
- Development of Indonesia PDP Law and the EU GDPR
The transition from traditional society to information society has driven various technological developments, the rise of advanced gadgets and complex networks have augmented many activities in all layers of society.[1] In the realm of data collection, the current technology enables real-time data collection of information such as the number of family members, user geolocation, transaction pattern, and many others that can be analyzed for strategic purposes.[2] The growth has also been accelerated throughout COVID-19, that forces technology adoption by society, companies, and even the government to assist in delivering goods or services. However, this rapid development must always be approached prudently, as the benefits technology brings can also be used for malicious purposes through personal information theft, impersonation, and other cybercrimes that exist due to the lack of awareness of digital privacy and security.[3]
Privacy and personal data protection are two distinct but interrelated concepts. The term Privacy was first proposed by Warren & Brandeis that argued privacy is the right to be let alone and must be respected by law.[4] Privacy is further elucidated by David Banisar, who classified four different categories of privacy: 1) physical/bodily privacy; 2) territorial privacy; 3) communication privacy; 4) informational privacy. Within that taxonomy, personal data protection is considered as part of informational privacy.[5] In order to ensure protection towards an individual’s informational privacy, data protection law was created that governs how data is processed from the collection, recording, organizing, storage, rectification, transfer, deletion, and up to data destruction.[6]
The incident of Facebook-Cambridge Analytica has become a stark reminder of the need to increase privacy awareness for users and for the government to review its data protection law to prevent organizations from unlawfully processing data or exploiting its users. 87.000.000 Facebook user data was collected without the user’s consent and transferred to third parties that analyzed and used the insight for political gains in various elections in the United States of America, South Africa, and even the United Kingdom.[7] The aftermath of Cambridge Analytica has incentivized many countries to strengthen and/or revamp their data protection regulation to ensure better safeguards are available to its citizens. Such development has brought the EU GDPR which succeeds European Privacy Directive 95/46/EC, as control mechanism for data processing entities within the European Union.
Indonesia, as a developing jurisdiction, has pursued stronger data protection law reform to accommodate with digital economy growth and a safer online environment. According to Sinta Dewi Rosadi, there are at least two factors that influence the legal development of data protection law in Indonesia.[8] First, the existence of a human rights instrument enshrined under International Covenant on Civil and Political Rights, referred under Indonesian 1945 Constitution as the right to live. Second, the rapid development of technology in Asia has created a sense of urgency to provide better personal data protection. The ability of major technology industry in collecting and analyzing information has brought complaints from society ranging from lack of trust of the processing company and cyber-enabled criminal activities.[9]
The fight for better data protection law in Indonesia has been challenging. Prior to 2022, the legal development is mostly done in only specific sectors and not unified into one legislation that applies comprehensively.[10] For instance, data protection themes are reflected in Law No. 23 Year 2006 on Civil Administration, Law No. 29 Year 2004 on Doctor, Law No. 28 Year 2007 on Tax General Provision & Procedure, Law No. 19Year 2016 on the Amendment of Information and Electronic Transaction and many others. While on the level of implementing regulations, there are Government Regulation No. 37 Year 2007 on Civil Administration Implementation, Law No. 71 Year 2019 on Electronic System and Transaction Operations, and Law No. 80 Year 2019 on Electronic Commerce. As a consequence of this fragmented and sectoral approach, several sectors may have no data protection themes at all or regulatory arbitrage with different data protection interpretations. Due to this landscape, a need to create a comprehensive data protection law is timely.
In 2022, the arrival of Law No. 27 Year 2022 on Personal Data Protection, was ratified by the House of Representatives and signed by the Indonesian President.[11] This is a pivotal moment for the Indonesian government to committing better protection for its citizen’s personal data and as a response to high-risk cyber attacks that threaten the integrity, confidentiality, and availability of data protection. The law aspires to increase awareness and legitimacy of data protection to all actors.[12] Promisingly, Law No. 27 Year 2022 on Personal Data Protection marks a new era that will affect how organizations process personal data.
Law No. 27 Year 2022 on Personal Data Protection governs various aspects of data protection, starting from the classification of personal data, data subject rights, personal data processing, obligation towards data controller and processor, international and national data transfer, the data protection supervisory authority, administrative and penal sanction, international participation, and the procedural applicable procedural laws. Majority of those components can be found under the EU GDPR. This is not surprising since the draft of Indonesian Personal Data Protection Law was drafted with the EU GDPR as baseline reference, aimed to ensuring that Indonesia might level up its adequate protection, align with the EU GDPR, subject to several exceptions[13] As a consequence, legal scholarship that has extensively discussed topics under the EU GDPR is contextually relevant vis-à-vis PDP Law and its future development.
As a primer, the EU GDPR is the pillar of data protection in the European Union that aims to harmonize the national legislation of its member states. Interestingly, the EU GDPR is one of the regulations that experienced the “Brussel Effect” a term used to refer when an EU legislation has direct or indirect effect on jurisdictions outside of the European Union.[14] For instance, the extraterritorial effect of the EU GDPR creates a situation where US-based service providers must also comply with the EU GDPR as long as it offers services through data processing activities of EU dataset.[15] In addition to being the first state-of-the art legislation on data protection, this development popularized concepts such as data processing principles, data actors (such as data subject, data controller, data processor), rights, and obligations among states outside of the European Union. This is exemplified in jurisdictions that modeled their data protection laws with GDPR key concept such as Brazil General Data Protection Law,Singapore PDP Act, USA California Consumer Privacy Act and other states.[16] This connection is considered essential, especially in the context of international data transfers that prioritizes adequacy conditions where both states have at least a similar or stronger data protection regulation.
Despite bringing tremendous benefits to both consumers and business, the EU GDPR has also brought unintended consequences – one of which is the burdensome compliance costs against organizations that process personal data.[17] Previously, Wanda Preshtus & Kaja Felix have classified and ranked failure to act on data subject rights to be one of the most frequent five violations of data protections laws.[18] In combination with unclear implementation guidance of various requirements, the International Association of Privacy professionals (IAPP)-EY Privacy Governance Report revealed that many business operations have failed to comply with the regulations after it came into effect in 2018.[19] Indonesia is not an exception. Certain sectors have voiced out their concerns on Indonesia PDP Law enforcement that might pose significant compliance risk and become a barrier to innovation.[20] However, Indonesia PDP Law has yet to become effective in 2024 and requires further implementing regulation details that are currently being drafted. This specific context triggered a perfect timeline to delve further on the normative obligations contained in the law and if additional adjustments are needed. Therefore, this paper builds upon the latter toward balanced academic and practical analysis.
Within the context of the data protection regime, there are four main actors that are actively involved. First, the data subject whose personal data is subject to processing such as the active user of an application. Second, data controller is an entity that acts separately or jointly with other data controllers to determine the purpose of data processing (in many instances, data controller is also the actor who offers products/services to the consumer). Third, data processor appointed by data controller to help the latter in processing collected data. Lastly, there is third party/ties not directly linked with the product/services.[21] Depending on its business model and how data is collected, many Financial Technology companies can be categorized as data controllers or data processors or both.[22]
This paper will be the first to discuss data subject rights, and particularly the exercise of data subject access request (“DSAR”) within an Indonesian context, supplemented by the EU GDPR-style influence. We start this paper by introducing the developments of personal data protection in Indonesia and how other jurisdictions influenced the existing law. We dissect the importance of data within Financial Technology (Fintech) industry and why compliance with data protection law is essential. Subsequently, we explore DSAR in the context of Indonesian law while proposing how implementing regulation should be structured to reflect international best practices. We also provide a case study of QRIS DSAR and pointed at least three concerns on the current national and regional regulations for access request and reflected other Fintech companies’ readiness in handling DSAR.
In relation to data subject rights, we learn two notable academic scholarship of Helena Vrabec’s dissertation (and subsequent manuscript) that analyzes data subject rights comprehensively, and Ausloos & Dewitte that reviewed DSAR extensively, in practice. Furthermore, to understand the Indonesian context, this paper referred to previous scholarships a priori to Indonesia PDP Law, written by Edmon Makarim, Sinta Dewi Rosadi, and Danrivanto Budhijanto. We acknowledge and refer to these indispensable legal scholarships from two jurisdictions to provide greater clarity on how Indonesia PDP Law should proceed with DSAR implementation.
We substantiate and balance our research by conducting DSAR Awareness survey commenced on 7th February and will be opened until the presentation of this paper in Bali, May 2023. As of 24th of February 2023, 80+ respondents ranging from global privacy practitioners, academia, organizations, and students participated. The questionnaire highlights five important insights on DSAR; 1) The familiarity of DSAR; 2) The procedures of DSAR; 3) Automating DSAR; 4) Indonesian 3×24 hours DSAR timeline; 5) Input for Indonesian DSAR timeline. Aside from multiple choice, we provide an option for respondents to provide commentary, which provided pragmatic insights. We combine theoretical application derived from the literature review together with DSAR Awareness survey to objectively unbox DSAR complexity, in practice.
- Data Subject Rights in Financial Technology: A New Horizon for Compliance in Digitally-Driven Economy
Within the financial sector, innovation and digital transformation is key to producing seamless service delivery to customers through trusted online customer’s journey and experience Throughout COVID-19 pandemic, the financial sector faced substantial challenges that incentivize changes, leading to rapid rise of Fintech services’ subscriptions and activities. [23] At the time, Indonesia experienced massive growth in Fintech companies such as Ajaib, Xendit, Akulaku, and 100+ companies listed under the Indonesian Financial Service Authority with a total of US$20.4 funds to deliver. Fintech industry revolves around 4 main categories: (1) Payment, clearing, and credit settlement; (2) Deposit, lending, fundraising; (3) Market provisioning; and (4) Investment risk management that aims to provide opportunities for Micro, Small, and Medium-Sized Enterprises.[24]
Fintech companies process voluminous personal data on its platform (including but not limited to profiling, targeting and analyzing customers’ datasets for revenue generation and improved future revenue generation model. The dataset is analyzed according to the company-specific business model, such as planning new services or product.[25] Hendrawan Agusta pointed out that in peer-to-peer lending Fintech, there are at least three sets of data being collected.[26] First, financial data such as the amount of money invested, transaction history, deadline of loan repayment, and many others that are considered sensitive/special category data. Second, health and biometrics data are collected when users upload photos of themselves, facial characteristics, and fingerprints in order to set out login credentials or authentication factors. Additionally, certain data are recorded by Fintech companies for mandatory customer onboarding, such as “Know-Your-Customer” verification method as required by law.[27]
The voluminous dataset Fintech companies process might lead to cybersecurity risk exposure, if security controls and resilience is vulnerable. Hackers have a strong incentive to steal information such as financial information, impersonate user transactions, and other illegal activities.[28] This puts tremendous burden on Fintech companies to ensure customers’ personal data protection and prevent cybersecurity threats. Hence, an introduction to data protection regime is necessary to protect its users.[29]
Previously, Fintech sector faced regulatory limbo before the Indonesian Financial Service Authority stepped up through POJK 77/POJK.01/2016, IT-Based Lending & Borrowing Services. Under Article 21, it sets out several obligations to Fintech companies to minimize risk against its customers but does not specifically regulate the use of personal data.[30] Afterwards, the Central Bank of Indonesia published Fintech regulations – in which it defines Fintech as “the use of technology within a financial system that results on a novel product, service, technology, or business model” under Bank Indonesia Regulation 19/12/PBI/2017 on Financial Technology Implementation to ensure Fintech adhere to consumer protection, risk management, and security principles. Within Article 8 of this Regulation, all Fintech providers are obliged to ensure data confidentiality related to financial transactions.
Fintech’s business and technology model is progressive, seamless and disruptive as compared to traditional financial business model. In such circumstances, it should also comply with various regulations enforced by the Financial Service Authority, Bank Indonesia, and data protection regulations as part of its compliance obligation. A privacy-respectful approach is important, to balance the business interest of the company and the protection of customers’ data. For example, end-to-end data encryption, increased or multi-layered authentication and secured network. Given the Fintech landscape and progress in Indonesia, the following sections outline DSAR principle, process and practicalities, and equally how and why it’s indispensable for Fintech companies to comply with such requests, post enforcement of Indonesia PDP Law.
III. Right to Access: Cornerstone Mechanism for Data Protection
The Right to Access, which is exercised through DSAR, is one of the primary pillars to enforce other data subject rights under the data protection law regime. Helena classified data subject rights into three categories: 1) Rights related with information & access to personal data; 2) Rights related with rectification & erasure of personal data; and 3) Right to object against automated decision-making.[31] In relation to the first category, both the Right to Information & Right to Access are considered to be the cornerstone of exercising other rights as impossible for data subjects to request for rectification or even object to automated processing if they do not know the information that is being processed by the data controller. In practice, Right to Access provides two main primary functions in increasing transparency for data subject and acting as control mechanism against unlawful processing.[32] In support of Kranenborg argument, the clarity and transparency over how data is processed are important for an individual.[33] Therefore, there is an emphasis to ensure that DSAR can be requested by data subjects and companies’ commitment to these rights due to the high deference it holds in data protection regulations.
In 2010s, Max Schrems’s notable DSAR to Facebook led to groundbreaking litigation due to Facebook’s unlawful data processing activities that might infringe the EU GDPR. Max Schrems submitted DSAR and received a 1200-page long document that contains voluminous personal data. The list includes all his private messages, records of all “Likes” activity, and many others which became the basis of 22 complaints directed to supervisory authority to investigate Facebook data protection compliance.[34] Max Schrems was not alone. Another DSAR leading to high-level investigation was requested by David Caroll that exposed Cambridge Analytica conduct during the 2016 US President election.[35] These highlight the importance of acknowledging data subjects’ DSAR rights and data controllers’ obligation to comply with such requests. It must not be understated as failure to respond will lead to administrative fines and unsolicited access may hamper data controllers’ trust and reputation.
Prior to the EU GDPR, Right to Access can be referred to Article 12(a) of Data Protection Directive (DPD) 95/46/EC which mandates all EU member states to guarantee data subjects to have the ability in: (1) Confirming if personal data is being processed, and further detail of this processing activity; (2) Receiving communication in an intelligible form of personal data that is currently processed; (3) Being informed if the processing is automated and the logic behind it.[36] However, since DPD 95/46/EC mandates member states and requires national legislation in transposing the Data Protection Directive, there has been substantial differences between member states in enforcing and facilitating right to access.[37] Owing to this, the EU GDPR harmonizes the modalities, deadline, and mechanism of handling Right to Access across the EU member states.
In contrast to the EU, previous legislation related to data protection in Indonesia does not recognize Right to Access of personal data by data subject. Previously, Right to Access only refers to the ability of government officials to access citizenship data for administrative purpose.[38] Therefore, Right to Access by data subject was newly introduced under Indonesia PDP Law alongside other data subject rights under Chapter IV Article 5-14. Specifically, Article 7 stipulates:
“Subjek Data Pribadi berhak mendapatkan akses dan memperoleh salinan Data Pribadi tentang dirinya sesuai dengan ketentuan peraturan perundang-undangan.”[39]
From the construction of Article 7, Recital of Indonesia PDP Law does not provide further corroboration regarding the scope of access provided to data subject, form of copy that will be given, nor the mechanism in providing access. This question remains open to further implementing regulations, as indicated in the last sentence of Article 7. This marks significant departure between Indonesia PDP Law to the EU GDPR in which the right to access must not be interpreted narrowly as the right to receive a copy. It is accepted that it must also cover additional set of information related to the request to ensure the requestor understands the context.[40] The European Data Protection Board (EDPB) Guideline 01/2022 also reflects this position, by explicitly mentioning that obtaining a copy is not a separate right from Right to Access, rather, access to copy and additional documents becomes the modalities or means of fulfilling the right to access. The EDPB, as a Union-level institution, has actively set out guidelines pertaining to GDPR Articles to ensure uniform application and interpretation throughout member states. Although the Guideline is not binding, it has been consistently followed by member state-level data protection authorities. Specifically, EDPB published Guideline 01/2022 on Data Subject Rights – Right to Access (“Guideline 01/2022”). Several topics discussed include: (1) General purpose & aim of the access (2) Principle of the right (3) Scope of the right (4) How to provide access (5) Limits & restriction of Right to Access.[41] From a practitioner perspective, Brennan & Matheson pointed that this Guideline is vital to reflect the views of data protection supervisory authorities and help organization familiarize with the procedure to handle DSAR.[42]
III.A Data Subject Access Request in Practice:
As Indonesia PDP Law implementing regulations are still work in progress, we propose five steps as set out in (Table 2). This flowchart is inspired by international best practice, partly replicating the EU GDPR-style practicalities.

III.A.I Receiving Request
In practice, there are two options used by an organization in order to receive DSAR. First, DSAR can be submitted manually through email and processed via batches by an organization’s designated Data Protection Officer (DPO). Second, DSAR can be automatically handled.[43] Most DSAR are submitted through electronic means via an online form. This is consistent with the EU GDPR Recital 65 recommendation: “Where possible, the controller should be able to provide remote access to a secure system which would provide the data subject with direct access to his or her personal data”.[44] Based on our cursory review of leading Indonesian Fintech companies’ privacy policy and privacy notice, we learned that some have yet to set out designated DPO, in the event there’s future DSAR request from data subject. Push forward in 2024 and beyond, we assert and anticipate that it might change – subject to the Indonesia PDP Law enforcement and clear implementing regulations in place.
The high-frequency of DSAR submitted to an organization has suggested that automation tools have become highly preferable. For instance, the use of “Dashboard” format, at which users can request access through clicking options available in setting menu. For example, takeout.google.com allows data subject to select and choose categories of personal data being processed, whether the personal data will be sent at an interval, and the company will send out accordingly within 1-2 days.[45] Dashboard is an optimal measure to verify data subject even before a request has been submitted.[46] Interestingly, 58.3% of respondents in our DSAR Awareness Survey revealed they prefer the use of automation tool when handling DSAR – although several comments partly suggest human input and intervention is pertinent (as and when necessary) while using automation tool.[47]

Image 1: Google Takeout Dashboard
While the Dashboard option seems ideal, there are two main drawbacks. First, a data subject does not necessarily need to have an account in order to request access (for instance, IP collection and geolocation without a user account). Second, the use of a dashboard may not cater to a user’s specific requests whilst the purpose and nature of DSAR is processed automatically as it might fail to provide a user with accurate information, as compared to, manually responding to a request.[48] To mitigate and minimize potential drawback, Starling Bank, one of the admirable global Fintech companies, has provided two options: manual request through a designated email and request through an application interface.[49] These options provide data subject an opportunity to opt.
The Indonesia PDP Law have yet to set out specific step-by-step guidance on how data subject can exercise DSAR or for data controller in handling such requests. Comparatively, the EU GDPR amongst others, provided the modalities (how to) such as format of communication, readibility of information given to users. While the Indonesian law is silent on modalities to handle DSAR. It is hoped and ideally anticipated that Indonesia PDP law implementing regulation shall provide practical clarity.
III.A.II User Authentication or Verification
Verifying Data Subject Request
Recital 64 of the EU GDPR called out identity verification: “The controller should use all reasonable measures to verify the identity of a data subject … a controller should not retain personal data for the purpose of being able to react to potential requests.” It emphasizes 2 important aspects: 1) The obligation to properly verify users and; 2) The limitation imposed against verification. In essence, Recital 64 provides leeway to data controller to adopt verification technique whilst verifying a requestor. Data controller may ask for login credentials, email address, national identity card, home address, or even go so far as to call the data subject to properly authenticate the request before proceeding with the request.[50]
Data controller should exercise precautionary measure as requesting an ID Card as means of authentication may be considered not proportional; in short, the principle of data minimization must always be upheld by requiring minimum information. As illustrated in the Irish Data Protection Commission Annual Report 2021, authentication through official ID is likely proportional only when it is impossible to determine the requestor’s identity or he/she asks for sensitive data.[51] This stance is echoed in Guideline 01/2022 that explains the utilization of ID Card in verifying data subject’s identity can lead to unauthorized or unlawful processing by the data controller – even more so when the documents are stored by the data controller.[52] Daniel Cooper & Lars Lensdorf pointed out that Guideline 01/2022 would put a considerable risk for data controller, as it did not provide a solution on how to verify request where verification is needed or when does requesting certain document would not be proportional. Alongside other commenters, Cooper & Lensdorf proposed that requesting ID Card for verification should be allowed if:[53] 1) There is reasonable doubt on the identity or 2) Requesting party has not been authenticated through login credentials. A more stringent verification system is needed to prevent misidentification which would result in personal data leaks to unauthorized parties.
The duty to verify, consistently applies even if no personal data has been disclosed by data controller. This is illustrated in the financial penalty given to Telecom GmbH for failing to set out strong identity verification measures, where a person could receive personal data by only providing name and date of birth.[54]
Indonesia PDP Law omits any norms on verifying data subject’s request that might cause an assumption that verification is not necessary. This is deeply concerning, as responding to DSAR must be done carefully as the information contained (and to be shared) may contain sensitive information and a false requestor becomes a risk that cannot be understated.[55] The term “verification” is called out in Article 29 that mandated data controller to carry out verification to ensure accuracy, completeness, and consistency of personal data.[56] However, according to the Article it is unlikely that this obligation refers to the act of verifying data subject access requests since it puts no reference on data subject rights. Therefore, Indonesia PDP Law is noticeably weaker in governing handling data subject requests from the lens of verification.
Outside of data protection context, the duty to verify is a requirement in Anti Money Laundering regulations, Bank Indonesia and Otoritas Jasa Keuangan regulations. For instance, Article 19 of Peraturan Bank Indonesia No. 23/15/PBI/2021 on Central Bank Services stipulates cautionary principle implementation in the form of identification, verification, and monitoring as part of customer due diligence is al Peraturan Otoritas Jasa keuangan No. 23/01/2019 on AML & Terrorism Funding Prevention.[57] Article 17 provides mandatory know-your-customer programs which requires the submission of National ID.[58] While this is an example of documents used to verify customers, it cannot be automatically translated as the necessary documents for DSAR from data subject – as not every request requires stringent verification. Therefore, the implementing regulations need to clarify types of documents, consider proportionality for each request.
Should 3×24 Hours Time Limit Starts Before Authentication?
One of the most common violations regarding DSAR, is the failure to provide timely response. In relation to DSAR timeline, there is a noticeable difference between the EU GDPR and Indonesia PDP Law.
Under the EU GDPR, Article 12 stipulates “controller shall provide information on action taken on a request … without undue delay, and in any event within one month of receipt of the request.” This deadline applies to most data subject rights such as rights to access (Article 15), right to rectification (Article 16), right to erasure (Article 17), right to restriction of processing (Article 18), right to data portability (Article 20), right to object (Article 21), right to not be automatically processed (Article 22), and in addition: the right to be notified in case of rectification and erasure (Article 19). One must note that the deadline under Article 12 does not mean the right must be fulfilled within the time period, as it only mandated the data controller to provide any form of response regarding information of the submitted request.
Prior to Guideline 01/2022, Helena Krabec pointed out that there are two diverging interpretations on when the timeline began. First, several data protection authorities have strictly followed the “date of receipt” wording of the EU GDPR where the date will be counted since the request has been received. On the other hand, other data protection authorities have followed a more flexible approach by counting “date of receipt” after a qualified request – meaning after the request has been clarified, paid, or where the requestor has been successfully verified.[59] However, Guideline 01/2022 provides clarity that the time limit should start when the request reaches the controller (regardless of whether the controller is aware or not) but can be suspended if there is uncertainty regarding the requestor identity or when the data controller requires additional information regarding specificity of the request.[60] On that note, EDPB also recommends for data controllers to sending out confirmation on the receipt requests and informs the data subject on specific timeline (eg: the one month period runs from 20 January 2023 to 20 February 2023).[61] Therefore, there is clarity on the time limit starting date.
In Indonesia, the time limit for exercising data subject rights varies as tabulated below:
| No. | Issue | Legal Basis | Deadline |
| 1. | Right to rectify | Article 30 | 3×24 hours (3 days) after receiving a request. |
| 2. | Right to access | Article 32 | 3×24 hours (3 days) after receiving a request. |
| 3. | Right to object | Article 40 | 3×24 hours (3 days) after receiving a request. |
| 4, | Right to restriction of processing | Article 41 | 3×24 hours (3 days) after receiving a request. |
Similar to the EU GDPR, Indonesia PDP Law has set out a uniform time limit to respond to data subject rights. Interestingly, the wording leads to completion of the request – not a response to the request. For instance, Article 32 Paragraph (2) stipulates: “The access as referred to in paragraph (1) shall be granted no later than 3 x 24 (three times twenty-four) hours from the time that the Personal Data Controller receives the access request.” This is a stark difference from the time limit provided under The EU GDPR which stipulates: “The controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject … in any event within one month …” Therefore, Indonesian data protection law expects the request to be fulfilled within 72 hours while the EU GDPR only requires any form of response within one month of the receipt.
The time limit for DSAR will become a huge issue in Indonesia, if Article 32 Paragraph (2) is not amended. Previously, Asosiasi Fintech Indonesia (AFTECH) submitted its input on the draft of Indonesian PDP Law and discussed with the Indonesian Parliament regarding several issues of the draft. Timeline for right to access is a contentious issue. AFTECH viewed the time limit as extremely restrictive based on two rationales: 1) Not all industry have the same capacity to comply with 3×24 hours timeline; and 2) The proposed timeline are stricter than the EU GDPR (1 month with possible extension) and even Malaysia Personal Data Protection Act 2010 (21 days with possible extension).[62] Other jurisdictions, such as the California Consumer Privacy Act allows up to 45 days with possible extensions in responding to DSAR.[63] While Singapore Personal Data Protection Act 2012 sets out an obligation to provide access as soon as possible, but allows extension by the company if it cannot provide access within 30 calendar days after notifying it to the requestor.[64] This shows that Indonesia is on the extreme side in DSAR time limit, as well as DSAR completion date. According to Meribeth Banaschik, DSAR compliance is not easy. From the resource perspective, it would require around US$ 1400 for each company to set out a system to handle DSAR exercise effectively while manual DSAR would require approximately 2 weeks to be processed.[65] This is consistent with our survey result, to which, a short DSAR timeline is suboptimal with 50% views that they are unsure if meeting the deadline is possible and 20.83% views it is not possible. Of relevance, and to contextualize, Fintech companies might face problem in compiling high volume DSAR within such strict deadline.
Risk Related to Deadline and Incorrect Verification
Within the context of DSAR deadline, organizations are being pressured into adhering to two aspects. First, the obligation to fulfill data subject’s rights within the strictly imposed timeline. Second, it must handle DSAR prudently as to prevent any unauthorized disclosure to another party. However, the two obligations can conflict with each other if organizations bypass security measure that might infringe the Right to Access through unauthorized third parties’ unlawful data access. In 2018, Pavur and Knerr conducted a study on attempts to simulate access requests from hackers by utilizing publicly accessible data to bypass DSAR verification mechanism on 150 companies. Unclear DSAR implementation guideline and weak authentication obligation to data controllers might lead to dreadful penalty. For instance, data subjects are compelled to refuse providing additional documents by arguing that it is not “proportional”.[66]
Guideline 01/2022 clarified that the objectives from data subject in exercising DSAR must not play a role in assessing the validity of the request,[67] Daniel Cooper & Lars Lensdorf pointed out that this is one of the most controversial statements by EDPB as assessing the intent or objectives of the request are necessary to prevent abusive requests.[68] The purpose of DSAR is to “enable the data subject to ascertain and verify the lawfulness of the processing, and if necessary, to exercise their rights”[69] while other purposes, such as circumventing administrative procedures to gain access to document or obtaining evidence for court proceedings should not be entertained by way of DSAR. Therefore, assessing the intent of hackers may not be easily possible under the EU GDPR and Indonesia DP Law.
In addition to the sheer volume of DSAR, some companies may opt to immediately comply with any request in fear of missing the timeline or choose not to refuse at all since the basis of DSAR refusal is ultimately vague. From that perspective, data controllers are more likely to comply with potentially invalid or fake DSAR.[70] Unlike other social engineering attempts, hackers can hide behind the legitimacy of DSAR to manipulate data controllers in justifying their access to data.[71] For instance, by sending vague DSAR requests and providing falsified documents – hackers could mislead data controllers to disclose personal data of affected data subjects.
In 2022, high-level data breaches in Indonesia exposed voluminous personal data and/or documents such as national ID (KTP), tax number (NPWP), and official passports that are often used as DSAR’s authentication measures[72] Coupled with the nonexistent verification guideline for handling DSAR, a scenario where hackers would have easily impersonated data subjects and abuse DSAR are very likely to occur. In January 2023, a criminal impersonated a bank customer using forged and stolen documents is a stark reminder on the verification procedural flaw in Indonesia.[73] With the opportunity to digitally impersonate customers, Right to Access may become the next weapon for hackers to exploit. Within the Indonesian context, DSAR obligation applies to almost every business sector, ranging from sophisticated digital industry to small medium enterprises that operate traditionally with varied resource strength and bandwidth.[74] A “one-size fit all” approach in determining the time limit might not have been an ideal choice as it can burden business actors disproportionately.
III.A.III Calibration, Recalibration, and Redaction
After authenticating the request, it’s important to clarify the scope of request, and make sure that the requested information falls into the category of personal data that can be accessed under DSAR. Data controller is encouraged not only to search within its online database, but also offline documents.[75] Calibrating the search criteria is also recommended by EDPB Guideline 01/2022. For instance, if the requestor’s personal data is stored in each category (name, date of birth, gender, and others) then the use of search criteria in these structured data. However, data controller has the discretion in determining how the search is conducted as long as it provides the accurate dataset.[76]
Throughout the search process, data controller may discover the data it compiled might have been mixed with non-personal data or third party’s personal data. At this stage, data controller must review, validate, redact and repeat the exercise for quality assurance purpose. DSAR scope is not the document in its entirety, but the data subject’s personal data. Therefore, data controller is mandated to disclose parts of document which contains personal data relating to the data subject’s request and does not disclose other documents, information and third party’s personal data.[77]
III.A.IV DSAR Exemption Check
Similar to another exercise of rights, there are limitations on how data subject can utilize their Right to Access through DSAR. We limit our discussion on DSAR-specific exemption and do not discuss the blanket exemption on all data subject rights as set out in Article 23 of the EU GDPR restrictions. In EU perspective, there are two grounds where data controllers can refuse to handle DSAR. First, Article 12 (5) stipulated: “Where request from a data subject are manifestly unfounded or excessive, in particular because of their repetitive characters, the controller may either (a) charge a reasonable fee … (b) refuse to act on the request”.[78] Second, whether answering DSAR would balance the rights and freedoms of others as stipulated under Article 15 (4). Data controller must act cautiously before deciding to refuse to act on DSAR as the threshold of manifestly unfounded or excessive request is very high, and the data controller must also inform the requestor that DSAR has been rejected. For instance, a case where the court held that a DSAR was “manifestly unfounded” arises where data subject is requesting documents utilized as evidence for civil litigation – in essence, DSAR was utilized as subpoena and not as the intended purpose of verifying data processing.[79] Data controller is still obliged to inform the requestor if the request cannot be processed any further and direct it to supervisory authority for any future complaint.
Furthermore, EDPB Guideline 01/2022 provides the mechanism in checking the limitation and restriction of DSAR. In the case that the DSAR fulfillment would lead to negatively affecting the freedom of others (for instance, a financial report of data subject also contains personal data of other persons such as sellers, management, or the counterpart of transactions), data controller must check if such issue can be resolved by redacting the data as mentioned in the previous section before considering to refusing the request. In addition, it must also be noted that the Right to Access scope only extends to personal data and does not provide access to the related document in its entirety.
Unlike the EU GDPR, Indonesia PDP Law does not mention any specific limitation for DSAR. The only limitation that can apply is the blanket exception against all data subject rights for the: 1) Interest of national defense and security; 2) Interest of law enforcement process; 3) Public interest in the context of state administration; 4) Interest of financial services, monetary, payment system, and financial system stability; 5) Statistics and scientific research.[80] The mechanisms and specifics of this exception will be regulated in implementing regulations.[81] Therefore, it is imperative to set out detailed specifics on the grounds where DSAR can be rejected similar to the EU GDPR and EDPB Guideline 01/2022.
III.A.V DSAR Secure Delivery
As the final step of DSAR, data controller must deliver the copy of requested personal data in secured platform to the data subject. Data controller might need to consider if specific assistance or requirements is needed (if the data subject is less able due to physical condition or being represented by a guardian or trusted person).
IV. Cross-Jurisdictional DSAR: Case Concerning ASEAN QRIS Payment System Request
Among the most recent development in the Financial & Technology sector is the deployment of Quick Response Code Indonesian Standard (“QRIS”) acts to standardize QR code for all payment providers – thus enabling interoperability between e-wallet and payment providers.[82] The program was first launched in 2019 to increase financial inclusion and digital payment accessibility acceleration for Micro Small Medium Enterprise in Indonesia, but now QRIS model is also utilized to facilitate cross border QR Payment Linkage as agreed on various Government-to-Government arrangement.[83] During Indonesia G20 Presidency, five central bank of major ASEAN countries (Bank Indonesia, Bank Negara Malaysia, Bank of Thailand, Bangkok Sentral ng Pilipinas, and Monetary Authority of Singapore) signed the Memorandum of Understanding on Cooperation in Regional Payment Connectivity to facilitate cross-border QR Code and Fast Payment by 2025.[84] While from the economic perspective, this will accelerate growth in the region, the personal data processing activities within this technology should be addressed appropriately.
The QR Code initiative will involve multiple data controllers, data processors or joint data controllers and processors from private entities. For instance, in the pilot project between Bank of Indonesia and Bank of Thailand – 76 financial service providers are involved in assisting cross-border QR code transactions from customers to merchant.[85] Eventually, the financial service providers and related Fintech companies will process personal data of consumers throughout ASEAN region. An Indonesian tourist can conduct transaction through QR code at Chatuchak Market in Thailand, at which the Thailand’s Fintech company will have financial records that contain personal data of the Indonesian tourist. In this scenario, the tourist, as data subject will be able to send out DSAR to these Fintech companies. While we have highlighted the problems of handling domestic DSAR, a Cross-Border DSAR would create another layer of complexity due to the different timeline, as illustrated below:
| Country | DSAR Timeline |
| Indonesia | 3 x 24 Hours (Non Extendable) |
| Malaysia | 21 Days (Extendable) |
| Thailand | 30 Days (Non Extendable) |
| Philippines | Subject to nature and complexity of DSAR |
| Singapore | 30 Days (Extendable) |
As illustrated above, different timeline might pose burdensome to Fintech companies as they would eventually need to comply with country-specific DSAR timeline. This is also not taking into account that every country shall have different verification mechanism considered “proportionate” as part of authenticating request before disclosing any data (including financial transactions data). A harmonization effort akin to the EU, bearing in mind the interconnectedness of ASEAN digital economy might be an interoperable solution.
This issue does not only arise on QR-based cross border payment system, but also occurs in all aspect of Fintech DSAR handling in ASEAN region. We conducted a privacy policies and notices analysis of leading and admirable Fintech companies in Indonesia, Singapore, Philippine, and Malaysia while comparing it to matured data protection jurisdiction such as the UK and the EU. From this analysis, we learned three crucial points: 1) In developing jurisdiction like Indonesia, there is generic information relating to DSAR ; 2) Several Fintech companies have yet to specify a designated DPO as main DSAR point of contact whether by manual or direct communications; 3) Language barrier shall become an issue in cross-jurisdictional DSAR as most privacy policies and notices are written in local language, instead of bilingual or multilingual (for instance, privacy policy and notice of an Indonesian Fintech company is only available in Bahasa Indonesia, but not other languages) which renders data subject outside Indonesia struggle to understand how their personal data is being processed and importantly to effectuate future DSAR.
In 2016, ASEAN adopted the Framework on Personal Data Protection, amongst others, recognizing the Right to Access as part of the principles of personal data protection in the region.[86] However, the principle mentions that the access should be provided “within a reasonable period of time” and ASEAN member states have different DSAR timeline and requirement despite this framework. Therefore, we propose two approaches; First, to create a uniform timeline and cross-border DSAR requirement across the region or at least between member states that have signed the Memorandum of Understanding on Cooperation in Regional Payment Connectivity. Second, to provide a clear exemption that can be used, when necessary, by Fintech companies in the QR-Code or international payment systems in the region.
IV. Concluding Remarks
To conclude, we have established the fundamentals of DSAR for data subject and data controller. As a developing jurisdiction, there will be practical challenges relating to DSAR implementation in Indonesia, chiefly derived from existing flaw of implementation guideline and lack of awareness on the exercise of data subject rights. In this article, we have provided the historical background of Indonesia PDP Law, influenced deeply by the EU GDPR, and showcased how DSAR is being practiced in developed jurisdictions. Visually, we illustrated DSAR workflow that might be useful to be considered in forthcoming DSAR implementing regulations in Indonesia, aimed to avoid legal uncertainty and contextualized baseline global best practice.
We admit that Indonesia PDP Law is still work in progress and recognize the sophisticated cross-border payments and rapid growth of Fintech technologies in ASEAN. We intertwined Fintech’s data processing activities and DSAR that could pose practical compliance challenge domestically, regionally and internationally. From an eagle’s eye view, diverging global DSAR timeline and requirements might trigger excessive compliance cost for Fintech companies and non-Fintech companies that process voluminous dataset (Indonesian, ASEAN and non-ASEAN personal data, including but not limited to the E.U dataset). As an interoperable solution, we proposed a common framework that harmonize DSAR handling, and unboxed the strict, but arbitrary DSAR timeline set forth in several jurisdictions in ASEAN member states, including Indonesia. Moving forward, we will aim to expand this paper to Part II and volunteer to be part of future stakeholders consultation to shaping Indonesia and ASEAN DSAR harmonization in 2024 and beyond.
[1] Edmon Makarim, Pengantar Hukum Telematika (Depok: PT Raja Grafindo Persada, 2005), 31.
[2] Daniel J. Solove, The Digital Person, Technology, and Privacy in the Information Age (New York: New York University Press, 2004), 13.
[3] Solove, The Digital Person, 13.
[4] Samuel Warren and Louis Brandeis, “The Right to Privacy,” Harvard Law Review, no. 5 (December 1890): 193-220.
[5] David Banisar, “Privacy & Human Rights An International Survey of Privacy Laws and Developments,” The John Marshall Journal of Computer & Information Technology, vol. XVIII (January 1999): 6.
[6] Ian J. Lloyd, Information Technology Law, (United Kingdom: Oxford University Press, 2014), 52.
[7] Jina Moore, “Cambridge Analytica Had a Role in Kenya Election, Too,” The New York Times, March 20, 2018, https://www.nytimes.com/2018/03/20/world/africa/kenya-cambridge-analytica-election.html/; Paul Lewis and Paul Hilder, “Leaked: Cambridge Analytica’s blueprint for Trump victory,” The Guardian, March 23, 2018, https://www.theguardian.com/uk-news/2018/mar/23/leaked-cambridge-analyticas-blueprint-for-trumpvictory/; Ed Power, “The Great Hack: The story of Cambridge Analytica, Trump and Brexit,” The Irish Times, July 24, 2019, https://www.irishtimes.com/culture/tv-radio-web/the-great-hack-the-story-of-cambridge-analytica-trump-and-brexit-1.3965788.
[8] Sinta Dewi, “Balancing Privacy Rights and Legal Enforcement: Indonesia Practices,”
International Journal of Liability and Scientific Enquiry 5, (February 2012): 233, https://doi.org/10.1504/IJLSE.2012.051961.
[9] Sinta Dewi Rosadi, Siti Yuniarti, and Rizki Fauzi, “Protection of Data Privacy in the Era of Artificial Intelligence in the Financial Sector of Indonesia,” Journal of Central Banking Law and Institutions, no. 2, (2022): 353-366, https://doi.org/10.21098/jcli.v1i2.18.
[10] Jeferson Kameo, “Panama Papers dan Diskursus tentang Perlindungan Data di Indonesia: Suatu Perspektif Teori Keadilan Bermartabat,” Jurnal Refleksi Hukum, no. 1, (2016): 92, https://doi.org/10.24246/jrh.2016.v10.i1.p84-98.
[11] Ima Dini Shafira, “DPR Resmi Sahkan RUU Perlindungan Data Pribadi,” Tempo.co, September 20, 2022, https://nasional.tempo.co/read/1636301/dpr-resmi-sahkan-ruu-perlindungan-data-pribadi.
[12] Umi Sugiyanti and Agung Pambudi, “Perlindungan Data Privasi dan Kebebasan Informasi dalam Platform WhatsApp,” Jurnal Ikatan Pustakawan Indonesia, no. 2 (2022): 67
[13] Pratiwi Agustini, “UU PDP Akan Permudah Pertukaran Data dengan Negara Lain,” Direktorat Jenderal Aplikasi Informatika,” accessed January 21, 2023, https://aptika.kominfo.go.id/2020/11/uu-pdp-akan-permudah-pertukaran-data-dengan-negara-lain/.
[14] Anu Bradford, “The Brussels Effect,” Northwestern University Law Review, no. 1 (2015): 1–68.
[15] Christian Peukert et. al, “Regulatory export and spillovers: How GDPR affects global markets for data,” Centre for Economic Policy Research, September 30, 2020, https://cepr.org/voxeu/columns/regulatory-export-and-spillovers-how-gdpr-affects-global-markets-data.
[16] Anastasia Petrova, “The Impact of the GDPR Outside the EU,” Lexology.com, September 17, 2019, https://www.lexology.com/library/detail.aspx?g=872b3db5-45d3-4ba3-bda4-3166a075d02f.
[17] Eline Chivot and Daniel Castro, “The EU Needs to Reform the GDPR to Remain Competitive in the Algorithmic Economy,” Center for Data Innovation, May 13, 2019, https://datainnovation.org/2019/05/the-eu-needs-to-reform-the-gdpr-to-remain-competitive-in-the-algorithmic-economy/.
[18] Wanda Presthus and Kaja Felix Sønslien, “An analysis of violations and sanctions following the GDPR,” International Journal of Information Systems and Project Management, no. 1 (2021): 45-46, https://doi.org/10.12821/ijispm090102
[19] “IAPP-EY Annual Privacy Governance Report 2018,” International Association of Privacy Professionals and Ernst & Young, accessed January 21, 2023, https://iapp.org/resources/article/iapp-ey-annualgovernance-report-2018/.
[20] Yudha Pratomo, “Google Sebut UU Perlindungan Data Pribadi Bisa Menyusahkan Startup,” Kompas.com, August 28, 2019; https://tekno.kompas.com/read/2019/08/20/14050087/google-sebut-uu-perlindungan-data-pribadi-bisa-menyusahkan-startup?page=all; Lona Olavia, “Industri Minta Kepastian Hukum Perlindungan Data Pribadi,” BeritaSatu.com, March 30, 2021, https://www.beritasatu.com/ekonomi/753123/industri-minta-kepastian-hukum-perlindungan-data-pribadi.
[21] Thomas Linden et al., “The Privacy Policy Landscape After the GDPR,” Proceedings on Privacy Enhancing Technologies, no. 1 (2020): 48-49, https://doi.org/10.2478/popets-2020-0004.
[22] Kazim Degerli, “Regulatory Challenges and Solutions for Fintech in Turkey,” Procedia Computer Science 158 (2019): 935
[23] Keke Gai, Meikang Qui, Xiaotong Sun, “A survey on FinTech,” Journal of Network and Computer Applications, vol. 103 (2018): 262–273.
[24] Lastuti Abubakar and Tri Handayani, “Financial Technology: Legal Challenges for Indonesia Financial Sector,” IOP Conf. Series: Earth and Environmental Science 175, (2018): 3.
[25] Elena Hernández et al., “Data Protection on Fintech Platforms,” International Conference on Practical Applications of Agents and Multi-Agent Systems, vol. 1047 (June 2019): 223–233, https://doi.org/10.1007/978-3-030-24299-2_19.
[26] Hendrawan Agusta, “Keamanan dan Akses Data Pribadi Penerima Pinjaman dalam Peer To Peer Lending di Indonesia,” KRTHA Bhayangkara, no. 1 (June 2021): 18-19, https://doi.org/10.31599/krtha.v15i1.289.
[27] Arnoud Boot et al., “Fintech: what’s old, what’s new?,” Journal of Financial Stability 53, (2021): 3, https://doi.org/ 10.1016/j.jfs.2020.100836
[28] Aleksandr P. Alekseenko, “Privacy, Data Protection, and Public Interest Consideration for Fintech,” in Global Perspectives in FinTech: Law, Finance and Technology, (London: Palgrave Macmillan, 2022), 39.
[29] Alekseenko, “Privacy,” 27.
[30] Abubakar and Handayani, “Financial Technology,” 3.
[31] Helena Vrabec, Data Subject Rights under the GDPR with a Commentary Through the Lens of Data-Driven Economy (New York: Oxford University Press, 2021), 38.
[32] Gabriela Zanfir-Fortuna, “The EU General Data Protection Regulation (GDPR): A Commentary,”: 452.
[33] Steve Peers et al., The EU Charter of Fundamental Rights: A Commentary (Oxford: Hart Publishing, 2014), 254.
[34] Hannah Kuchler, “Max Schrems: the man who took on Facebook – and won,” The Irish Times, April 5, 2018, https://www.irishtimes.com/business/technology/max-schrems-the-man-who-took-on-facebook-and-won-1.3451485
[35] Cedric Lauradoux, “Can Authoritative Governments Abuse the Right to Access?,” in Privacy Technologies
and Policy 10th Annual Privacy Forum, APF 2022 Warsaw, Poland, June 23–24, 2022, Proceedings, (Warsaw: APF 2022, 2022), 23.
[36] Gabriella Zanfir Fortuna, the EU General Data Protection Regulation (GDPR): A Commentary: 453.
[37] Antonella Galetta et al., “Mapping the Legal and Administrative Frameworks of Access Rights in Europe: A Cross-European Comparative Analysis,” Work Package 5 for the IRISS Project (2014).
[38] Article 79 of Law No. 23 of 2006 on Citizen Administration (Amended by Law No. 24 Year 2003).
[39] Article 7 ofLaw No. 27 of 2022 on Personal Data Protection Act.
[40] Beatriz Esteves, Vıctor Rodriguez-Doncel, and Ricardo Longares, “Automating the Response to GDPR’s Right of Access,” Legal Knowledge and Information Systems (2022): 171,
https://doi.org/10.3233/FAIA220462
[41] “Guidelines 01/2022 on data subject rights – Right of access,” European Data Protection Board, adopted on January 18, 2022, https://edpb.europa.eu/system/files/2022-01/edpb_guidelines_012022_right-of-access_0.pdf.
[42] Davinia Brennan, “The New Guidelines on Access Request – is the bar now too high?,” Data Protection Ireland, vol. 15 (May 2022).
[43] Lauradoux, “Can Authoritative,” 25.
[44] Vrabec, “Data Subject,” 38.
[45] Author experience.
[46] Thomas J. Smedinghoff, “The Duty to Verify Identity: A Criticial Component of Privacy and Security Compliance,” PLI 22nd Annual Institute on Privacy & Cybersecurity (April 2021): 10.
[47] Muhammad Deckri Algamar and Noriswadi Ismail, “DSAR Awareness Question Survey Results”: Question 5, 2022.
[48] Vrabec, “Data Subject,” 110.
[49] Starling Bank. “Privacy Notice” Security Boulavard, Version 3.1, Effective 13 July 2022. https://www.starlingbank.com/legal/privacy-notice/
[50] Mariano Di Martino et al., “Personal Information Leakage by Abusing the GDPR “Right of Access”,” Fifteenth Symposium on Usable Privacy and Security, (August 2019): 374.
[51] Data Protection Commission, “Irish Data Protection Commission’s Annual Report 2021,” An Coimisiun Chosaint Sonrai, February 24, 2022, 30.
[52] European Data, “Guideline 01/2022,” 69-78.
[53] Daniel Cooper & Lars Lensdorf, “EDPB Draft Guidelines 01/2022 on Data Subject Rights – Right of Access”, Computer Law Review international (March 2022): 68.
[54] Graham Cluley, “1&1 Telecom GmbH hit by almost €10 million GDPR fine over poor security at call centre,” Security Boulavard, last modifiedDecember 11, 2019, https://securityboulevard.com/2019/12/11-telecom-gmbh-hit-by-almost-10-million-gdpr-fine-over-poor-security-atcall-centre.
[55] Vrabec, “Data Subject,” 111.
[56] Indonesia, Law No. 27 of 2022, Personal Data Protection Act, Article 29.
[57] Indonesia, Peraturan Bank Indonesia No. 23/15/PBI/2021, Article 19
[58] Indonesia, Peraturan Otoritas Jasa Keuangan No. 23/01/2019, Article 17
[59] Vrabec, “Data Subject,” 113.
[60] European Data, “Guideline 01/2022,” 157.
[61] European Data, “Guideline 01/2022,” 57.
[62] “Masukan dan Pandangan Industri Fintech atas Rancangan Undang-Undang Perlindungan Data Pribadi,” Fintech Indonesia: 50, accessed on 5 February 2023 https://www.dpr.go.id/dokakd/dokumen/K1-RJ-20200706-021940-3243.pdf; Rancangan Undang-Undang Data Pribadi,” Fintech Indonesia: 18, accessed on 5 February 2023, https://www.dpr.go.id/dokakd/dokumen/K1-RJ-20200706-022052-5497.pdf.
[63] “The California Consumer Privacy Act of 2018,” Spirion: 1798.130, accessed on 7 February 2023, https://www.spirion.com/wp-content/uploads/2020/07/Spirion_CCPA_v3.pdf.
[64] “Guide to Handling Access Requests,” Personal Data Protection Commisison Singapore, accessed on 7 February 2023, https://www.pdpc.gov.sg/-/media/Files/PDPC/PDF-Files/Other-Guides/guide-to-handling-access-requests-v1-0-(090616).pdf.
[65] https://www.ey.com/en_gl/forensic-integrity-services/how-to-comply-with-data-subject-access-request
[66] James Pavur and Casey Knerr, “GDPArrrrr: Using Privacy Laws to Steal Identities,” Blackhat USA 2019 Whitepaper (December 2019): 4, https://doi.org/10.48550/arXiv.1912.00731.
[67] European Data, “Guideline 01/2022,”13
[68] Daniel Cooper & Lars Lensdorf, “EDPB Draft Guidelines 01/2022 on Data Subject
Rights – Right of Access”, Computer Law Review international (March 2022): 57
[69] EU General Data Protection Regulation, Recital 63
[70] Pavur and Knerr, “GDPARRRR: Using Privacy,” 2.
[71] Pavur and Knerr, “GDPARRRR: Using Privacy,” 8.
[72] Izzat Ats Tsaqofi, “Kebocoran Data PeduliLindungi Valid? Begini Jawaban Pakar,” Voi.id, November 17 2022, https://voi.id/teknologi/228258/kebocoran-data-pedulilindungi-valid-begini-jawaban-pakar.
[73] Praditya Fauzi Rahman, “Pemilik Rp 320 Juta yang Dibobol Tukang Becak Pertanyakan Tanggung Jawab Bank,” DetikJatim, January 23, 2023, https://www.detik.com/jatim/hukum-dan-kriminal/d-6529276/pemilik-rp-320-juta-yang-dibobol-tukang-becak-pertanyakan-tanggung-jawab-bank.
[74] Titah Arum M. R. Toewoeh, “Kominfo dan Kadin Sosialisasi UU PDP ke Pelaku Usaha,” Kominfo, October 29, 2022, https://aptika.kominfo.go.id/2022/10/kominfo-dan-kadin-sosialisasi-uu-pdp-ke-pelaku-usaha/.
[75] European Data, “Guideline 01/2022,” 123.
[76] Davinia Brennan, “The New Guidelines on Access Request – is the bar now too high?,” Data Protection Ireland, vol. 15 (May 2022): 2.
[77] Paul Buckle, “Data subject access requests and beneficiaries’ rights to information,” Trusts & Trustees, Vol. 25, No. 3, (April 2019): 336.
[78] EU General Data Protection Regulation, Article 12(5).
[79] Agencia Espanola Proteccion Datos, E/00739/2021.
[80] Indonesia, Law No. 27 of 2022, Personal Data Protection Act, Article 15 (1)
[81] Indonesia, Law No. 27 of 2022, Personal Data Protection Act, Article 15 (2)
[82] Oxford Analytica, “Fintech growth outpaces regulation in Indonesia”, Expert Briefings, accessed on 18 February 2023] https://doi.org/10.1108/OXAN-DB264128.
[83] Perry Warjiyo and Solikin M. Juhro, Central Bank Policy Mix: Key Concepts and Indonesia’s Experience dalam Central Bank Policy Mix: Issues, Challenges, and Policy Responses, (Jakarta: BI Institutes, 2022), 15.
[84] Communication Department of Bank Indonesia, “Central Banks of Indonesia, Malaysia, Philippines, Singapore and Thailand Seal Cooperation In Regional Payment Connectivity,” Bank Indonesia, November 14, 2022, https://www.bi.go.id/en/publikasi/ruang-media/news-release/Pages/sp_2430822.aspx.
[85] Communication Department of Bank Indonesia, “Indonesia dan Thailand Meresmikan Implementasi Pembayaran Kode QR Lintas Negara,” Bank Indonesia, August 29, 2022, https://www.bi.go.id/id/publikasi/ruang-media/news-release/Pages/sp_2423222.aspx.
[86] “Framework On Personal Data Protection,” Asean Telecommunications And Information Technology Ministers Meeting (TELMIN), accessed on 20 February 2023. https://asean.org/wp-content/uploads/2012/05/10-ASEAN-Framework-on-PDP.pdf.
Muhammad Deckri Algamar
Universitas Indonesia
Noriswadi Ismail
European Advisory Board Member, International Association of Privacy Professionals, United Kingdom
Tulisan ini telah terbit di Journal of Central Banking Law and Institutions 2(3), 481–512. https://doi.org/10.21098/jcli.v2i3.171
