Video summary

Perlindungan Data Pribadi & ITE

Main summary

Key takeaways

Educational

Main ideas & lessons conveyed

  • Indonesia’s digital transformation is accelerating, moving economic and social activities from manual/offline processes to internet/mobile-based systems.
  • Industry 4.0 (from 2018 onward) and newer technologies—especially AI—increase both benefits and risks.
  • Personal data is highly valuable (“data is new oil/new currency”): it can be used to infer personal profiles, improve services, and generate economic value, but it also enables fraud, manipulation, and surveillance when misused.
  • Big data characteristics (5V model) make data processing difficult and increase the need for strong governance:
    • Volume (too large for spreadsheets)
    • Velocity (grows/changes fast)
    • Variety (text + non-text like photos/videos)
    • Veracity (data trustworthiness/decision reliability issues)
    • Victory (the need to use big data effectively to “win” in the era of big data)
  • Indonesia’s legal framework is evolving for digital life, particularly:
    • ITE Law (UU ITE), including the second revision (Law No. 1 of 2024)
    • Personal Data Protection Law (PDP Law): Law No. 27 of 2022, signed Oct 17, 2020, effective after a 2-year transition (stated as effective Oct 17, 2024 in the talk)
  • Despite effectiveness, implementation readiness is a concern, especially because:
    • Government regulations (PP) are reportedly not yet visible/signed
    • The Personal Data Protection Authority is also not yet formed/operational

PDP Law (Personal Data Protection) — core points from the talk

1) Purpose / spirit of the law

  • Personal data is treated as a human right and must be protected.
  • The law aims to:
    • Fulfill human rights
    • Increase public awareness
    • Ensure respect for the importance of personal data protection

2) Categories of personal data

  • General personal data, e.g.:
    • Full name, citizenship, religion, marital status
    • Combinations of general data
  • Specific personal data (requires stronger protection), e.g.:
    • Health data
    • Biometrics
    • Genetics
    • Child criminal records
    • Personal finances

3) Data subject rights (individual rights)

The speaker lists a broad set of rights, including:

  • Right to control personal data, including:
    • Knowing the identity/clarity
    • Understanding purposes and intent of data requests/use
  • Right to correct inaccurate personal data (e.g., KTP data such as birth date, gender, address)
  • Right to obtain a copy of personal data when there is inaccuracy
  • Right to delete/destroy personal data, e.g.:
    • Job applications retaining CV data even after the user no longer wants it stored
  • Right to expiration/retention handling, with an example compared to GDPR practice:
    • Data owners may decide whether to keep or delete after a time period
  • Right to object/withhold certain processing, especially where it leads to harm or unwanted sharing
  • Right related to automatic decision-making, e.g.:
    • Credit scoring decisions that are automatic and may be incorrect
  • Right to sue and seek compensation for violations (including data misuse/disclosure)
  • Right to restrict/delay processing in certain circumstances
  • Right to receive explanations regarding processing of their data
  • Right to obtain information and access to personal data processing records (as described by the speaker)

4) Exceptions (when rights can be limited)

The talk notes the law contains exceptions where rights can be disregarded for reasons such as:

  • Defense interests / national security
  • Law enforcement processes
  • Public interest in state administration
  • Supervision related to financial services/payment stability

It also describes coverage of the processing lifecycle broadly:

  • From collection, processing, analysis, storage, announcement/notification, to deletion/destruction

5) Core principles for personal data processing (operational rules)

Key obligations/principles include:

  • Limited and specific purpose:
    • Data can only be processed for the stated purpose (e.g., job application data should not be shared to other vacancy-openers).
  • No unlawful sharing beyond consent/purpose:
    • Example: telecommunication operator data should not be shared to banking without the required approval/consent.
  • Accuracy and completeness
    • Must avoid misleading data.
  • Security safeguards
    • Protect from unauthorized access and unauthorized disclosure.
  • Retention and deletion
    • After the retention period, data must be destroyed/deleted.
    • Retention timing is described as governed by rules (example mentioned: certain retention like 3/6 months for some contexts), with further provisions in Government Regulations.

Responsibilities & enforcement — PDP Law institutions and sanctions

1) Key roles: data controller vs data processor

  • Data controller:
    • The party that controls why/how data is processed and typically stores the data.
  • Data processor:
    • The party that processes data on behalf of the controller.

Both roles have compliance obligations, but responsibility is primarily tied to the controller (as emphasized in Q&A).

2) Data Protection Officer (DPO) requirement

  • Controllers/processors are expected to appoint a Data Protection Officer (“di aseng” officer in subtitles), chosen based on professional knowledge of PDP practices.
  • The speaker suggests this will create professional roles and compliance work.

3) Administrative sanctions

Possible forms mentioned:

  • Written warning
  • Temporary restriction/suspension actions
  • Deletion of personal data
  • Administrative fines

Fine magnitude described:

  • Up to 2% of annual income/receipts (as stated in the talk)

The speaker questions practicality for very large companies and notes disputes about details of violation variables.

4) Criminal provisions

Criminal provisions referenced as Articles 67–73 (as described), including examples such as:

  • Collecting personal data not belonging to oneself
  • Disclosing personal data not belonging to oneself
  • Using personal data not belonging to oneself
  • Unauthorized entry/processing

5) Personal Data Protection Authority (agency)

The talk explains the authority will:

  • Formulate policies/strategies on personal data protection
  • Supervise implementation and law enforcement
  • Impose sanctions
  • Support dispute resolution outside court (compared in function to other Indonesian bodies)
  • Publish supervision results
  • Receive complaints, inspect, summon parties, etc.

Analogies mentioned:

  • Compared to an Information Commission-type body
  • Parallels referenced to other institutions (e.g., KPPU style as analogy)

Major implementation concern raised in Q&A:

Agency formation is not yet done, while the law is said to be effective.


UU ITE (ITE Law) — main explanation themes

1) Why UU ITE was revised

The speaker frames UU ITE as having shifted over time, particularly regarding:

  • Misuse/overreach of certain provisions (especially Article 27, noted as a problem area)

Changes are portrayed as correcting “abuse trends” and aligning provisions better with digital-era realities.

2) General direction of the 2024 revision (Law No. 1 of 2024)

Major types of revisions included:

  • Around 34 changes (as claimed)
  • Validity of electronic information/documents as evidence
  • Changes to electronic signature provisions
  • Clarifications regarding “reliable security”
  • Obligations for electronic system organizers to protect children
  • Adjustments to prohibitions related to:
    • Gambling/pornography and morally violating content
    • Threats/harassment and defamation-like conduct

The speaker emphasizes changes to Articles 27, 28, 29 and related insertions.

3) Illustrative restructuring of Article 27 and related provisions

Additions/changes described include:

  • Pornography-related broadcasting/transmission
  • Expanded/clarified defamation/honor and good-name attacks
  • Threats of violence/intimidation (including via electronic systems)
  • Threats involving revealing secrets (extortion patterns described)

4) Article 28 updates (politics/hoaxes framing)

The revision changes handling of:

  • Previously e-commerce-linked provisions
  • Use in political contexts (fake news/hatred/hostility/SARA-type content)

A point discussed:

  • If content does not cause riots in society, the provision might not apply (as described by the speaker).

Digital-era risks & examples used to motivate data protection and ITE compliance

The speaker provides scenario examples, including:

  • Data leaks becoming investigative rather than instant:
    • Example: using NIK-based integration to extract health/vaccination outcomes
  • Cybercrime evolution:
    • Fraud moving from physical bank robbery to ransomware/data theft
    • Online fraud and gambling concerns
  • Social media data misuse:
    • Mention of the Facebook data leak and collaboration claims with Cambridge Analytica (as described)
  • Online loans (pinjol) data abuse risks:
    • Spread of customer data and photos
    • Pressures/harassment patterns when repayments fail
  • Healthcare integration risks:
    • Mention of Satu Sehat integration and the possibility of disease inference when data is linked

Methodology / instruction-like guidance included (structured bullets)

A) How PDP compliance is expected to work (practical steps mentioned directly or implied)

  • Consent first:
    • Data processing requires consent from the data owner (self-declaration/agree-click described as allowed in the talk)
  • Purpose limitation:
    • Process data only for the stated purpose
    • Do not share data beyond what the purpose/consent allows
  • Data protection impact assessment (DPIA-style concept):
    • Perform risk assessment especially for specific personal data
    • Identify risks and mitigate them
  • Appoint a Data Protection Officer (where required)
    • Ensure DPO is appointed based on legal/data protection expertise
  • Secure processing throughout the lifecycle:
    • Protect collection, processing, storage, and deletion
    • Use technical safeguards such as encryption (especially suggested in healthcare example)
  • Retention period enforcement and deletion:
    • Define retention periods
    • Delete/destroy data when retention ends (including distributed copies)
  • Accountability for data controllers:
    • Even if vendors/processors exist, the controller bears primary responsibility (e.g., hospital/KPU/election system owner)
  • Handle third-party data processors:
    • Ensure processors comply via contractual/operational control
  • Plan for automatic decision-making transparency:
    • Allow objections and provide explanation when decisions are algorithmically made

B) What individuals can do when data is misused (rights framed as actions)

  • Request access and information about data processing
  • Correct inaccurate data (e.g., KTP mistakes)
  • Obtain copies of personal data
  • Request deletion/destruction when appropriate (including after service no longer needed)
  • Object/limit processing in certain cases
  • Seek compensation and sue for violations
  • Use safeguards through consent withdrawal/choice where retention/archiving decisions are offered (as described with a GDPR-like example)

Speaker / sources featured

Speakers

  • Mr. Ir Herusadi, M.Si (main presenter; Executive Director at the Indonesia ICT Institute, as stated)

Other persons mentioned in the event/Q&A (not primary speakers)

  • Ms. Rahmi (MC/host)
  • Mr. Kamil Sagala, SH, M.H. (mentioned in context of filing a lawsuit)
  • Mr. Jim Tomy (mentioned in supervisory/pratin supervisory board context)
  • Mr. Nas Mer (symbolic certificate handover context)
  • Mr. Nasir (certificate recipient)
  • Ms. Siti (participant asking a healthcare/data question)
  • Brother Muhammad Mega (participant asking about consent form and data deletion)
  • Mr. Sat Gunayoman (participant asking about suing aliases vs real names)
  • Muhammad Rama (participant asking about legal preparations for digital era; pinjol question)
  • Mr. Pakiansyah (participant asking whether existing regulations are enough for AI challenges)
  • Ms. Kristi (mentioned in discussion of AI openness/ethics)
  • Mr. Ter (mentioned in discussion as raising/continuing AI-related points)
  • Mr. Heru / “sir” references in Q&A (calls addressing the presenter)

Sources / institutions referenced

  • UU ITE: Law No. 11 of 2008 and subsequent revisions, including Law No. 1 of 2024
  • PDP Law: Law No. 27 of 2022
  • Minister of Communication and Information Regulation No. 20 of 2016
  • Government regulations (PP) (referenced as not yet visible/signed at time of talk)
  • GDPR (Europe) (used as analogy)
  • OJK (referenced in loan-related narrative context)
  • KPU (mentioned as a data controller example in elections)
  • BPJS (referenced in data leak example)
  • Satu Sehat / Peduli Protect / PeduliIndungi (referenced as systems in examples)
  • Facebook / Cambridge Analytica (referenced in data misuse example)
  • South Jakarta District Court (mentioned in connection with a lawsuit)
  • Kominfo / Komd as (mentioned in Q&A as something not matching PDP authority terms)
  • KPPU, Information Commission (mentioned by analogy for dispute/supervision roles)

Original video