
- DATA BREACH NOTIFICATION AS KEY PRINCIPLE OF PERSONAL DATA PROCESSING IN INDONESIA
Personal data protection legal framework globally is based on data processing principles to ensure that normative requirements of the law can go hand-in-hand with the foundational principle throughout Personal Data processing. The historical root of these principles can be traced to OECD Principle 1980 and Council of Europe 108+ Convention that sets out the early framework of personal data processing principles, this framework is then modernized and adapted into various jurisdictions across the world.[1] Most notably, European General Data Protection Regulation (“EU GDPR”) became the most comprehensive and mature data protection framework that first adopted personal data processing principles, however the norms under EU GDPR have continued to influence and inspire other countries beyond EU Member States jurisdiction in drafting their national privacy laws.[2] In 2021, Graham Greenleaf pointed out that GDPR as a data protection legal framework has become a major inspiration of over 145 data protection laws across the globe.[3] This includes the recently legislated Indonesia’s Law No. 27 Year 2022 on Personal Data Protection (“UU PDP”) that contains similar data processing principles that must be adhered to throughout data collection, data usage, data storage, data transfer, and data erasure to any entities processing Personal Data. The similarities are illustrated on the table below:[4]
Table 1. Data Processing Principles under UU PDP & EU GDPR
| No. | UU PDP Principles | EU GDPR Principles |
| 1. | Personal Data collection must be conducted in a limited manner, specific, lawful, and transparent | “Lawfulness, fairness, and transparency” “Data minimization” |
| 2. | Personal Data processing must be conducted in accordance with its purpose | “Purpose limitation” |
| 3. | Personal Data processing is conducted by ensuring the rights of Personal Data Subject | No similar principle is found |
| 4. | Personal Data processing must be conducted accurately, complete, not misleading, up-to-date, and in accountable manner | “accuracy” |
| 5. | Personal Data processing is conducted by protecting the security of Personal Data from unauthorized access, unauthorized disclosure, unauthorized alteration, misuse, destruction, and/or loss of personal data | “integrity and confidentiality” |
| 6. | Personal Data Processing is conducted by informing the purpose and processing activity in addition to failure of Personal Data Protection | No similar principle is found |
| 7. | Personal Data shall be destroyed and/or deleted after the retention period expires, or at the request of Personal Data Subject, unless otherwise stipulated by laws and regulations | “storage limitation” |
| 8. | Personal Data processing is conducted responsibility and can be clearly proven | “accountability” |
Although data processing principles related to “data minimization” or “lawfulness, fairness, and transparency” are commonly found both under UU PDP and EU GDPR, Indonesia uniquely introduces a new principle that elucidates “Personal Data Processing is conducted by informing the purpose and processing activity in addition to failure of Personal Data protection.”[5] This new principle encapsulates two aspects, first is the requirement to inform Data Subjects on the purpose and name of processing activity – which coincides with other data processing principles under UU PDP.[6] The second aspect becomes the foundational principles in delivering Data Breach Notification, a key aspect of cybersecurity incident response management. Further technical application of the latter is found under the current Draft Government Regulation on Implementation of PDP Law (“RPP PDP”), where the current draft expands the principle implementation through conducting a lawful Data Breach Notification, establishing and implementing policy/procedures/guideline to prevent and mitigate cyber incidents.[7] This emphasis towards Data Breach Notification is both found as principle (Article 16 UU PDP) and a separate requirement (Article 46 UU PDP), making Indonesia the only jurisdiction in the world to encapsulate Data Breach Notification both as a data processing principle and key privacy obligation.
The legal framework of Personal Data Protection is not limited to UU PDP, a sector specific requirements must also be taken into account to comply with privacy regulations in Indonesia. For instance, in the financial sector, the newly enacted Bank Indonesia Governor Board Member Regulation No. 20 Year 2023 on the Implementation of Consumer Protection (“PADG 20/2023”) recognizes the importance of Personal Data Protection as part of key principle in consumer protection.[8] Specifically, PADG 20/2023 elucidated that payment system and service operators must always maintain confidentiality and security of data and/or consumer information by using data in accordance with the interest and purpose that has been consented by consumers.[9] PADG 20/2023 is amongst the new series of privacy regulation introduced in the financial sector, with other regulation such as SEOJK 29/2022 on Cybersecurity and Resilience in addition to PBI 23/6/PBI/2021 on Payment Service Providers that mandates a reliable and safe cybersecurity system. Additionally, the sensitivity of several financial institutions might result in the applicability of privacy and security requirements under Presidential Regulation No. 82 Year 2022 on Vital Information Infrastructure if the financial company’s electronic system is categorized under critical infrastructure.[10]
Within the context aforementioned above, it is imperative for any companies in the financial service industry to adapt with the new waves of privacy regulations – not only to comply with the minimum requirement, but also build trust to the consumers in the area of cybersecurity. However, the amount of sensitive data such as financial information makes this industry the most susceptible to cyberattacks that are profit-oriented, such as the case of Ransomware attacks to several major banks and financial service institutions globally.[11] Unfortunately, many companies prior to UU PDP have silently gotten away in dealing with cyber incidents without having to deal with any legal repercussions in maintaining a secure system or providing Data Breach Notification as part of transparency obligations.[12]
Previous writings on the legal liability of failure to notify data breach[13] and calls to establish a Data Protection Authority[14] has been extensively discussed under the regime of Law No. 11 of 2008 year 2008 on Electronic Information and Transactions (“UU ITE”) supported by Government Regulation No. 71 Year 2019 on Electronic System Provider (“PP 71/2019”) and Ministry of Communication and Information Regulation No. 20 Year 2016 (“Permenkominfo 20/2016”). However, there is a novel need to understand privacy and security requirements under UU PDP alongside its intersection with sectoral regulations, when does security failure arise, and the triggers of conducting Data Breach Notification especially in the financial sector that processes high volumes of sensitive Personal Data. In turn, this paper will also explore the practical issue of Data Breach Notification in Indonesia by comparing from the lens of Data Protection Authorities across European Union (Datatilsynet, Tietosuojavaltuutetun toimisto, Gegevensbeschermingsautoriteit, Irish Data Protection Commission, Cyprus Data Protection Commission). Thus, this paper will continue to explore two legal questions:
- How does Indonesia and the EU set out security requirements of Personal Data Protection in the financial sector?
- How does Indonesia and the EU determine Data Breach Notification triggers, its procedures, and the involvement of the Personal Data Protection Supervisory Authority?
In order to answer these questions, this paper will be divided into four sections. First, the introduction to principles and legal framework of cybersecurity and data protection as mentioned above. Second, discussing the cyber risk landscape in the financial sector with a focus on Ransomware as an emerging cybersecurity threat. Third, an analysis of cybersecurity and data protection requirements that must be considered during a cyber incident, followed by an analysis of Data Breach Notification triggers to Data Subjects and/or Data Protection Supervisory Authority. Lastly, we propose a One-Stop Notification Model to mitigate the existing cumbersome and fragmented procedures, with the aim to streamline cyber incident management for Data Controllers, especially in the financial services sector where it had to notify more than one supervisory authority.
- CYBER RISK LANDSCAPE OF FINANCIAL SECTOR: A STUDY ON RANSOMWARE ATTACKS
In the realm of cyber risk, there are three categories of cyber incidents that must be mitigated: (i) incidents due to malicious actors; (ii) incidents due to failure of an organization’s system; and (iii) incidents due to human error.[15] Out of all three, the first category is the most severe due to possible follow-up actions by malicious actors based on financial incentives that could harm Data Subjects directly.[16] This is clearly exemplified in one of Indonesia’s biggest Sharia Bank incidents in May 2023, where a Ransomware group called Lockbit 3.0 has attacked the institution. First, a complete system failure occurred on 8th May 2023 where customers cannot access the bank services at all, this includes preventing customers from conducting transactions, paying bills, or even taking monthly payrolls. In response to this, the bank stated that maintenance is being conducted with no confirmed cyber incidents despite high suspicion from the public.[17] As customer remains anxious, LockBit 3.0 publicly announced that a cyber attack has been deployed against the Sharia Bank after installing a Ransomware that encrypted more than 1.5 terabytes of data containing more than 15.000 customers Personal Data, LockBit 3.0 threaten to release the data into public if the Sharia Bank failed to pay a ransom of $200.000.000 within 72 hours.[18] After receiving the news, the Sharia bank only recognized this Ransomware attack from the malicious group as a generic, one-line “serangan siber” in its 11th May 2023 press statement.[19]As customers scramble in fear of their safety, the Sharia Bank’s continued statement of guaranteeing their customer personal data have become empty promises after LockBit 3.0 leaked all of their ransomed data into the Dark Web after failed negotiation.[20]
The LockBit 3.0 attack is part of the emerging trend of Ransomware attacks against financial institutions. Ransomware is a software that is specifically designed to lock its victim’s system through forced encryption, enabling only the hackers to have access to the data such as photos, personal data, confidential information, or database of its targets – be it public institutions, business, or even individuals. As a business model, Ransomware organizations would use an aggressive tactic to extort their victims after taking control of corporate or institutional assets, promise to provide encryption keys and leave the information safely if the victims are willing to pay a ransom payment.[21] Ransomware organizations will also target organizations by utilizing Ransomware-as-a-service method, where it persuade and recruits individual outside the Ransomware group (such as former employees, insiders, or unassociated hackers) to implant Ransomware to the target and share profit after a successful attack.[22] LockBit 3.0 is among the most successful Ransomware groups to operate by targeting strategic organizations with valuable information such as Personal Data or classified information to be used as leverage during ransom negotiations.
This method of cyberattack has skyrocketed since COVID-19 after mass digitization efforts by many organizations that are not backed with proper cybersecurity and data governance, especially in the banking industry. Badan Siber dan Sandi Negara (“BSSN”) has reported more than 160.000.000 malware anomalies in Indonesia, making it among the highest number of cyberattack categories in the region.[23] With an enhanced capability, there is an expected surge of Ransomware-based cyber attacks in the near future.[24] Similar number of Ransomware attacks is also reflected in various jurisdictions, with Ransomware rising to become the most lucrative malware attacks with the predicted global damages exceeding to $20 trillion annually by 2031.[25]
After being aware of the Ransomware attack, the victim must balance a question: whether or not an organization should pay the ransom? While it remains one of the most difficult question to answer, statistically, 83% of Ransomware attacks globally were paid by organizations because it is believed that it is the quickest and easiest route to ensure business continuity as usual and also to prevent the retrieved consumers personal data to be leaked if it fails to pay.[26] In conjunction with this, Ransomware groups have played their interpretation of data protection laws against their victims, for instance they claim the ransom payment would be cheaper compared to full-on financial penalty by data protection authorities.[27] As a consequence, many companies are persuaded by the Ransomware organization, seeing it as the best solution to settle the incident as quickly and discreetly as possible.
This interpretation is incorrect, as whether the ransom was paid or not does not erase the company’s failure of data protection obligations.[28] Nadir and Bakhshi argued that any form of payment towards attackers is not ideal because of three reasons. First, complying with Ransomware demands would fulfill the business model operated by Ransomware groups and provide more resources to enable more attacks, thus denying payment would be the first step to stop the Ransomware industry. Second, there are no guarantees of the encryption key actually working as seen in several WannaCry Ransomware attacks. In addition, it is also possible for the attackers requesting more money after initial payment was made. Third, ransom payment does not guarantee any more attacks as the hackers already know the vulnerability point to be exploited at a later stage.[29] In fact, there are trends for malicious hackers threatening to sell important files or data to competitors for them to exploit.[30] However, despite all the reasons to not pay ransom, the time-sensitive nature and operational pressure of Ransomware attacks might persuade the organization to pay, as the majority does.
In case of paying Ransomware, negotiation is a key part in managing Ransomware attacks, like its name – hacker groups will set up a price that must be paid as a ransom, paying will provide victims with the needed encryption key to ensure no further harms is done while failure to pay will often lead to data leaks and other malicious actions from the hacker’s side.[31] In its analysis on the dynamics of Ransomware negotiation, P. Ryan et al describes that attackers will refuse a lower counter offer because of several factors,[32] First, Ransomware groups need to maintain their status as a threat, willingness to accept counter offers will demonstrate weakness and trend of accepting lower counteroffers. Two, while a quick negotiation is desirable, attackers do not lose out in the prolonged negotiation, on the contrary, victims may lose more money and reputation as a consequence of Ransomware disruption. Therefore, it is quite clear that Ransomware attackers are not persuaded by sudden lower offers from its victims to the contrary, it might act more aggressively to the victims.
Ransomware and other cyber attacks against financial institutions will be on the rise, as these types of businesses hold valuable personal data which includes financial records, account numbers, and even access to customer credentials that can be lucrative for hackers to exploit after an attack. There seems to be an emerging attack towards the financial service institutions. The Central Bank of Indonesia was allegedly attacked by another Ransomware group in 202 that targeted non-critical employee data,[33] and a financial lending institution was also attacked in May 2023 by an unconfirmed malware which led to an operational switch off during the incident. [34] Thus, there is a strong urgency to put emphasis on the protection of Personal Data in the banking and financial service institutions to prevent attacks from opportunistic hackers.
III. NAVIGATING CYBSERCURITY AND MANDATORY DATA BREACH NOTIFICATION REQUIREMENTS
After understanding the setting of Ransomware as a cybersecurity threat, it is important to recognize the legal requirements set out within Indonesia. In principle, Indonesia’s legal regime for informational privacy and data security stems from UU ITE that was legislated in 2008. Article 16 UU ITE requires that every electronic system provider protects the availability, integrity, authenticity, confidentiality, and availability of electronic systems throughout its operation, thus providing the first requirement of cybersecurity to protect all electronic information (regardless whether the information contains Personal Data or not).[35] While UU ITE provides a security requirement, it is also the first regulation that prohibits IT-based crimes such as illegal access, cracking, and hacking which entails legal repercussions for malicious actors.[36] In 2022, the most recent development is found under UU PDP that specifically regulates the protection of Personal Data, where every entity that processes Personal Data must ensure no failure of personal data, such as failing to maintain confidentiality, integrity, or the availability of Personal Data. In the context of a cyber incidents such as Ransomware attacks, there are two requirements that must be considered: first is to determine whether a security measure is adequate, and second is to determine whether a Data Breach Notification is required as will be discussed in the following sub-section.
III.A. Legal Framework for Cybersecurity Requirements in Indonesia and European Union
UU PDP established a twofold security aspect. First is through the mandatory adherence towards “security principle” mentioned in Section I as Personal Data processing must be carried out by protecting it from unauthorized access, unauthorized disclosure, unauthorized alteration, misuse, and accidental destruction and/or loss of Personal Data.[37] Further elaboration on this principle is set out under RPP PDP,[38] while future changes is expected from the finalized draft, the following measures can be utilized as guiding actions in preparing compliance to the “security principle:[39]
- establish security measures to limit authority for accessing, rectifying, disclosing, and deleting personal data; ensuring accuracy of storage and processing; preparing recovery measures if a data is accidentally lost, altered, or destroyed;
- conducting risk analysis on personal data processing activities to determine the appropriate level of security measures;
- establish information security and personal data protection policy while ensuring the appropriate steps in implementing the policies;
- periodically review the information security and personal data protection policy;
- establish basic technical control;
- implement Personal data protection mechanism through encryption and/or masking;
- discern, determine, and implement parameters for confidentiality, integrity, availability, authentication, wholeness, and accountability of the Personal Data processed;
- ensure that access to Personal Data can be recovered in the case of cyber incidents through creating backup process in accordance with the laws and regulations;
- conducting periodical testing and review against the security control procedures to ensure the activity remains effective and continuous;
On the second layer, UU PDP provides three security-related requirements that must be taken during Personal data processing. Article 35 UU PDP maintains that both Data Controller and Data Processor must set out technical operational measures in protecting Personal Data Security.[40] Similarly, RPP PDP has drafted the implementing steps of “technical operational measures” such as through carrying out pseudonymization/encryption measures towards Personal Data, ensuring the system is capable in retrieving access and returning availability in case of technical or physical incidents, and requires Data Controller or Data Processor to periodically test, evaluate, and assess the effectiveness of the aforementioned measures to ensure security of Personal Data processing.[41] The two other requirements are found under Article 36 and 39 UU PDP that mentioned similar requirements under UU ITE, as Article 36 requires maintaining the confidentiality of Personal Data and Article 39 creates an obligation to prevent Personal data from being illegally accessed.[42] It is to be understood that the requirement to prevent illegal access remains incomplete, as Article 39 Paragraph (2) UU PDP limits the scope of this obligation only to implementing a reliable, safe, and accountable system, but is silent on whether a system is considered “reliable, safe, and accountable” when a malicious attackers, such as Ransomware organization has successfully breached the system despite best efforts from Data Controller or Data Processor.
In comparison with EU GDPR, UU PDP provides a more stringent approach in setting out security requirements. EU GDPR only has 1 (one) security requirements found under Article 32, which provides any Data Controller or Data Processor to “implement appropriate technical and organizational measures.”[43] This can be conducted through non-exhaustive list of action such as: (i)pseudonymization and encryption; (ii) ensuring confidentiality, integrity, availability, resilience of system and services; (iii) capacity to restore availability and access to Personal Data in case of physical or technical incident; (iv) regular testing, assessing, and evaluating the effectiveness of technical and organizational measures to ensure security of processing.[44] Cedric Burton in his analysis of “appropriateness” of technical and organizational measures determined that the action taken must correlate with the risk associated with Personal Data processing activities. Not all measures mentioned under Article 32 (a-d) under EU GDPR must be taken, but EU regulators have indicated a clear preference of these measures to be taken by Data Controllers or Processors.[45]
In stark contrast to Article 36 and Article 39 UU PDP, there is no obligation to maintain complete confidentiality or ensure no illegal/unauthorized access to Personal Data under EU GDPR. As a result, not every breach of the system would result in violation of security requirements under EU GDPR. Within the same line of argumentation, Advocate General Giovanni Pitruzella stated that in order to be exempted from liability on violation of Article 32 EU GDPR, Data Controller must demonstrate that it is not in any way responsible for giving rise to the event which causes damage.[46] Thus, an assessment must be made on a case-by-case basis regarding the appropriate technical or organizational measures taken by the Data Controller alongside its effectiveness by the court of the Data Protection Authority.[47]
However, as it has been made clear: no security measures can completely prevent the possibility of attack or compromise. Therefore, complying with the cybersecurity requirements does not serve as a proof there will be no cyber incident or data breach. Not every data breach is a violation of cybersecurity requirements, however the next step after realizing a system has been attacked is to assess whether data breach triggers mandatory notification.
III.B. Data Breach Notification: Navigating Complexity of Informing Cyber Incidents in Indonesia and European Union
After establishing and meeting the security requirements related to Personal Data, the next step any company must prepare is an effective Data Breach Notification procedure. As mentioned previously, no security system can be completely impenetrable and thus companies need to prepare an incident response policy, this also includes steps in determining when to send notification.While companies must ensure to follow the guideline in mitigating a data breach and recovering the system as quickly as possible, it must also take into account the obligation of drafting and sending out notifications within the stipulated timeline (72 hours or 3×24 hours) regardless if the security incident is caused by internal negligence or due to malicious actors externally. In Indonesia, the obligation to conduct Data Breach Notification arises when “failure of Personal Data Protection” occurred,[48] although the practice remains ambiguous as this section will establish.
A Data Breach Notification is not a simple statement made by the public relations division to preserve a reputation of the company, as privacy law requires mandatory elements that must be included in the notification to ensure the notification is lawful and could provide meaningful information. In essence, there are two types of Data Breach Notification: i) addressed to supervisory authority[49] and; ii) addressed to Data Subjects.[50] Prior to UU PDP, there have been sectoral regulations pertaining Data Breach Notification. Similarly, after UU PDP, there have also been sectoral regulations that provide different specifications to conduct the same notification with no clear delineation on which requirement takes precedence. Therefore, to formulate a comprehensive Data Breach Notification in the financial sector, there are three key regulations that need to be considered in conjunction. First, Ministry of Communication and Informatics Regulation No. 20 Year 2016 on Electronic Personal Data Protection & Government Regulation No. 71 Year 2019 on Private Electronic System Operators which governs data breach in the context of electronic system providers failure.[51]Second, Indonesia’s Law No. 27 Year 2022 on Personal Data Protection which regulates data breach notification procedures in the context of failure to protect Personal Data. Third, is Indonesia’s Financial Service Authority Circular Letter No.29/SEOJK.03/2022 that establishes a Data Breach Notification form for incidents in the financial sector. While all three regulations diverge from each other with no clear lex specialis, understanding the key aspect from each regulation is necessary in drafting a proper Data Breach Notification.
First, in the context of an electronic system provider, a Data Breach Notification is triggered when a “Failure” occurs.[52] This term is elucidated under Article 24 PP PSE as “part or complete cessation of Electronic System function which are essential so that the electronic system no longer functions properly.”[53] When such circumstances arises, a Data Breach Notification must be send out to both relevant subjects and supervisory authority within 14 (fourteen) days after the Failure is known,[54] in accordance with the minimum requirement under Article 14 Paragraph (4) of PP PSE in conjunction with Article 28 Permenkominfo 20/2016:
- Include the reason or cause of Data Protection Failure;
- Send to the victim at maximum 14 (fourteen) days after Data Protection Failure is known;
- Ensure Data Breach Notification is directly received by the relevant victim of Data Protection Failure;
- Received in a written format, unless consent has been established to send the Data Breach Notification electronically.
Permenkominfo 20/2016 also established the principle of “good faith” in sending out Data Breach Notification.[55] While no mention of what this principle entails, it can be concurred that sending the notification as quickly as possible is appreciated to minimize the potential impact that could occur. Furthermore, Article 28 (i) Permenkominfo 20/2016 also mandated an easily contactable contact person for data subjects to liaise with,[56] this is especially important in the context of data breaches where data subjects will need an emergency helpline to ensure that their information is safe or wanting to know further information specific to the subject.
Second, in the context of Personal Data Protection, UU PDP alongside RPP PDP is relevant as it provides a different framework of Data Breach Notification. There are diverging points that sets UU PDP apart from its predecessor: (i) trigger and content of notification; (ii) existence of public notification; and (iii) timeline of Data Breach Notification as will be explained below.
On the first point, a mandatory Data Breach Notification is triggered every time “Personal Data Protection Failure” occurred,[57] unless the failure does not result in any disclosure of Personal Data.[58] Article 46 UU PDP Elucidations provides a clearer guideline on this term, it refers to a failure of protection the confidentiality, integrity, and availability of personal data, including security violations that is intended or not intended which includes to the destruction, loss, alteration, disclosure, or unauthorized access to personal data transmitted, stored, or processed.[59] Similar to PP 71/2019 or Permenkominfo 20/2016, there is no distinction between the minimum information provided to supervisory authority or data subject. Existing draft or RPP PDP establish that Data Breach Notification must at least include:
- Personal Data that has been compromised;
- chronology (how and when) of the compromise;
- impact of Personal Data Protection failure, followed by mitigation and recovery efforts to the compromised Personal Data;
- contact of Person-in-Charge.
On the second point, UU PDP also maintains that a public notification must also be conducted in special circumstances. This circumstance is drafted under UU PDP where an incident has: a) disrupted public services; b) seriously affected public interest; c) cause an impossibility for Data Controller to ensure notification can be directly received by Data Subjects.[60] This issue will be further analyzed after comparison with EU GDPR at the end of this section, there is no guideline or indication to determine when a public notification is necessary and whether it erases the obligation to notify Data Subjects individually in Indonesia.
Lastly, UU PDP provides a significantly diverging timeline of Data Breach Notification when compared to Electronic System Providers regime. Article 46 UU PDP determines a prima facie shortened timeline of 3 x 24 hours to conduct Data Breach Notification.[61] However, RPP PDP clarifies further, the deadline only starts ticking after Personal Data Protection failure is known certainly, appropriately, and reasonably according to the conclusion made from the documentation process of the incident.[62] There is no further guidance on the process of documentation, as Article 125 RPP only clarified the content of documentation as the following:[63]
- root cause of the failure;
- timing and chronology of the failure;
- affected Personal Data;
- consequence of the failure;
- mitigation and recovery actions that is conducted;
- conclusion on whether a compromise has occurred towards Personal Data
- timeline of Data Breach Notifications addressed to Data Subject and PDP Authority;
- impact risk of Personal Data compromise towards Data Subject;
The documentation must be delivered to PDP Authority,[64] but is an entirely different document from a Data Breach Notification that must also be delivered to PDP Authority. While the documentation process provides some leeway in the Data Breach Notification timeline and room for Data Controller to identify risk. We criticize the current draft wording as it provides an unclear scope on the documentation process, essentially enabling an indefinite amount of period before obligation to conduct notification arises. If the 3 x 24 hours deadline starts only after a formal conclusion was made by the Data Controller – there is a possibility for the Data Controller to delay as much as they can before finalizing the documentation process. Below is the example to illustrate the Data Breach Notification timeline:
| On 8th of January 2024, a Digital Bank experienced a Ransomware attack which locks users and operators from the system – essentially creating system failure. Pursuant to Permenkominfo/PSE regime, the latest date of Data Breach Notification must be provided is 14 (fourteen) days after the date which is 22 January 2024. However, under UU PDP and current RPP PDP, the 3 x 24 deadline starts ticking after a formal documentation process has been concluded by the Digital Bank. In practice, a formal documentation process can take months and even years for it to actually materialize – this is the case during Bank of Ireland cyber incident, where a breach has been known by the Bank since 26 April 2019 while final internal investigation was concluded by 6 March 2020, almost a year after the breach is known.[65] As a result, there needs to be further supervision on the documentation stage before leading to notification as this paper will recommend Section IV for Indonesia’s Data Protection Authority in ensuring a reasonable timeline of Data Breach Notification. |
Additionally, the legal relationship between Data Processor and Data Controller adds to the complexity of conducting Data Breach Notification, especially in the context of financial services arrangement. For instance, Banking institutions that directly collect Personal Data from its consumers may require the involvement of other entities such as payment service infrastructure or third-party vendors that added more layers to incident response management.[66] Banking institutions acting as Data Controller will have the obligation to regularly supervise Personal Data processing by third parties that provide assistance to the institutions on their behalf.[67] However, an additional obligation arises in the case of Data Breach on Data Processor’s side (for instance, a company providing cloud storage hosting suffered a data breach, whereas an Indonesian Bank utilized that company service to store consumer and employee data).[68] The duty to notify supervisory authority and Data Subject remains with the bank as its principal, however the cloud-service company has the obligation to notify any failure of Personal Data to the Data Controller at first instance. As the term “first instance” was not clarified under RPP PDP, it is important to establish a clearly defined workflow and procedure of notification during cyber incidents under the mandatory Data Processing Agreement between all parties to establish rights and obligations. [69] Reflecting on EDPB Guideline 9/2023, the European Data Protection Board added an example that Data Processors can send out Data Breach Notification on behalf of the controller as long as proper authorization from the Controller has been made within the contractual agreements.[70]
Moving to the last regulation, the recently enacted Circular Letter 29/SEOJK.03/2022 on Cyber Security and Resilience outlines mandatory security testings and assessments for Banks, but it also laid out detailed procedures of Data Breach Notification to Financial Service Authority as a relevant supervisory authority when data breach occurred in the financial sectors. Similar to Permenkominfo/PSE regime, the trigger arises when a cybersecurity incident arises, defined as “attempts, activity, and/or action that cause electronic system to function not as intended, for instance due to Malware, Web Defacement, and Distributed Denial of Services.” [71] When such an incident occurs, Bank are required to notify the Financial Service Authority in two stages.
First, is Initial Cyber Incident Notification that must be reported within 24 hours after the incident is known, the report contains all available information at early stage regarding cyber incident towards the Bank,[72] (i) such as timing of the incident; (ii) when the incident is known; (iii) type of cyber incident (malware, hacking, Ransomware, defacement, etc); (iv) the name of system or server as incident entry point; (v) initial response after cyber incident; (vi) initial impact assessment. This Initial Cyber Incident Notification can be delivered electronically to the Financial Service Authority, and the Bank must ensure the notification is received properly by the authority.[73] Subsequently, Bank have the obligation to deliver Cyber Incident Report which must include 29 questions in total related to information on the data breach point of contact/reporter, general information of the cyber incident; assessment on the cyber incident towards bank; chronological information of the incident, analysis on the cause of incident; final analysis which includes restorative plans and the target date to solve the issue.[74] This final report must be delivered through the Financial Service Authority reporting system at maximum 5 (five) working days after the cyber incident is known.[75]
Requirements under Circular Letter 29/SEOJK.03/2022 stands independent of any other data breach notification requirements that are in place, such as what is stipulated under Permenkominfo 20/2016 and PDP Law 27/2022. As OJK requirements are more comprehensive compared to the other laws, this can be seen as best practices adopted into the banking industry and financial services institutions. However, it raises the issue of regulatory overlap when Permenkominfo 20/2016, UU PDP, and sectoral regulations significantly diverge from each other either in the content of notification in addition to the timeline.[76] This will be dissected further under Section IV.
II.A.1. EU GDPR Perspective and Practices on Data Breach Notification
As a comparison in understanding the depth of Data Breach Notification requirements, EU GDPR as a more mature privacy jurisdiction have established various jurisprudence and guidelines to supplement the interpretation procedures. After the EU GDPR came into effect in 2018, there have been more than 160.000 Data Breach notifications in the jurisdiction with a daily average of 335 breach notifications received by Data Protection Authorities in the region.[77] While EU GDPR is not directly applicable in Indonesia, UU PDP itself is drafted with EU GDPR framework due to the more developed practices of the jurisdiction.[78] Thus, there are lessons learned in the normative framework and established practice under EU GDPR.
Under the GDPR, Data Breach Notifications towards the Supervisory Authority are governed under Article 33 GDPR, while delivery towards Data Subjects are governed under Article 34 GDPR. In addition to the separate article regarding Data breach Notification, the European Data Protection Board has also published Guideline 9/2022 on Personal Data Breach Notifications in order to clarify persisting issues in practice.[79]
As a start, not all data breaches[80] triggers Data Breach Notification towards Supervisory Authority or Data Subjects. Pursuant to Article 33 GDPR, only data breaches that present a risk to the rights and freedoms of natural persons must be notified to the Supervisory Authority without undue delay or no more than 72 hours.[81] In turn, Article 34 GDPR provided that requirement to notify Data Subjects only arises when the data breach presents a high-risk to the rights and freedoms of natural persons. This is also supplemented by Article 34 Paragraph (2) GDPR that established scenarios where a data breach does not need to be notified:[82]
- there has been appropriate technical and organizational protection measures applicable to the Personal Data affected by the breach, for instance rendering personal data unintelligible to any person who is not authorized to access it, such as encryption;
- there controller has taken subsequent measures to the point that high-risk to the rights and freedoms of Data Subject no longer likely to materialize;
- where disproportionate effort would be required, a public communication or similar would suffice to inform Data Subjects in an equally effective manner.
Following this, the next burning question under EU GDPR is how to determine the risk posed to individuals when a Data Breach has occurred. EDPB Guideline 9/2022 provided that the logic or assessment to determine whether or not a data breach would pose a risk, high risk, or be exempted is to be conducted by the organization experiencing data breach itself, with a note that there needs to be an internal documentation process in the case that the data breach will not be notified.[83] This also aligns with Article 34 Paragraph (4) EU GDPR as control mechanism, where Supervisory Authority can instruct the Data Controller to conduct Data Breach Notification to the Data Subject based on the provided documentation, even if the initial conclusion was not high risk.[84]
Documentation is essential for companies to conduct, not only as a way to ensure preventive measures can be taken for similar incidents but also as fulfillment of accountability principles to the Data Protection Authority. The incident documentation is often requested in hearing by the Data Protection Authority in the European Union, in pursuance of EU GDPR Article 33 Paragraph (5) “the controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and remedial action taken. That documentation enables the supervisory authority to verify compliance within this Article.”[85] The DPA considered that the accountability principle is applicable in cyber incidents through conducting proper documentation processes that can demonstrate that all necessary actions have been taken to set out technical and organizational measures throughout the incident, thus failure to conduct proper documentation would result in failure of Article 33 and 34 of GDPR.[86]
Initially, the decision to trigger a notification should be mainly decided by the Data Controller as the party who is in the best position to assess the risk while the Data Protection Authority can provide recommendations on the risk assessments.[87] However, almost six years after GDPR came into force, the threshold to determine “risk” remains open to interpretation, leading to many organizations underreporting the breach due to increasing possibility of legal action and the rise of administrative fines.[88]
There is no clear delineation on the methodology to assess risk posed to the rights and freedoms of natural persons under EU GDPR. Prior commentaries on Article 33 and Article 34 EU GDPR have heavily criticized the regulation for failing to distinguish “risk” and “high risk” situations, especially in the context to determine threshold of Data Breach Notification.[89] Burdon, Reid, and Low argued that the initial distinction between “risk” and “high risk” is to prevent a notification fatigue where Data Subjects will experience a diluted perspective if all technical or organizational failures are being notified.[90] In a similar vein, conducting too many Data Breach Notifications with irrelevant risks will deplete significant resources from Data Protection Authorities which need to respond and act accordingly to the delivered notifications. As a middle ground, EDPB Guideline 9/2022 recommends to utilize the following criteria for Data Controller in assessing the level of risk during data breach:[91]
- Type of breach;
- Nature, sensitivity, and volume of Personal Data;
- Ease of identification of individuals;
- Severity of consequences towards individuals;
- Special characteristics of affected individuals.
In 2022, Belgian Data Protection Authority (Gegevensbeschermingsautoriteit) utilized the proposed risk framework under the guideline to determine whether a breach would result in a high-risk against the rights and freedoms of a natural persons, even if the breach relates only to a single individual. Alternatively, Data Controllers can also utilize the European Union Agency for Network and Information Security that has proposed a methodology for assessing severity of Personal Data breach since 2013.[92]
Should a Data Breach Notification is considered mandatory, the next stage is ensuring the following elements must be present within the notification: i) nature of personal Data Breach, and additional information if possible such as the number of data subject concern, categories, and number of records affected; ii) name, and contact details of Data Protection Officers or other contact point; iii) description on the likely consequences of the data breach; iv) description on the measures taken or proposed to be taken in addressing the breach, including mitigation measures.[93] There is no obligation for this notification to be fully accurate as it should only reflect the real-time information, considering the strict nature of Data Breach Notification under EU GDPR. To accommodate this, an emerging practice of dual-stage notification has been commonly accepted. As the first 72 hours of cyber incidents would require organizations to focus on containing the breach and ensuring no mitigation steps are properly taken, organizations can conduct Data Breach Notification with the minimum requirements mandated by the law during the 72 hours period while conveying a more complete report beyond the timeline.[94] This is similar to the existing initial and final notification found under Circular Letter 29/SEOJK.03/2022.
In order to shed light on the triggers of Data Breach Notification and the notification procedures in practice, the following are summary of decisions made by Data Protection Authorities within the European Union.
Table 2. EU GDPR Data Breach Notifications Decisions
| No. | Data Protection Authority/Case Number | Case Summary | Results |
| 1. | Datatilsynet (Denmark) – 2020-441-4364 | A company notified data breach to Data Subject, however the notification did not reach all related Data Subjects in addition to not include information such as the: (i) likely consequence of the breach; (ii) the indication of the period of the breach. | Datatilsynet (Denmark Data Protection Authority) concluded that the company has failed to meet the minimum requirements that must be included under Data Breach Notification. The minimum information is needed to enable Data Subjects in taking mitigative measures to prevent possible harm attributed to the breach. Datatilsynet did not impose administrative fines, but ordered the company to take corrective measures.[95] |
| 2. | Tietosuojavaltuutetun toimisto (Finland) – 2437/161/22 | A public institution experienced a data breach due to Pegasus Spyware on 24 January 2022, but fails to inform it to the Data Protection Authority without undue delay or within the 72 hours time limit after the breach has been known.[96] The public institution argued that it needs to finish an investigation and gain reasonable assurance, before conducting Data Breach Notification to the supervisory authority. Thus the notification was conducted on 16 March 2022. | Tietosuojavaltuutetun toimisto (Finland Data Protection Authority) concludes that even if the Data Controller cannot provide all information of the breach within 72 hours, it still needs to conduct a notification in several stages to the supervisory authority.[97] Thus a violation of Article 33 and 34 EU GDPR has occurred. Tietosuojavaltuutetun toimisto (Finland Data Protection Authority) did not impose administrative fine.[98] |
| 3. | Gegevensbeschermingsautoriteit (Belgium) -DOS-2019-04867 05/2021 | In a technical error, a company accidentally switched Data Subject’s phone number to an unaffiliated third party for a period of four days. The accident gives the opportunity to the third party to access Data Subject’s WhatsApp application and other various Personal Data associated with the phone number. The company argued there is no obligation to conduct Data Breach Notification to supervisory authority and data subject, as the breach only concerned a single individual for a short duration, with no sensitive data involved.[99] | APB/GBA (Belgium Data Protection Authority) concluded that even if a data breach relates only to a single person, it would have still fulfill the threshold of mandatory Data Breach Notification as long as it could result in a serious consequences to the person[100] APB/GBA (Belgium Data Protection Authority) imposed an administrative fine of €25,000 to the company.[101] |
| 4 | DPC (Ireland) – DPC Case Reference: IN-19-9-5 BN-19-1-25 | A banking institution accidentally uploaded wrong customer data to the Central Credit Register, causing an unauthorized disclosure of Personal Data. The banking institution was aware of the breach on 22 January 2019 and notified the Irish Data Protection Commission with an indication of high-risk breach. However, the bank waited until technical action to remediate the breach was taken on 5 December 2019, before deciding to conduct Data Breach Notifications to 236 Data Subjects.[102] | Irish Data Protection Commission concluded that communication Data Breach Notification, especially in the case related to financial data is necessary to enable Data Subject in mitigating the consequences of the breach. The delay of notification is almost 10 months since the breach has been known, resulting in the violation of Article 34 EU GDPR.[103] The Irish Data Protection Commission did not impose administrative fines due to the small number of data subjects affected and the less severe delay in communicating the breach when compared to other cases (BN-19-4-490).[104] |
| 4. | DPC (Ireland) – DPC Case Reference: IN-19-9-5 BN-19-4-490 | A banking institution has incorrectly attributed over 47.000 Data subjects with a “Restructure Event” status that leads to reduced creditworthiness. The banking institution was aware of the breach from 26 April 2019, but only started conducting Data Breach Notification to Data Subjects at the end of November 2020.[105] | Irish Data Protection Commission concluded that the length it took to identify numbers of individuals affected; failure to communicate the Data Breach in a timely manner; and postponing communication until the establishment of the total number of individuals affected by the breach has violated Article 34 EU GDPR. Irish Data Protection determined that, even if further investigation needs to be concluded to accurately establish the number of affected individuals, the banking institutions should have notified Data Subjects earlier without waiting for a complete list of affected individuals.[106] Irish Data Protection Commission imposed an administrative fine of €125.000. |
| 5 | Commissioner (Cyprus) – 11.17.001.010.007 | A company has suffered data breach, however the company only provides public announcement of the Data Breach Notification, without addressing individual Data Breach Notification. A Data Subject that received the news from a third party, complained that it has not received a Data Breach Notification where it should have been appropriate. The company argues that there is no indication to which individuals are affected by the breach. Thus a public announcement would have been sufficient.[107] | Cyprus DPA concluded that the company should have conducted Data Breach Notification directly to the affected Data Subjects, by leveraging existing registered user emails in the company. This is strengthened by the fact that the company is processing sensitive data, such as sex life of its registered users.[108] Cyprus DPA found a violation of Article 34 GDPR, but only issued reprimands without administrative fines.[109] |
From the decisions made by various EU Data Protection Authorities above, there are three key takeaways that can be maintained. First, the Data Controller does not need to wait until all affected data subjects are identified before sending Data Breach Notifications. Second, Data Controllers need to utilize public announcement through the website carefully as it does not necessarily erase its initial obligation to notify Data Subjects individually. Third, there is no minimum requirement on duration or scale of data breach, every single breach that poses high-risk even to an individual would need to have Data Breach Notification sent out. While the practices are non-binding, this could shape as a practical guideline in Data Breach Notification in Indonesia both to the Supervisory Authority and to the Data Subjects.
When compared to Indonesia, the only notable difference between UU PDP and EU GDPR is the trigger in conducting Data Breach Notification. As the metrics established under Article 124 RPP PDP is only to consider whether there has been Personal Data disclosure without mandatory risk matrix assessment under Article 33 and Article 34 EU GDPR.[110] This approach circumvents the “risk” and “high risk” debate entirely by focusing on the actual consequences of a cyber incident. While the regulation remains as a draft, this mechanism would prove ineffective in the context of Ransomware attacks where a breach or cyber incident has been clearly announced to the public while the data disclosure (pengungkapan) will follow only if the companies failed in negotiation. As the requirement of notification only manifests after the disclosure has occurred, Data Subjects will remain helpless after the Ransomware group announced their clear intention. Thus in many future scenarios, Indonesia’s Data Breach Notification will be “too late, too ineffective” if the Article 124 RPP PDP remained as is in the final implementing regulations of UU PDP.
All in all, the rules and guidelines gathered can be a good guidance on drafting a proper data breach notification. An interesting note is that data breach notification should also be sent to the “supervisory authority”. However, in Indonesia – who exactly is the leading supervisory authority regarding data protection and privacy violations?
IV. REGULATORY COMPLEXITIES IN DATA BREACH NOTIFICATION: ONE-STOP NOTIFICATION MODEL FOR INDONESIA’S PERSONAL DATA PROTECTION AUTHORITY
Indonesia’s Personal Data Protection Authority will play a key role as an institution that will oversee compliance towards UU PDP and its implementing regulation. Under EU GDPR, Garante in Italy, Irish DPC in Ireland, and AP in the Netherlands are highly active in monitoring and providing sanctions for violations of the EU GDPR.[111] In the context of data breaches, these supervisory authorities are well-equipped with the know-how on managing notifications that have been informed from Data Controllers.[112] In an Indonesian twist, almost two years since UU PDP was legislated, the fate of Indonesia’s Personal Data Protection Authority remains unclear as only the necessary Presidential Regulation to establish this institution have yet to be enacted. As a consequence, a single Data Breach in 2023 would trigger an ad-hoc engagement from Data Controller to every single other institution that might be relevant, with every institution requiring different notification procedure and format:
Table 3. Data Breach Notification Procedures to Supervisory Authority in Indonesia
| No. | Authority | Procedure | Remarks |
| 1. | Personal Data Protection Authority | Not available as of writing | RPP PDP did not mention whether the procedure will be stipulated further under PDP Authority regulation |
| 2. | Badan Siber dan Sandi Negara | Applicable to all cyber incident 1) Report is submitted through hotline calls at 02178833610 or email to bantuan70@bssn.go.id. 2) Report must include the identity of reporter supported by the evidence of cyber incident (photo/screenshot/log file) 3) BSSN will provide confirmation of report submission 4) BSSN will conduct observation and investigation over the report 5) BSSN will provide recommendation in handling the cyber incident 6) BSSN can be involved to act upon the cyber incident if the IT administrator/asset owner cannot solve the cyber incident independently. | Guideline is available at https://www.bssn.go.id/aduan-siber/ |
| Applicable to cyber incident on Vital Information Infrastructure 1) Organization’s Cyber Incident Response Team must report to Sector Cyber Incident Report Team within 1×24 hours after the incident is found. 2) The Report must be forwarded to National Cyber Incident Team under BSSN within the same timeline. | Presidential Regulation No. 82 Year 2022 on Vital Information Infrastructure As of writing, there is no public list of Electronic System classified as Vital Information Infrastructure to determine whether this procedure applies to an organization or not. Within the Financial Sector, the Sectoral Incident Report Team is OJK-CSIRT | ||
| 3. | Ministry of Communication and Information | Ministry of Communication and Information will provide a link to “Alleged Data Breach Report Form.” However, this electronic submission form is not accessible publicly. In practice, companies experiencing data breach must manually liaise with the Ministry of Communication and Information through email. | It usually took more than 3 x 24 hours to liaise with the Ministry of Communication and Information. It remains unclear whether liaising to Ministry of Communication and Information will utilize the 14 (fourteen) days after breach is known under PP PSE/Permenkominfo or 3 (three) days after the breach is known under UU PDP |
| 4 | Financial Service Authority | Initial Cyber Incident Notification must be reported within 24 hours after the breach is known electronically to the Financial Service Authority. Cyber Incident Report must be reported within 5 working days after the breach is known to the Financial Service Authority reporting system. | No publicly available information is found on the recipient or address to OJK reporting system to deliver both Initial Cyber Incident Notification and Cyber Incident Report. |
| 5. | Indonesian National Police | No specific procedures, but every cyber crimes are advised to be reported to the Directorate of Cyber Crime. This will be followed by an investigation by the Directorate’s Computer Security Incident Response Team.[113] | Submission form is available at https:/patrolisiber.id/ |
As established under Section III, what constitutes “Failure” under UU ITE/Permenkominfo regime differs from UU PDP in addition to the sectoral regulations under Indonesian Financial Service Authority, this is also the case of diverging timeline to trigger Data Breach Notification between the regulations. A banking and financial services institution has no guidance on whether it should only notify the Financial Service Authority as its direct supervisor or also need to go through the cumbersome procedure of notifying every single authority to ensure bulletproof compliance. Notification process would have cost significant resources, while failing to notify might result in administrative sanction from the supervisory authorities.[114]As a solution, a harmonizing effort is necessary to deal with the gap between regulations.
The last minute scramble which results in a jarring procedural hassle every time a breach occurs can be avoided, if Indonesia commits itself into having a leading Personal Data Protection Authority as mandated under Article 58 UU PDP.[115] A single institution that is envisioned to wield the power in formulating strategies and policies related to Personal Data Protection that will become the central lead in guiding compliance up to imposing administrative sanctions where possible.[116] Specifically, Article 60 UU PDP authorized Indonesia’s Personal Data Protection Authority to as the following:[117]
- formulate and stipulate policies in the area of Personal Data Protection;
- supervise the compliance of Personal Data Protection;
- impose administrative sanction on Personal Data Protection violations;
- assist the law enforcement in handling allegation of Personal Data crimes;
- cooperates with other Personal Data Authority to facilitate cross-border issues;
- assess whether the requirement for cross-border data transfer has been satisfied;
- enact order as a follow-up of supervision towards Data Controller and Data Processor;
- establish publication of supervision results;
- receive complaints and/or report alleged to Personal Data Protection violations;
- conduct inspection and searchers upon complaints, reports, and/or supervision results of alleged Personal Data Protection violations;
- summon any person and/or public agency related to possible Personal Data Protection violation;
- request statement, data, information, and document from any person and/or public institution related to possible Personal Data Protection violations;
- summon any experts that are necessary in the inspection and search related to alleged Personal Data Protection violation;
- conduct an inspection and search against electronic systems, facilities, room, and/or places used by Data Controller and Data Processor, this includes obtaining access to data and appointing third party;
- request legal assistance from the Attorney General in Personal Data Protection dispute.
As it stands in February 2024, the fragmented procedure to conduct Data Breach Notification to various supervisory authorities has not only created uncertainty among Data Controllers to determine which authority needs to be notified, the diverging formats of notification to each institution, and costs a significant amount of time in manually liaising to each authority. Organizations experiencing data breach already have to juggle with limited resources to contain the incident, assess the impact of the breach, and conducting recovery or documentation of the attack.[118] Therefore, the existing patchwork procedure of Data Breach Notification will cost significant resources by the Data Controller. In response to this, we propose that Indonesia’s Personal Data Protection Authority to utilize One-Stop-Notification Model:
Chart 1. One-Stop Notification Model for Data Breach Notification
Under the One-Stop-Notification Model, the Data Controller must inform the Personal Data Protection Authority as soon as possible after knowing the existence of the breach. This process will be considered a part of initial documentation procedure maintained under Article 125 RPP,[119] and separate from the official Data Breach Notification to Supervisory Authority maintained under Article 46 UU PDP.[120]
The involvement of the Personal Data Protection Authority at the early stage of the incident would provide three concrete benefits. First, it would provide better room for assessing the actual impact of the breach, for instance Data Controller may initially determine that the breach does not result in the compromise of Personal Data,[121] while the Personal Data Protection Authority may determine otherwise. This will eventually reduce the high possibility of the Data Controller underreporting the impact of the breach. Second, liaising with Personal Data Protection Authority would take into account our initial concern under Section III where Data Controller may abuse the unspecified deadline of conducting documentation process, if Article 125 RPP PDP timeline remains open to interpretation – the Personal Data Protection Authority can provide recommendations to the Data Controller regarding the time needed to conclude documentation process on a case-by-case basis. On the context of Ransomware attacks, Data Controller who are being extorted by malicious actors can communicate effectively with the Personal Data Protection Authority, the latter could provide advice or recommendation in dealing with the Ransomware groups to prevent ransom payment. Thus, breaking the vicious cycle of Ransomware extortion tactics.
Lastly, the existing issue of patchwork notification procedures to other supervisory authorities can be circumvented if the One-Stop-Notification-Model could connect the notification submitted to the Personal Data Protection Authority to the relevant supervisory authority. For instance, a Major Bank needs to inform the Personal Data Protection Authority, Ministry of Communication and Information, and the Financial Service Authority but does not have access to any link or network to the notification procedures of the other institution as highlighted in Table 3. After submitting through One-Stop-Notification form, Indonesia Personal Data Protection Authority can determine if another supervisory authority needs to be notified and connect the submission form of another supervisory authority within the One-Stop-Notification Form.
The proposed One-Stop-Notification Model build from smart thresholds approach proposed by Nieuwesteeg and Faure which put a stronger emphasis on Data Protection Authority role to become the major player in assisting data controllers to determine whether Data Subjects need to be notified, owing to the fact that DPA will have more expertise in determining whether an action is needed, understood the impact of the breach, and are able to prevent data subject’s notification fatigue as the DPA would know how any notifications have been send previously to data subjects.[122] Further, the model is partially inspired by Dutch-DPA electronic Data Breach Notification form that assists Data Controller in submitting initial notification, while also requiring the declaration of whether other supervisory authority has been notified.[123] We take the Dutch-DPA model one step further by connecting Data Breach Notification towards supervisory authority to ensure no notification is missing.
V. Concluding Remarks
Bank and other financial service providers, is a business of trust as customers entrust their accounts to its intermediary. As a highly regulated sector, a practice of good corporate governance is imperative in banking to reduce the credit risk, market risk, operational risk, and reputational risk. However, when a new technology is introduced; be it in the form of digital banking, payment system, or even operational platforms, will introduce cyber risk which affects all the previously mentioned risk. Malicious cyber actors such as Ransomware organizations pose a threat to the new opportunities, highlighted as one of the most lucrative cyberattacks throughout the years. Banking and financial institutions remain the most targeted organizations due to the sheer amount of sensitive financial data and strategic assets it processed, Ransomware attacks also have the capability to shut down strategic infrastructure, thus forcing organizations to either pay ransom or risk further exploits.
UU ITE, alongside relevant regulations such as PP 81/2019 and Permenkominfo 20/2016 have acted as the initial framework for organizations compliance towards cybersecurity and privacy. Further, the enactment of UU PDP has explored more details on the framework of personal data protection which also enhances additional cybersecurity and data protection requirements that companies must adhere to, such as enabling access management or appropriate encryption throughout Personal Data collection, use, storage, transfer, and erasure. These new requirements, which are also further detailed on the latest version of RPP PDP, can serve as a starting point to ensure a proper cybersecurity and personal data protection framework of organizations. Banking and other financial service providers must also take into account waves of new regulations both from Bank Indonesia and Financial Service Authority that often mandates a stricter requirement, reflecting the importance of safeguarding trust and consumer data in the area.
This paper has analyzed the complexities between the new regulations, which will result in a procedural challenge regarding Data Breach Notification. Every single regulation provides a different trigger, timeline, and procedure in order to conduct an appropriate notification to Data Subjects and Supervisory Authority. The existing practice also provides no clear framework, as it stands now, a data breach notification process is cumbersome as an organization must manually contact the relevant Supervisory independently and separately.
In the spirit of welcoming Indonesia’s Personal Data Protection Authority, this paper proposes a model that sets a central role of this authority in managing Data Breach Notifications through One-Stop-Form mechanism. In our model, the Data Controller would cooperate closely with the authority in determining whether a data breach is notifiable and to whom notification should also be forwarded to. This model establishes a strong connection with Personal Data Protection Authorities while also preventing Data Controllers from potentially abusing flexible timeline within UU PDP implementing regulation. Ergo, coordination on cyber incidents, can then be conducted with other relevant authorities such as Financial Service Authority and Indonesia Cyber and Crypto Agency to ensure necessary cooperation is reached to mitigate the damage and protects data subject from receiving any further harm such as phishing, data interception, and other cybersecurity threats through exploitation of leaked data.
[1] Dara Hallinan and Frederik Zuiderveen Borgesius, “Opinions Can Be Incorrect (in our opinion!) On Data Protection Law’s Accuracy Principle,” International Data Privacy Law, Vol. 10, No. 1 (2020): 2.
[2] R. O Brien, “Privacy and security: The new European data protection regulation and it’s data breach notification requirements,” Business Information Review, Vol, 30 (2016): 81.
[3] Graham Greenleaf, “Global Data Privacy Laws 2021: Despite COVID Delays, 145 Laws Show GDPR Dominance,” 169 Privacy Laws and Business International Report, 1, (2021): 3-5.
[4] Indonesia, Personal Data Protection Law,” Law No. 27 of 2022, LN.2022/No.196, TLN No.6820, Article 16 Section (2).
[5] Indonesia, “Personal Data Protection Law,” Article 16 Paragraph (2) Point f.
[6] Indonesia, “Personal Data Protection Law,” Article 16 Paragraph (2) Point a and b.
[7] Indonesia, “Draft Regulation on Government Regulation on the Implementation of Personal Data Protection Law, Article 30 Point d, e, and f.
[8] Bank Indonesia, “Amendment of Regulation of the Members of the Board of Governors,” Regulation Number 20 of 2023 concerning the Implementation Procedure of Consumer Protection of Bank Indonesia, Article 3 Paragraph 1 Point f.
[9] Bank Indonesia, “Amendment of Regulation of the Members of the Board of Governors,” Regulation Number 20 of 2023 concerning the Implementation Procedure of Consumer Protection of Bank Indonesia, Elucidation of Article 3 Paragraph 1 Point f.
[10] Indonesia, “Presidential Regulation on Protection of Vital Information Infrastructure,” Regulation No. 82 of 2022, LN.2022/No.129, Article 13.
[11] Abdulbasit Darem, et.al., “Cyber threats classifications and countermeasures in banking and financial sector,” IEEE Access, Vol 11 (2023): 125139.
[12] Edmon Makarim, “The Law Against Personal Data Leaks,” Public Relation of Faculty of Law Universitas Indonesia, July 10, 2020, https://law.ui.ac.id/pertanggungjawaban-hukum-terhadap-kebocoran-data-pribadi-oleh-edmon-makarim/.
[13] Maichle Delpiero, et.al., “Analisis Yuridis Kebijakan Privasi dan Pertanggungjawaban Online Marketplace dalam Pelindungan Data Pribadi Pengguna Pada Kasus Kebocoran Data.” Padjadjaran Law Review, Vol. 9, No. 1 (2021): 13-16.
[14] Gunardi Lie, Dylan Aldianza Ramadhan, and Ahmad Redi, “Independent Commission of Personal Data Protection: Quasi-Judicial and Efforts to Create Right to be Forgotten in Indonesia,” Jurnal Yudisial, Vol. 15, No. 2 (August 2022): 241-243.
[15] Eleni Kosta, “Thematic Document: Security of Processing and Data Breach Notification,” European Data Protection Board (November 2023): 8.
[16] “NCCA Hearing Meeting with Commission I The House of Representatives of the Republic of Indonesia,” National Cyber and Crypto Agency, accessed February 8th, 2024, https://www.bssn.go.id/rapat-dengar-pendapat-bssn-bersama-komisi-i-dpr/.
[17] “PRESS RELEASE BSI President Director: We Apologize and Are Trying to Restore Services,” Bank Syariah Indonesia, accessed February 8th, 2024, https://ir.bankbsi.co.id/newsroom/dc70693fac_d7743dac9a.pdf.
[18] “LockBit hackers pocket 15 million BSI customer records, threaten to sell them if negotiations fail,” Merdeka.com, accessed February 8th, 2024, https://www.merdeka.com/teknologi/hacker-lockbit-kantongi-15-juta-data-nasabah-bsi-ancam-dijual-jika-negosiasi-gagal.html.
[19] “PRESS RELEASE BSI Branch, ATM & Mobile Banking Services Have Returned to Normal,” Bank Syariah Indonesia, accessed February 8th, 2024, https://ir.bankbsi.co.id/newsroom/1a92cc8ca2_4364ce956d.pdf.
[20] Erwin Pratama, “Negotiation period ends, LockBit reveals BSI data on the Dark Web,” Tempo.co, accessed February 8th, 2024, https://tekno.tempo.co/read/1726219/masa-negosiasi-berakhir-lockbit-ungkap-data-bsi-di-dark-web.
[21] Stuard E. Madnick, “The Continued Threat to Personal Data: Key Factors Behind the 2023 Increase,” Apple, December 2023, 11, https://www.apple.com/newsroom/pdfs/The-Continued-Threat-to-Personal-Data-Key-Factors-Behind-the-2023-Increase.pdf.
[22] “The Prolificacy of LockBit Ransomware,” The Hacker News, accessed February 8th, 2024, https://thehackernews.com/2023/03/the-prolificacy-of-lockbit-ransomware.html.
Ransomware on cyber-physical systems: Taxonomies, case studies, security gaps, and open challenges; Mourad Benmalek Computer Engineering Department, College of Engineering and Architecture, Al Yamamah University, Riyadh, Saudi Arabia, Journal Internet of Things and Cyber-Physical Systems 4 (2024), 193
[23] Agustinus Rangga Respati, Aprillia Ika, “NCCA Mentions the Potential for Cyber Attacks is Still High, Especially the “Ransomware Type” Kompas.com, accessed Febraury 8th, 2024, https://money.kompas.com/read/2023/11/15/114406526/bssn-sebut-potensi-serangan-siber-masih-tinggi-terutama-jenis-ransomware.
[24] “Dark Web Profile: LockBit 3.0 Ransomware,” SOCRadar, accessed February 8th, 2024, https://socradar.io/dark-web-profile-lockbit-3-0-ransomware/#:~:text=LockBit%203.0%20is%20a%20Ransomware,businesses%20and%20critical%20infrastructure%20organizations.
[25] Mourad Benmalek, “Ransomware on cyber-physical systems: Taxonomies, case studies, security gaps, and open challenges,” Journal Internet of Things and Cyber-Physical Systems 4 (January 2024): 186.
[26] “83% of organizations paid up in ransomware attacks,” VentureBeat, accessed February 8th, 2024, https://venturebeat.com/security/83-of-organizations-paid-up-in-ransomware-attacks/.
[27] Anne Gotay, How Ransomware Shakes Up GDPR Compliance, Sotero, accessed February 8th, 2024, https://www.soterosoft.com/blog/how-ransomware-shakes-up-gdpr-compliance/.
[28] Marianne Kolbasuk McGee, “Irish Authorities Levy GDPR Fine in Centric Health Breach,” Bank Info Security, accessed February 8th, 2024, https://www.bankinfosecurity.com/irish-authorities-levy-gdpr-fine-in-centric-health-breach-a-21346.
[29] Ibrahim Nadir and Taimur Bakshi, “Contemporary Cybercrime: A Taxonomy of Ransomware Threats & Mitigation Techniques,” International Conference on Computing, Mathematics and Engineering Technologies (2018): 5.
[30] Tom Meurs, et al., “Deception in Double Extortion Ransomware Attacks: An Analysis on Profitability and Credibility,” Computers & Security Vol. 138, (March 2024): 3.
[31] Pierce Ryan, et. al., “Dynamics of Targeted Ransomware Negotiation,” IEEE Access, Vol. 10 (March 2022): 32839.
[32] Pierce, “Dynamics,” 32839.
[33] “Expert Calls Conti Ransomware Gang that Breached BI Dangerous Hackers,” CNN Indonesia, accessed February 8th, 2024, https://www.cnnindonesia.com/teknologi/20220120191930-185-749298/ahli-sebut-geng-ransomware-conti-yang-bobol-bi-peretas-berbahaya.
[34] Yunia Rusmalina, “Not Ransomware, BFI Finance Admits to Malware Attack,” Bloomberg Technoz, accessed February 8th, 2024, https://www.bloombergtechnoz.com/detail-news/7300/bukan-ransomware-bfi-finance-akui-terkena-serangan-malware.
[35] Indonesia,“Electronic Information and Transactions Law,” Law No. 11 of 2008, LN.2016/No.251, TLN No. 5952, Article 16.
[36] Mochammad Tanzil Multazam and Noor Fatimah Mediawati, “Personal Data Collection: Recent Developments in Indonesia,” 2nd Virtual Conference on Social Science In Law, Political Issue and Economic Development (August 2022): 52.
[37] Indonesia, “Personal Data Protection Law,” Law No. 27 of 2022, Article 16 Paragraph (2) Point e.
[38] Indonesia, Draft Regulation on Government Regulation on the Implementation of Personal Data Protection Law, Article 29.
[39] “Press Release No. 256/HM/KOMINFO/08/2023 Drafting Implementing Rules, Kominfo Opens Public Participation Through the pdp.id,” Public Relations Bureau of the Ministry of Communication and Information, accessed February 8th, 2024, https://www.kominfo.go.id/content/detail/51157/siaran-pers-no-256hmkominfo082023-tentang-susun-aturan-pelaksana-kominfo-buka-partisipasi-publik-lewat-laman-pdpid/0/siaran_pers.
[40] Indonesia, “Personal Data Protection Law,” Law No. 27 of 2022, Article 35.
[41] Indonesia, Draft Regulation on Government Regulation on the Implementation of Personal Data Protection Law, Article 131 Paragraph (2).
[42] Sinta Dewi Rosadi, Pembahasan UU Pelindungan Data Pribadi, (Jakarta: Sinar Grafika, 2023), 102.
[43] European Union, “General Data Protection Regulation,” Regulation 2016/679, Article 32.
[44] European Union, “General Data Protection Regulation,” Regulation 2016/679, Article 32 Point A-D.
[45] Cedric Burton, “Article 32: Security of Processing” in Christopher Kuner The EU General Data Protection Regulation: A Commentary (Oxford: Oxford University Press, 2020), 635-636.
[46] “Advocate General Opinion in Case C-340/21, Press Release No. 67/23,” Court of Justice of the European Union, accessed 8th February 2024, https://curia.europa.eu/jcms/upload/docs/application/pdf/2023-04/cp230067en.pdf.
[48] Under PDP Law Article 46 (1) Explanation: “Data Protection Failure” refers to the failure of protection the confidentiality, integrity, and availability of personal data, including security violations that is intended or not intended which includes to the destruction, loss, alteration, disclosure, or unauthorized access to personal data transmitted, stored, or processed.
[49] Indonesia, “Personal Data Protection Law,” Law No. 27 of 2022, Article 46 Paragraph (1) Point b.
[50] Indonesia, “Personal Data Protection Law,” Law No. 27 of 2022, Article 46 Paragraph (1) Point a.
[51] Pursuant to Government Regulation No. 71/2019 on Private Electronic System Operators Article 24 Explanation, “Failure” refers to the cessation partly or wholly of Electronic System function which are essential so that the electronic system does not function properly.
[52] Indonesia, “Electronic System and Transaction Operation Regulation,” Government Regulation No. 71 of 2019, Article 24 Paragraph 3.
[53] Indonesia, “Electronic System and Transaction Operation Regulation,” Government Regulation No. 71 of 2019, Elucidation of Article 24.
[54] There is no distinction between notification send to supervisory authority and data subjects under this regulation.
[55] Indonesia, “Protection of Personal Data in Electronic Systems Law,” Regulation of the Minister of Communication and Information Technology No. 20 of 2016, Article 2, Paragraph 2, Point f.
[56] Indonesia, “Protection of Personal Data in Electronic Systems Law,” Regulation of the Minister of Communication and Information Technology No. 20 of 2016, Article 28, Point i.
[57] Indonesia, “Personal Data Protection Law,” Article 46.
[58] Indonesia, “Personal Data Protection Law,” Article 46, “Draft Regulation on Government Regulation on the Implementation of Personal Data Protection Law,” Article 124 Paragraph (5).
[59] Indonesia, “Personal Data Protection Law,” Elucidation of Article 46.
[60] Indonesia, Draft Regulation on Government Regulation on the Implementation of Personal Data Protection Law,” Article 124 Paragraph (4).
[61] Indonesia, “Personal Data Protection Law,” Article 46 Paragraph (1).
[62] Indonesia, Draft Regulation on Government Regulation on the Implementation of Personal Data Protection Law,” Article 124 Paragraph (2) and Elucidation.
[63] Indonesia, Draft Regulation on Government Regulation on the Implementation of Personal Data Protection Law,” Article 125 Paragraph (1) and (2).
[64] Indonesia, Draft Regulation on Government Regulation on the Implementation of Personal Data Protection Law,” Article 125 Paragraph (2).
[65] Irish Personal Data Protection Commission, Decision on IN-19-9-5, 59.
[66] Indonesia, Draft Regulation on Government Regulation on the Implementation of Personal Data Protection Law,” Article 133 Paragraph (1) and (2).
[67] Indonesia, “Personal Data Protection Law,” Article 37.
[68] Indonesia, Draft Regulation on Government Regulation on the Implementation of Personal Data Protection Law,” Article 162.
[69] Indonesia, Draft Regulation on Government Regulation on the Implementation of Personal Data Protection Law,” Article 21.
[70] “Guidelines 9/2022 on personal Data Breach Notification under GDPR,” European Data Protection Board, accessed February 8th, 2024, https://edpb.europa.eu/system/files/2023-04/edpb_guidelines_202209_personal_data_breach_notification_v2.0_en.pdf.
[71] Financial Services Authority, Circular Letter 29/SEOJK.03/2022 on Cyber Security and Resilience, 16-17.
[72] Financial, Circular Letter 29/SEOJK.03/2022, 17.
[73] Financial, Circular Letter 29/SEOJK.03/2022, 17.
[74] Financial, Circular Letter 29/SEOJK.03/2022, 85-87.
[75] Financial, Circular Letter 29/SEOJK.03/2022, 85.
[76] Pursuant to Circular Letter 29/SEOJK.03/2022 on Cyber Security and Resilience, if other authority regulates the timeline of Initial Cyber Incident Notification or Cyber Incident Report with a longer timeline, the timeline within Circular Letter must be adhered to.
[77] DLA Piper Report, “DLA Piper GDPR Fines and Data Breach Survey: January 2024,” accessed February 8th, 2024, https://www.dlapiper.com/en/insights/publications/2024/01/dla-piper-gdpr-fines-and-data-breach-survey-january-2024.
[78] Pratiwi Agustini, “PDP Law will facilitate data exchange with other countries,” Directorate General of Informatics Applications, accessed February 8th, 2024,
https://aptika.kominfo.go.id/2020/11/uu-pdp-akan-permudah-pertukaran-data-dengan-negara-lain/.
[79] Lou Mailhac, “The EDPB updates the WP29 guidance on personal data breach notification,” Lexology, accessed February 8th, 2024, https://www.lexology.com/library/detail.aspx?g=c95a7003-2cd1-4694-a78c-12374adc7254.
[80] Pursuant to GDPR, Article 4 Paragraph 12 defined as breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.
[81] European Union, “General Data Protection Regulation,” Regulation 2016/679, Article 33.
[82] European Union, “General Data Protection Regulation,” Regulation 2016/679, Article 34 Paragraph (2).
[83] “Guidelines 9/2022 on personal Data Breach Notification under GDPR,” Paragraph 125-126, European Data Protection Board, accessed February 8th, 2024, https://edpb.europa.eu/system/files/2023-04/edpb_guidelines_202209_personal_data_breach_notification_v2.0_en.pdf.
[84] European Union, “General Data Protection Regulation,” Regulation 2016/679, Article 34 Paragraph (4).
[85] European Union, “General Data Protection Regulation,” Regulation 2016/679, Article 33 Paragraph (5).
[86] “APD/GBA (Belgium) – 05/2021,” Paragraph 46, GDPRhub, accessed February 8th, 2024, https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_05/2021.
[87] “Data breach notifications in the EU,” European Network and Information Security Agency, 18, accessed February 8th, 2024, https://www.enisa.europa.eu/publications/dbn/@@download/fullReport.
[88] DLA, “DLA Piper GDPR,” 6.
[89] https://www.duo.uio.no/bitstream/handle/10852/84194/1/ICTLTHESIS—Candidate-8012.pdf, 27.
[90] Bernold Nieuwesteeg and Michael Faure, “An Analysis of the Effectiveness of the EU Data Breach Notification Obligation,” Computer & Law Security Review No. 34 (2018): 1237.
[91] “Guidelines 9/2022,” Paragraph 103-119.
[92] “APD/GBA (Belgium) – 05/2021,” Paragraph 41.
[93] European Union, “General Data Protection Regulation,” Regulation 2016/679, Article 33 Paragraph (3) and Article 34 Paragraph (2).
[94] Ralph O’ Brien, “Privacy and security: The new European data protection regulationand it’s data breach notification requirements,” Business Information Review, 33(2), (2016): 83.
[95] “Case No. 2020-441-4364”, Datalysisnet (Danish Data Protection Authority), accessed February 8th, 2024, https://www.datatilsynet.dk/afgoerelser/afgoerelser/2020/nov/sikkerhedsbrud-hos-zoo.
[96] Tietosuojavaltuutetun toimisto (Finland Data Protection Authority), Decision of the Deputy Data Protection Commissioner Case ID Number 2437/161/22, 1.
[97] Tietosuojavaltuutetun, Case ID Number 2437/161/22, 4.
[98] Tietosuojavaltuutetun, Case ID Number 2437/161/22, 7.
[99] Gegevensbeschermingsautoriteit, Case Number -DOS-2019-04867, Paragraph 40, 15.
[100] Gegevensbeschermingsautoriteit (Belgium Data Protection Authority), Case Number -DOS-2019-04867, Paragraph 41, 15.
[101] Gegevensbeschermingsautoriteit, Case Number -DOS-2019-04867, 22.
[102] Irish Personal Data Protection Commission, Decision on IN-19-9-5, 27-28.
[103] Irish, Decision on IN-19-9-5, 29.
[104] Irish, Decision on IN-19-9-5, 29.
[105] Irish, Decision on IN-19-9-5, 59.
[106] Irish, Decision on IN-19-9-5, 32.
[107] “Stripchat reprimanded for 64.694.953 account breach,” Floort.net, accessed February 8th, 2024, https://floort.net/posts/stripchat_data_breach/.
[108] Office of the Commissioner for Personal Data Protection Republic of Cyprus, Decision Requesting Excessive Identification Information to Comply to a Subject Access Request by Technius Ltd, Case Ref 11.17.001.010.007, 6, https://drive.google.com/file/d/1nL7rkTZ8BT3srqKXYX2rk18Ib8I8xDXb/view?usp=sharing
[109] Cyprus, Decision Requesting, 6.
[110] Indonesia, Draft Regulation on Government Regulation on the Implementation of Personal Data Protection Law,” Article 124.
[111] Brian Daigle and Mahnaz Khan, “The EU General Data Protection Regulation: An Analysis of Enforcement Trends by EU Data Protection Authorities,” Journal of International Commerce & Economics 2020: 9-13.
[112] “Breach Notification,” Data Protection Commission, accessed February 8th, 2024, https://www.dataprotection.ie/en/organisations/know-your-obligations/breach-notification.
[113] “Police Investigate Alleged Hacking of 204 Million Permanent Voter List Data at the General Election Commission,” Metrotvnews.com, accessed February 9th, 2024, https://www.metrotvnews.com/play/bJECaroO-polri-usut-dugaan-peretasan-204-juta-data-dpt-di-kpu.
[114] Indonesia, “Personal Data Protection Law,” Article 57.
[115] Article 58 UU PDP
[116] Article 59 UU PDP
[117] Article 60 UU PDP
[118]Nivedita Shinde and Priti Kulkarni, “Cyber Incident Response and Planning: A Flexible Approach,” Computer Fraud & Security (2021) No.1: 16.
[119] Indonesia, “Draft Regulation on Government Regulation on the Implementation of Personal Data Protection Law , Article 125.
[120] Indonesia, “Personal Data Protection Law,” Article 46.
[121] DLA, “DLA Piper GDPR Fines and Data Breach,” 6.
[122] Bernold, “An Analysis,” 1244-1245.
[123]“Meldformulier datalekken,” Autoriteit Persoonsgegevens, accessed February 8th, 2024, https://datalekken.autoriteitpersoonsgegevens.nl/.
Muhammad Deckri Algamar
Universitas Indonesia
Prof. Abu Bakar Munir
University of Malaya, Malaysia
Hendro
Deloitte, Indonesi
Tulisan ini telah terbit di Journal of Central Banking Law and Institutions, 3(3), 547–584. https://doi.org/10.21098/jcli.v3i3.271
