Data Protection and Privacy 2025

INDONESIA TRENDS AND DEVELOPMENTS Contributed by: Agus Ahadi Deradjat (Agung), Mahiswara Timur, Nina Cornelia Santoso and Dhan Partap Kaur (Sonia), ABNR Counsellors at Law

lindungan Data Indonesia or APPDI), for exam - ple, has started developing compliance toolkits and Records of Processing Activities (RoPA) templates to help organisations manage and document their data processing activities in line with the intended regulations. These initiatives aim to provide clarity and guidance during the interim period while awaiting the finalisation of the Draft GR PDP. Draft Online Child Protection Government Regulation: addressing personal data protection for children The MOCD has also prepared a draft regulation that focuses on mitigating the negative impacts of the digital space for children (“Draft GR Online Child Protection”). This regulation, once enact - ed, will be a derivative of the EIT Law and the PDP Law. The Draft GR Online Child Protection regulation outlines the responsibilities of ESOs in manag - ing online products, services, or features, over - seeing child protection governance in electronic systems, and enforcing administrative sanc - tions. It applies to ESOs that develop or oper - ate internet-connected products, services, or features, such as websites, mobile apps, social media platforms, or gaming services. The Draft GR Online Child Protection regulation does not provide exemptions for financial services, health - care, or AI software for education and entertain - ment that may be targeted towards child users. Regarding children’s personal data protection, the Draft GR Online Child Protection regulation addresses the following. DPIA for children ESOs must conduct a DPIA for any online prod - uct, service, or feature accessible to children before it is used by them. The DPIA should cover

the processing activities, the provider’s interests, the necessity and proportionality of the process - ing, a risk assessment for children’s protection, and risk mitigation measures. Additionally, the ESO must maintain the DPIA documentation for as long as the product, service, or feature remains accessible to children, and include a plan to address identified risks before market - ing the product. Obligation to protect children’s personal data ESOs must implement technical and operational measures to ensure appropriate age verification for children using online products, services, or features. These measures should align with specified risks and protect children’s personal data, secure electronic systems, and prevent unauthorised breaches. Data collected for age verification should only be used for that purpose and deleted once the age requirement is met. Providers must also offer mechanisms for users to challenge or adjust age verification decisions and report privacy or security violations, ensur - ing accessibility and fairness without unjustly restricting children’s access to services. Additionally, ESOs are prohibited from using children’s personal data in ways that could harm their physical, mental, or overall wellbeing, and from developing products that encourage excessive data collection. Data should only be processed if necessary for the service, unless there is a strong reason in the child’s best inter - est. Providers are also banned from using chil - dren’s data for other purposes without justifiable cause. Lastly, ESOs must appoint a dedicated officer or staff to oversee compliance with child data protection laws and regulations. Roles of DPOs in Indonesia The PDP Law mandates that both data control - lers and processors appoint an officer or staff

218 CHAMBERS.COM

Powered by