Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Chinese hackers operate SAP RCE LINK

May 9, 2025

38 000+ Friedomen Found that exploit SEO to steal the crypt -seed phrases

May 8, 2025

Sonicwall Patches 3 flaws in SMA 100 devices, allowing attackers to run the code as a root

May 8, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Understanding Privacy Compliance in Indonesia
Data Privacy

Understanding Privacy Compliance in Indonesia

AdminBy AdminJuly 6, 2024No Comments6 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


With the implementation of Law No. 27 of 2022 on Personal Data Protection (“PDP Law”), both personal data controllers and personal data processors are mandated to provide external notification to personal data subjects, demonstrating organizational transparency in handling personal data. This notification, commonly known as a privacy notice, is typically accessible on the personal data controller’s or personal data processor’s website, mentioned either as a privacy notice or privacy policy.

A privacy notice serves as an external document, informing visitors about the utilization of their data and outlining their data privacy rights. Meanwhile, a privacy policy functions as an internal document that governs the organization’s procedures for implementing personal data protection. This privacy policy delineates guidelines for employees on safeguarding the personal data of customers or third parties.

Find Business Support

It is noteworthy that while there are essential differences between the functions/ purposes, as well as the information included in a privacy policy and a privacy notice, the terms can still be confused and are often used interchangeably. Despite this confusion, personal data controllers and personal data processors should still develop both documents as best practices to comply with the PDP Law and protect the data privacy rights of personal data subjects.

Requirements for privacy notices in Indonesia

As previously mentioned, the PDP Law outlines the obligations of personal data controllers and personal data processors to inform personal data subjects through the development of a privacy notice. The PDP Law specifies the minimum information that must be included in a privacy notice, comprising:

  1. The legality of the processing of the personal data;
  2. The purpose of processing personal data;
  3. The type and relevance of the personal data to be processed;
  4. The retention period for documents containing the personal data;
  5. Details regarding the information that is collected;
  6. The period in which the personal data is processed; and
  7. The rights of the personal data subjects.

Additionally, the Indonesian Government has drafted a Bill of Government Regulation on the implementation of the PDP Law, which further elaborates on the minimum required information in a Privacy Notice. This information includes:

  1. Identity of Personal Data Controller and/or Personal Data Processor;
  2. Source of collection and purpose of sending Personal Data;
  3. Basis for processing Personal Data;
  4. Purposes of processing Personal Data;
  5. Type of Personal Data;
  6. Legal basis for use of Personal Data;
  7. The period of time that Personal Data will be used;
  8. The period of time Personal Data will be stored; i. the period of time that Personal Data will be destroyed;
  9. How Personal Data is stored and managed;
  10. Information on the Party that will use the Data in the event that the Personal Data Controller involves the Personal Data Processor;
  11. The mechanism for consent and withdrawal of consent in the case of processing of Personal Data is carried out based on explicit valid consent from the Personal Data Subject and fulfillment of contractual obligations
  12. Mechanism for obtaining access and/or copies;
  13. Mechanism for submitting objections.
  14. Mechanisms for access, copying, verification, and correction of Personal Data;
  15. Security measures to protect Personal Data.

It is the responsibility of Personal Data Controllers and Processors to ensure that Privacy Notices are easily accessible to Personal Data Subjects. This obligation applies before and during the processing of Personal Data. Furthermore, in case of any changes in the information provided, the Personal Data Controller must notify the Personal Data Subject before such changes occur.

Requirements of privacy policy in Indonesia

While the PDP Law currently does not explicitly mandate the development of a Privacy Policy for Personal Data Controllers and Personal Data Processors, the current draft Bill of Government Regulation on the Implementation of the PDP Law introduced by the Indonesian Government requires both Personal Data Controllers and Personal Data Processors to develop an internal policy, procedure, and/or guideline for managing requests from Personal Data Subjects concerning their rights.

Despite the absence of a specific requirement in the PDP Law, both Personal Data Controllers and Personal Data Processors should develop a Privacy Policy. Such Privacy Policy may ensure the fulfilment of Personal Data Subject rights as stipulated by the PDP Law. Moreover, a Privacy Policy is essential for organizations seeking ISO 27701 certification which is an international standard that defines management systems and requirements for processing Personal Data.

The format of the privacy policy may vary according to organizational standards but should, at a minimum, include:

  1. Purpose: Clearly stating the organization’s privacy objectives and elucidating how the policy contributes to achieving them.
  2. Scope: Defining the boundaries of the policy and specifying the individuals or entities to which it applies.
  3. Risks and Responsibilities: Outlining the roles and responsibilities concerning privacy and data protection within the organization. This section should clarify the consequences of policy violations on compliance and business operations, including potential disciplinary actions for staff failing to fulfill their responsibilities.

The Privacy Policy must be published and effectively communicated within the organization to ensure that all employees and stakeholders are aware of their responsibilities and obligations outlined therein.

How to Prepare a privacy notice and privacy policy

If you are engaged in Personal Data processing activities as either a Personal Data Controller or a Personal Data Processor, there are several approaches to developing a Privacy Notice and Privacy Policy:

  1. Engage with External Consultants

Seeking assistance from external consultants can streamline the process of creating a legally compliant Privacy Notice and Privacy Policy. These consultants will tailor solutions to your specific needs, ensuring that the resulting documents adhere to all relevant Indonesian laws and regulations.

  1. Use a Template

Utilize templates provided by consultants or other reputable sources, allowing you to customize them according to your requirements. This method saves time and effort by providing a framework that aligns with legal requirements, reducing the risk of non-compliance with the PDP Law and other applicable regulations.

  1. DIY (Do It Yourself)

For those who prefer a hands-on approach, creating a privacy notice or policy from scratch is an option. However, it’s essential to ensure that all legally necessary information is included. This can be achieved by referencing reliable sources and staying informed about current legal requirements to avoid any inadvertent violations of the PDP Law or other regulations.

Complying with Indonesia’s Personal Data Protection Law: Essential Steps for Businesses

Webinar | Tuesday, April 30, 2024 / 3:00 PM Jakarta / 4:00 PM China / 10:00 AM CET

Join our upcoming webinar as Hardy Salim, Assistant Manager of the Business Advisory Unit, takes you through an in-depth explanation of Indonesia’s Personal Data Protection law and what steps companies need to undertake to ensure compliance.

This webinar is free of charge

Register Now

About Us

ASEAN Briefing is produced by Dezan Shira & Associates. The firm assists foreign investors throughout Asia and maintains offices throughout ASEAN, including in Singapore, Hanoi, Ho Chi Minh City, and Da Nang in Vietnam, in addition to Jakarta, in Indonesia. We also have partner firms in Malaysia, the Philippines, and Thailand as well as our practices in China and India. Please contact us at asean@dezshira.com or visit our website at www.dezshira.com.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Indonesia Regulates Foreign Private Electronic System Operators

July 28, 2024

Modal Timnas Bola Voli Putri Indonesia Menatap Dua Lawan Tangguh

July 27, 2024

Vast Voter Data Leaks Cast Shadow Over Indonesia ’s 2024 Presidential Election

July 26, 2024

Here is why Indonesia needs to enforce its new Data Privacy Law urgently

July 23, 2024

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 22, 2024

Indonesia underlines importance of ethical use of AI

July 22, 2024
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Chinese hackers operate SAP RCE LINK

May 9, 2025

38 000+ Friedomen Found that exploit SEO to steal the crypt -seed phrases

May 8, 2025

Sonicwall Patches 3 flaws in SMA 100 devices, allowing attackers to run the code as a root

May 8, 2025

Qilin leads April 2025. Spike ransomware with 45 disorders using malware Netxloader

May 8, 2025

Mirror aims Japan and Taiwan with Roysingmouse and upgraded malicious program

May 8, 2025

Only security tools do not protect you – control efficiency makes

May 8, 2025

Russian hackers using Flackfix Fake CAPTCHA to deploy new malware LostKeys

May 8, 2025

Cisco Patches Cve-2025-20188 (10.0 CVSS) in iOS XE, which allows root feat via JWT

May 8, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Chinese hackers operate SAP RCE LINK

May 9, 2025

38 000+ Friedomen Found that exploit SEO to steal the crypt -seed phrases

May 8, 2025

Sonicwall Patches 3 flaws in SMA 100 devices, allowing attackers to run the code as a root

May 8, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.