INDONESIA TRENDS AND DEVELOPMENTS Contributed by: Agus Ahadi Deradjat (Agung), Mahiswara Timur, Nina Cornelia Santoso and Dhan Partap Kaur (Sonia), ABNR Counsellors at Law
ian consent for the use of minors’ personal data, including for financial services, healthcare, or AI software for education and entertainment. Ser - vice providers must ensure that (i) parental or guardian consent is obtained for any services used by minors, and (ii) the person authorising the service is indeed the parent or legal guard - ian. Cross-border data transfer As stated above, the PDP Law provides that a data controller may transfer personal data off - shore should they fulfil the layered requirements of Adequacy of Protection, Appropriate Safe - guards, and consent of the data subjects. Data controllers are expected to be fully respon - sible for implementing appropriate security measures in the processing of data transfer. Particularly, in the financial services sector, the POJK 22 mainly governs cross-border transfer of customers’ information. • For the transfer of individual customers’ infor - mation, the FSP must comply with personal data protection laws and regulations, includ - ing those that are determined by the OJK. In this case, according to the PDP Law, the transfer of individuals’ personal data must be based on: (a) Adequacy of Protection; (b) Appropriate Safeguards; and (c) the data subject having provided their consent. • For the transfer of corporate customers’ infor - mation, the FSP must be based on: (a) Adequacy of Protection as determined by the OJK; (b) Appropriate Safeguards deemed as ac - ceptable by the OJK, for which POJK 22 provides further details on what would constitute Appropriate Safeguards, such
as bilateral agreement, binding corporate rules, and standard contractual clauses determined by the OJK; and (c) securing consent from the customer. The Draft GR PDP determines the Adequacy of Protection for personal data transfers by assessing the recipient country’s circumstances, including: • the existence of personal data protection laws; • a supervisory authority; and • international commitments or obligations from legally binding conventions or participation in multilateral systems. The Data Protection Authority will compile the list of approved countries. When using Appropriate Safeguards for trans - ferring personal data abroad, the Draft GR PDP allows safeguards such as: • agreements between the sender’s and recipi - ent’s countries; • standard contractual clauses; • binding company regulations for a group; or • other recognised instruments. Data controllers and processors must also meet additional obligations, such as recording the transfer cycle, mapping its implications, and ensuring that the transferred data is sufficient, relevant, and limited to the transfer’s purpose. Following the enactment of the PDP Law and the absence of Draft GR PDP, businesses and industry associations have taken proactive steps to ensure compliance with the existing legal requirements. The Indonesian Data Protection Practitioners Association ( Asosiasi Praktisi Per -
217 CHAMBERS.COM
Powered by FlippingBook