1. Overview
Indonesia’s Law No. 27 of 2022 on Personal Data Protection (PDP Law) represents the domestic implementation of Indonesia’s binding international obligations regarding privacy and personal data protection. The PDP Law must be understood within the framework of Indonesia’s commitments under international human rights law, particularly Article 17 of the International Covenant on Civil and Political Rights (ICCPR), which Indonesia ratified through Law No. 12 of 2005 .
2. International Legal Framework
The right to privacy is enshrined in Article 12 of the Universal Declaration of Human Rights and Article 17 of the ICCPR, both of which provide that no one shall be subjected to arbitrary or unlawful interference with privacy, family, home, or correspondence . The UN Human Rights Committee’s General Comment No. 16 clarifies that this protection extends to the gathering and holding of personal information, surveillance, and interception of communications, and requires that any interference be authorized by precise, accessible law and be necessary and proportionate .
3. Indonesia’s International Obligations
As a State Party to the ICCPR, Indonesia has a legal obligation to ensure that domestic law conforms to Article 17 standards . Indonesia’s constitutional framework, specifically Article 28G(1) of the 1945 Constitution, already recognizes the right to protection of personal dignity and security from threats . The PDP Law operationalizes these obligations by establishing:
Core Principles: The PDP Law incorporates internationally recognized principles including lawfulness and fairness, purpose specification, data minimization, accuracy, and security safeguards, consistent with UN Guidelines on computerized personal data files and OECD Privacy Guidelines .
Data Subject Rights: The law grants rights to access, correction, erasure, restriction of processing, data portability, and objection to automated decision-making. These align with international standards requiring individual participation in data processing .
Legal Basis for Processing: Processing requires a valid legal basis, with explicit consent being primary. International law permits exceptions only when necessary for national security, public order, public health, or the rights of others, with such exceptions clearly specified by law .
Breach Notification: Controllers must notify affected individuals and authorities within 72 hours. International standards require prompt, accessible remedies and transparent procedures for privacy violations .
Cross-Border Transfers: Permitted where adequate protection exists or safeguards are in place. This reflects the OECD transborder data flow principles and the ASEAN Framework on Personal Data Protection .
4. Regional Framework
The ASEAN Framework on Personal Data Protection (2016) , to which Indonesia is a party, provides non-binding principles that align with international standards. It recognizes consent, notification, purpose limitation, accuracy, security safeguards, and access/correction rights . Notably, the ASEAN Framework explicitly states it does not create binding legal obligations, serving instead as a cooperative instrument .
5. Conclusion
Indonesia’s PDP Law reflects a conscious effort to implement international human rights obligations under the ICCPR and align with regional and global data protection standards. The law’s principles, rights framework, and enforcement mechanisms mirror the requirements established by Article 17 and authoritative UN interpretations. As international standards continue to evolve in the digital age, Indonesia’s domestic framework will require ongoing harmonization to remain consistent with its binding international commitments.
Comments
Post a Comment