INDONESIA TRENDS AND DEVELOPMENTS Contributed by: Agus Ahadi Deradjat (Agung), Mahiswara Timur, Nina Cornelia Santoso and Dhan Partap Kaur (Sonia), ABNR Counsellors at Law
cessor processes the personal data on behalf of the data controller. A data controller is fully accountable and liable to the data subject for the processing of their personal data. However, a data processor is only independently liable if it processes personal data in a manner that devi - ates from the data controller’s instruction, order or purpose. Lawful basis for processing of personal data The PDP Law acknowledges several legal bases for personal data processing: • consent; • contractual necessity; • compliance with a data controller’s legal obligations; • protection of the vital interests of the data subject; • public interest, for the provision of public services or for the exercise of lawful authority; and • legitimate interest. The authors observe that the above legal bases are very similar to the concept adopted by the EU GDPR. Rights of data subjects The PDP Law acknowledges a data subject’s right to obtain information, and the right to rec - tify, access, terminate processing (including to delete and/or destroy personal data), withdraw consent, object to automated decision-making, suspend or restrict processing, lodge a com - plaint and seek compensation, and data port - ability. The PDP Law further mandates that data sub - jects’ rights must not be implemented in an absolutist manner: they can be adjusted if con - sidered prejudicial to certain interests (national
defence and security, or to law enforcement, etc). Cross-border data transfer The PDP Law introduces layered requirements to allow data controllers to transfer personal data outside Indonesian territory, namely that: • (a) the country receiving the transfer of personal data has an equal or higher level of personal data protection than afforded under the PDP Law (“Adequacy of Protection”); • (b) in the absence of Adequacy of Protection, an adequate level of binding personal data protection must be available (“Appropriate Safeguards”); and • (c) in the event that neither Adequacy of Protection nor Appropriate Safeguards are present, consent for the cross-border data transfer must be given by the data subject. Points (a) to (c) above must be assessed and implemented in sequence. To date, there is no indication that an official approved list of coun - tries that meet the Adequacy of Protection requirements will be published. Data Protection Authority The PDP Law mandates the formation of a Data Protection Authority that is tasked to act as reg - ulator, supervisor, and executor in data protec - tion matters by the President. Whilst there have been efforts to expedite the establishment of the Data Protection Authority, this authority has yet to be formed. In the meantime, pursuant to Ministry of Communication and Digital Affairs (MOCD) Regulation 1/2025 on Organization and Work Procedures, matters concerning personal data protection are currently under the Directo - rate General of Digital Space Supervision’s (DG) authority. The DG is tasked with formulating and implementing policies related to digital space
213 CHAMBERS.COM
Powered by FlippingBook