Data Protection and Privacy 2025

INDONESIA TRENDS AND DEVELOPMENTS Contributed by: Agus Ahadi Deradjat (Agung), Mahiswara Timur, Nina Cornelia Santoso and Dhan Partap Kaur (Sonia), ABNR Counsellors at Law

• If an FSP transfers consumers’ data and/or information offshore, they must fulfil the lay - ered requirements, which are similar to those under the PDP Law, which also requires the FSP to ensure that the receiving country has adequate personal data protection. However, as FSPs are subject to both the PDP Law and POJK 22, this creates a dilemma, as they could face sanctions under both regula - tions for the same conduct. This situation places undue pressure on FSPs and creates an unfair competitive disadvantage compared to busi - nesses outside the financial services sector. Additionally, upon the issuance of other imple - menting regulations by both MOCD or OJK in the future, including the list of approved coun - tries for data transfer, there may be duality of regulation. Update on data breaches Pursuant to the Indonesian Cyber Security Land - scape published by the National Cyber and Crypto Agency, there have been 56,128,160 data exposures that affected 461 stakeholders in Indonesia. Recurring data breaches in Indo - nesia highlight vulnerabilities in the country’s cybersecurity policies and systems, along with insufficient supervision and enforcement against perpetrators. Despite the existence of formal legal instruments on cybersecurity, cybersecu - rity awareness and comprehensive implementa - tion of security measures, from a technical and organisational perspective, play an important role in anticipating and mitigating cybersecurity risks. The Indonesian legal framework on data breach - es requires reporting to the MOCD and notify - ing data subjects, while cybersecurity incidents without a data breach must be reported to regu - lators and law enforcement. Below are the regu -

latory regimes for data breach and cybersecurity incident notification. • PDP Law – upon “failure to protect personal data”, the data controller must notify both the affected data subject and the Data Protec - tion Authority within 72 hours. This includes breaches that impact confidentiality, integrity, or availability of personal data, resulting in destruction, loss, alteration, or unauthorised access. • Electronic System Operation Regulations (GR 71/2019) – an ESO must: (a) report to relevant authorities and law enforcement if there is a serious system failure due to third-party interference; and (b) notify data subjects if personal data pro - tection fails within its system. Likely implementation of the Draft GR PDP As briefly touched upon above, the Indonesian government has been preparing the Draft GR PDP. This is expected to shed some light on gen - eral requirements under the PDP Law, although the draft also confers some authority on the Data Protection Authority (which has yet to be formed) to regulate certain matters. Some notable provisions under the Draft GR PDP include the following. Requirements for reliance on lawful bases Data controllers may rely upon other appropriate lawful bases such as contractual necessity, legal obligations, or vital, public, or legitimate interest. The Draft GR PDP provides further guidance and requirements on reliance upon the lawful bases, including as follows. • Express consent – if the data subject refuses to provide consent, the data controller cannot

215 CHAMBERS.COM

Powered by