2023, July 7). Perkembangan penanganan gugaan kebocoran data paspor 34,9 juta warga Indonesia. Ministry of communication and informatics of the republic of Indonesia. https://www. kominfo.go.id/content/detail/50065/siaran-pers-no-138hmkominfo072023-tentang-perkemban gan-penanganan-dugaan-kebocoran-data-paspor-349-juta-warga-indonesia/0/siaran_pers
Muñoz, L. A., & Bolívar, M. P. R. (2018). Experiences of E-government development implementation in developing countries: Challenges and solutions. in L. A. Muñoz & M. P. R. Bolívar (Eds.), International E-Government Development. Palgrave Macmillan.
OECD. (2020). OECD Digital Economy Outlook 2020. OECD.
Otjacques, B., Hitzelberger, P., & Feltz, F. (2007). Interoperability of E-government information systems: Issues of identification and data sharing. Journal of Management Information Systems, 23(4), 29–51. https://doi.org/10.2753/MIS0742-1222230403
Privacy International. (2018). A guide for policy engagement on data protection: The keys to data protection. Privacy International.
Rahman, F. (2021). Kerangka hukum perlindungan data pribadi dalam penerapan sistem pemerintahan berbasis elektronik di Indonesia. Jurnal Legislasi Indonesia, 18(1), 81–102.
Rahman, F., & Wicaksono, D. A. (2021). Examining the reference of personal data interpretation in Indonesian constitution. Jurnal Penelitian Hukum De Jure, 21(2), 187-200.
Regan, P. M. (1986). Privacy, government information, and technology. Public Administration Review, 46(6), 629–634.
Rubinstein, I. S., Nojeim, G. T., & Lee, R. D. (2014). Systematic government access to personal data: A comparative analysis. International Data Privacy Law, 4(2), 96–119.
Rumbold, J. M. M., & Pierscionek, B. K. (2018). What are data? A categorization of the data sensitivity spectrum. Big Data Research, 12, 49–59.
Sabowo, H. K., Hartati, S., & Karyono, H. (2022). The urgency of personal data protection for the community: There is need for an independent commission. International Journal of Educational Research & Social Sciences, 3(1), 413–424.
Septiani, L. (2022). Ahli sebut pengesahan UU PDP terancam jadi macan kertas. Katadata. https://katadata.co.id/syahrizalsidik/digital/6329c8ec9abcc/ahli-sebut-pengesahan-uu-pdp-tera ncam-jadi-macan-kertas
Sloot, B. van der. (2017). Legal fundamentalism: Is data protection really a fundamental right? In R. Leenes, R. Van Brakel, S. Gutwirth, & P. De Hert (Eds.), Data protection and privacy: (In) Visibilities and Infrastructures (pp. 3–32). Springer International Publishing.
Solove, D. J. (2008). Understanding privacy. Harvard University Press.
Staunton, C., Slokenberga, S., & Mascalzoni, D. (2019). The GDPR and the research exemption: Considerations on the necessary safeguards for research biobanks. European Journal of Human Genetics, 27(8), 1159–1167. https://doi.org/10.1038/s41431-019-0386-
Tauda, G. A. (2011). Kedudukan komisi negara independen dalam struktur ketatanegaraan republik Indonesia. Pranata Hukum, 6(2).
Thompson, N., Mullins, A., & Chongsutakawewong, T. (2020). Does high e-government adoption assure stronger security? Results from a cross-country analysis of Australia and Thailand. Government Information Quarterly, 37(1), 101408. https://doi.org/10.1016/j.giq.2019.101408
Thompson, N., Ravindran, R., & Nicosia, S. (2015). Government data does not mean data governance: Lessons learned from a public sector application audit. Government Information Quarterly, 32(3), 316–322.
Van Zoonen, L. (2016). Privacy concerns in smart cities. Government Information Quarterly, 33(3), 472–480.
Walters, R., Trakman, L., & Zeller, B. (2019). Data protection law: A Comparative Analysis of Asia-Pacific and European Approaches. Springer Singapore. https://doi.org/10.1007/978-981-13-8110-
Widiatedja, I. G. N. P., & Mishra, N. (2022). Establishing an independent data protection authority in Indonesia: A future-forward perspective. International Review of Law, Computers & Technology, 37(3), 1–22.
Wu, Y. (2014). Protecting personal data in E-government: A cross-country study. Government Information Quarterly, 31(1), 150–159.
Xiao, C. (2019). Personal data rights in the era of big data. Social Sciences in China, 40(3), 174–188.
Yu, X., & Zhao, Y. (2019). Dualism in data protection: Balancing the right to personal data and the data property right. Computer Law and Security Review, 35(5), 1–11.
Published
Issue
Section
License
Copyright (c) 2025 UUM Journal of Legal Studies

This work is licensed under a Creative Commons Attribution 4.0 International License.
How to Cite
Research impact
Harvested 2026-09-06Counts differ between services because each indexes a different body of literature. None of them is the whole picture.
- Semantic Scholar 5 View →
- Scopus 5 View →
- OpenCitations 3 View →
- OpenAlex 2 View →
- Crossref 2 View →
- Google Scholar no free count Search →
- Dimensions no free count Search →








