INDONESIA
Since June 2009, last amended in August 2020
Since July 2014, last amended in May 2020
Since July 2014, last amended in May 2020
Pillar Quantitative trade restrictions for ICT goods and online services |
Sub-pillar Other import restrictions, including non-transparent/discriminatory import procedures
Ministry of Trade Regulation No. 56/2009
Ministry of Trade Regulation No. 28/2020
Ministry of Trade Regulation No. 36/M-DAG/PER/7/2014
Ministry of Trade Regulation No. 51/2020
Ministry of Trade Regulation No. 28/2020
Ministry of Trade Regulation No. 36/M-DAG/PER/7/2014
Ministry of Trade Regulation No. 51/2020
It is reported that in 2009, the Indonesian government implemented non-automatic import licensing procedures on a broad range of products, including electronics through the issuance of Ministry of Trade (MOT) Regulation No. 56/2009. It was extended by the MOT in 2010 and again in December 2012 through Regulation 83/M-DAG/PER/12/2012. The amended Decree retains a requirement for pre-shipment verification by designated companies at the importers’ expense and a restriction that limits the entry of imports to designated ports and airports. Indonesia has informally limited the application of the MOT Regulation to “final consumer goods”.
Regulation 83/M-DAG/PER/12/2012 has been replaced several times, the last one being MOT No. 28/2020. This new regulation, which added a list of products exempted from the non-automatic import licensing procedures, still implements non-automatic import licensing procedures to electronics products such as mobile phones as set out in the previous regulation. Furthermore, the MOT issued MOT Regulation No. 36/M-DAG/PER/7/2014 as amended by MOT Regulation No. 51/2020 regarding ports of entry and mandatory provisions at loading ports. The regulation includes the verification at the loading port of a Notification Letter or Distribution Permit Agreement Letter for certain products that are regulated.
Regulation 83/M-DAG/PER/12/2012 has been replaced several times, the last one being MOT No. 28/2020. This new regulation, which added a list of products exempted from the non-automatic import licensing procedures, still implements non-automatic import licensing procedures to electronics products such as mobile phones as set out in the previous regulation. Furthermore, the MOT issued MOT Regulation No. 36/M-DAG/PER/7/2014 as amended by MOT Regulation No. 51/2020 regarding ports of entry and mandatory provisions at loading ports. The regulation includes the verification at the loading port of a Notification Letter or Distribution Permit Agreement Letter for certain products that are regulated.
Coverage Several products, including electronics such as e.g. mobile phones
Sources
- https://ustr.gov/sites/default/files/2014%20NTE%20Report%20on%20FTB.pdf
- https://peraturan.bpk.go.id/Home/Details/143171/permendag-no-28-tahun-2020
- https://peraturan.bcperak.net/peraturan-menteri-perdagangan-nomor-nomor-83m-dagper122012
- https://peraturan.bcperak.net/sites/default/files/peraturan/2014/36m-dagper72014.pdf
- https://peraturan.bpk.go.id/Home/Details/160276/permendag-no-51-tahun-2020
- Show more...
INDONESIA
Since January 2013
Since November 2016
Since November 2016
Pillar Quantitative trade restrictions for ICT goods and online services |
Sub-pillar Other import restrictions, including non-transparent/discriminatory import procedures
Ministry of Trade Regulation No. 38/2013
Ministry of Industry Regulation No. 68/2016
Ministry of Industry Regulation No. 68/2016
The Ministry of Trade Regulation 38/2013 imposes requirements on importers of mobile phones, handheld computers, and tablets to prove previous import activities and local aftersales activity as well as requirements regarding the distribution and the establishment of industrial activity in Indonesia. In addition, the Ministry of Industry Regulation 68/M-IND/PER/9/2016 includes new licensing requirements for different types of importers of tablets, cellular phones, and handheld computers. These differ depending on:
- whether the importer is working with an Indonesian producer,
- whether the importer is also the producer of the goods,
- whether the imports are conducted with a specific purpose (i.e., specialized orders) or concerning after-sales services.
- whether the importer is working with an Indonesian producer,
- whether the importer is also the producer of the goods,
- whether the imports are conducted with a specific purpose (i.e., specialized orders) or concerning after-sales services.
Coverage Mobile phones, handheld computers and tablets
Sources
- http://trade.ec.europa.eu/doclib/docs/2014/november/tradoc_152872.pdf
- http://www.scisi.co.id/scisi/repository/upload/mod_commodity_files/1570019225PERMENDAG%2038%20M-DAG%20PER%208%202013-HP.pdf
- http://jdih.kemenperin.go.id/site/baca_peraturan/2248
- https://docs.wto.org/dol2fe/Pages/SS/directdoc.aspx?filename=q:/G/LIC/M40.pdf&Open=True
- Show more...
INDONESIA
Since March 2014, last amended in November 2020
Since August 2007, last amended in December 2022
Since August 2007, last amended in December 2022
Pillar Quantitative trade restrictions for ICT goods and online services |
Sub-pillar Other import restrictions, including non-transparent/discriminatory import procedures
Law of the Republic of Indonesia No. 7/2014 About Trade
The Law of the Republic of Indonesia No. 40 of 2007 Concerning Limited Liability Company
The Law of the Republic of Indonesia No. 40 of 2007 Concerning Limited Liability Company
Pursuant to Art. 24 of the Trade Act and Art. 5 of the Limited Liability Company Act, all exporters and importers are subject to a licence issued by the government, which is subject to a commercial presence requirement.
Coverage Horizontal
Sources
- https://sim.oecd.org/Simulator.ashx?lang=En&ds=DGSTRI&d1c=apf&d2c=idn
- https://peraturan.bpk.go.id/Download/27842/UU%20Nomor%2007%20Tahun%202014.pdf
- http://faolex.fao.org/docs/pdf/ins49202.pdf
- https://peraturan.bpk.go.id/Download/29563/UU%20Nomor%2040%20Tahun%202007.pdf
- http://www.flevin.com/id/lgso/translations/Laws/Law%20No.%2040%20of%202007%20on%20Limited%20Liability%20Companies%20%28BKPM%29.pdf
- Show more...
INDONESIA
Since October 2019
Since November 2020
Since November 2020
Pillar Content access |
Sub-pillar Licensing schemes for digital services and applications
Government Regulation No. 71/2019 regarding the Provision of Electronic System and Transaction
Indonesia Minister of Communication and Informatics Regulation No. 5/2020
Indonesia Minister of Communication and Informatics Regulation No. 5/2020
According to the Minister of Communication and Informatics Regulation No. 5 of 2020 on Private Electronic System Operators, foreign Private Electronic System Operators (ESOs) are required to register their businesses with the relevant ministry through the online single submission system. ESOs should also appoint liaison officers, who have to be domiciled in Indonesia. The duty of the liaison officer is to facilitate any access request by government authorities and takedown requests. According to the regulation, ESOs are persons, business entities, or communities that operate an electronic system. ESOs include electronic system operators that are supervised by ministers or institutions in accordance with laws and regulations, and electronic system operators that have an online portal, site, or application through the internet. The requirement was first enacted with Government Regulation No. 71/2019 regarding the Provision of Electronic Systems and Transaction which repealed the Government Regulation No. 82 of 2012.
Coverage Electronic system operators
Sources
- https://jdih.kominfo.go.id/produk_hukum/view/id/759/t/peraturan+menteri+komunikasi+dan+informatika+nomor+5+tahun+2020
- https://www.bakermckenzie.com/en/insight/publications/2019/10/new-regulation-electronic-system-and-transactions
- https://peraturan.bpk.go.id/Home/Details/122030/pp-no-71-tahun-2019
- https://www.lexology.com/library/detail.aspx?g=cd6e5251-6dd7-4b46-b6be-759c78c9bf7b
- https://www.globalcompliancenews.com/2022/07/05/indonesia-deadline-for-registration-of-electronic-system-operators-is-now-set-for-20-july-2022-01072022/
- Show more...
INDONESIA
Since November 2020
Pillar Intermediary liability |
Sub-pillar Monitoring requirement
Regulation of the Minister of Communication and Information Technology Number 5 of 2020 concerning Electronic System Operators for Private Scope (MR5)
According to regulation MR5 of 2020, Private Electronic System Operators (ESOs), except cloud providers, are required to ensure that their service, websites, or platforms do not contain and do not facilitate the dissemination of prohibited information or documents. Private ESOs are then required to ensure that their system does not carry prohibited content or information, which will in practice require a general monitoring obligation and the adoption of content filters.
Coverage Internet Intermediaries
Sources
- https://www.eff.org/deeplinks/2021/02/indonesias-proposed-online-intermediary-regulation-may-be-most-repressive-yet
- https://www.accessnow.org/indonesia-intermediary-liabilities/
- https://jdih.kominfo.go.id/produk_hukum/view/id/759/t/peraturan+menteri+komunikasi+dan+informatika+nomor+5+tahun+2020
- Show more...
INDONESIA
Reported in 2014, last reported in 2021
Pillar Content access |
Sub-pillar Blocking or filtering of commercial web content
Blocking the online content
It is reported that in 2014, Indonesia blocked video-sharing websites: Reddit and Imgur. In addition, in 2015, Indonesia blocked the video-sharing website Vimeo. In March 2020, the online subtitling service Subscene.com was reportedly blocked. Political content has also been subject to blocking. Academic and civil society researchers have found that numerous blogs and other sites carrying criticism of the government or Islam are blocked. Online news outlets and websites with information about the provinces of Papua and West Papua, where military forces have been accused of violently suppressing an independence movement, have been blocked in recent years.
In addition, in January 2018, the Ministry of Communication and Information Technology (MCIT) launched “Cyber Drone 9,” a crawler system driven by AI tools that are designed to proactively detect content violations. It is reported that this tool replaced the Trust+ system, which relied on a passive database. A specialized task force monitors the new system and reviews the material it flags for filtering and blocking; the blocking itself is still carried out by ISPs. Each ISP may employ its software for blocking and thus may blacklist additional sites at its discretion. This has increased the likelihood of arbitrary, inconsistent blocking, creating uncertainty for users seeking redress when content is wrongfully blocked. In July 2020, the MCIT stated that it planned to purchase more sophisticated technology to block more categories of negative content and websites.
In addition, in January 2018, the Ministry of Communication and Information Technology (MCIT) launched “Cyber Drone 9,” a crawler system driven by AI tools that are designed to proactively detect content violations. It is reported that this tool replaced the Trust+ system, which relied on a passive database. A specialized task force monitors the new system and reviews the material it flags for filtering and blocking; the blocking itself is still carried out by ISPs. Each ISP may employ its software for blocking and thus may blacklist additional sites at its discretion. This has increased the likelihood of arbitrary, inconsistent blocking, creating uncertainty for users seeking redress when content is wrongfully blocked. In July 2020, the MCIT stated that it planned to purchase more sophisticated technology to block more categories of negative content and websites.
Coverage Websites
Sources
- https://www.lowyinstitute.org/the-interpreter/indonesia-bans-vimeo
- http://suarapapua.com/2017/04/18/blokir-lima-situs-di-papua-indonesia-dinilai-bungkam-ekspresi-maya-rakyat-papua/
- https://www.techinasia.com/online-porn-crackdown-vimeo-reddit-imgur-blocked-indonesia
- https://freedomhouse.org/country/indonesia/freedom-net/2020
- https://thenetmonitor.org/research/2017-global-internet-censorship/idn
- https://trustpositif.kominfo.go.id
- https://www.antaranews.com/berita/1608038/kominfo-berencana-pasang-mesin-untuk-blokir-situs-judi
- Show more...
INDONESIA
Reported in 2016
Pillar Intermediary liability |
Sub-pillar Monitoring requirement
Ministry of Communication and Informatics Circular Letter No. 3/2016
The Ministry of Communication and Informatics Circular Letter No. 3/2016 requires the providers of Over the Top (OTT) services to use local IP numbers. It is reported that the requirement could present compliance problems for foreign service providers and raise competition concerns and trade barriers.
Coverage OTT services
Sources
- https://jdih.kominfo.go.id/produk_hukum/view/id/517/t/surat+edaran+menteri+komunikasi+dan+informatika+nomor+3+tahun+2016+tanggal+31+maret+2016
- https://www.lexology.com/library/detail.aspx?g=44d84bcc-652d-4a5a-a3e3-4778fae2e383
- https://www.kominfo.go.id/content/detail/7194/siaran-pers-no28pihkominfo32016-tentang-surat-edaran-nomor-3-tahun-2016-terkait-penyediaan-layanan-aplikasi-danatau-konten-melalui-internet-over-the-top/0...
- Show more...
INDONESIA
Since December 2016
Since November 2019
Since November 2020
Since November 2019
Since November 2020
Pillar Intermediary liability |
Sub-pillar Safe harbour for intermediaries for any activity other than copyright infringement
Circular of the Minister of Communication and Information Technology No. 5/ 2016
Government Regulation No. 80/2019
Minister of Communication and Informatics (“MOCI”) Regulation No. 5 of 2020 on Private Electronic System Operators (“MOCI Regulation 5”)
Government Regulation No. 80/2019
Minister of Communication and Informatics (“MOCI”) Regulation No. 5 of 2020 on Private Electronic System Operators (“MOCI Regulation 5”)
Circular of the Minister of Communication and Information Technology No. 5/ 2016 provides the exemption to e-commerce providers from liability for failures to comply with the relevant laws in the event of force majeure, errors, or negligence. E-commerce providers will only be responsible for prohibited content posted on their platform if they are unable to prove that the uploading of such content was caused by the users.
In addition, Government Regulation No.80/2019 provides broad immunity to e-commerce service providers and intermediary service providers from the legal consequences arising from illegal third-party content. For e-commerce service providers, the regulation discharges them from any liability for illegal content found on their platforms, provided they have acted expeditiously to remove or disable access to such content after knowing of its existence (either by way of a report from a third party or finding it out themselves). To ensure that an e-commerce service provider is alerted of illegal content on its platform, the regulation requires such provider to provide terms of use/terms and conditions of the platform to its users and employ certain technology and/or feature in the platform for users to submit a report.
For intermediary service providers, the regulation discharges them from any liability for illegal content provided that such providers are acting as a mere conduit. If an intermediary service provider provides an 'interactive computer service', such as a social media platform, they will be discharged from any liability for restricting or removing access to content if such action was carried out in good faith and based on a report that such content is illegal.
Furthermore, MOCI Regulation 5 of 2020, provides that private ESOs hosting user-generated content may be exempted from legal liability for prohibited content transmitted or distributed on their electronic systems as long as they have fulfilled their governance obligations, shared information on subscribers who uploaded the prohibited content for monitoring and law enforcement purposes, and take down the prohibited content as regulated under MOCI Regulation 5. According to the law, private ESOs must ensure that their electronic systems do not (i) contain prohibited electronic information or documents and (ii) facilitate the dissemination of prohibited electronic information or documents. They also must take down prohibited content within 24 hours or four hours (the latter is for urgent prohibited content, such as child pornography content, terrorism content, and content that causes public unrest, which is very broad) after receiving the takedown notice. MOCI Regulation 5 classifies prohibited content into content that: is in violation of laws and regulations; causes anxiety for society and disturbs public order based on the government’s assessment; posts or provides access to prohibited content.
In addition, Government Regulation No.80/2019 provides broad immunity to e-commerce service providers and intermediary service providers from the legal consequences arising from illegal third-party content. For e-commerce service providers, the regulation discharges them from any liability for illegal content found on their platforms, provided they have acted expeditiously to remove or disable access to such content after knowing of its existence (either by way of a report from a third party or finding it out themselves). To ensure that an e-commerce service provider is alerted of illegal content on its platform, the regulation requires such provider to provide terms of use/terms and conditions of the platform to its users and employ certain technology and/or feature in the platform for users to submit a report.
For intermediary service providers, the regulation discharges them from any liability for illegal content provided that such providers are acting as a mere conduit. If an intermediary service provider provides an 'interactive computer service', such as a social media platform, they will be discharged from any liability for restricting or removing access to content if such action was carried out in good faith and based on a report that such content is illegal.
Furthermore, MOCI Regulation 5 of 2020, provides that private ESOs hosting user-generated content may be exempted from legal liability for prohibited content transmitted or distributed on their electronic systems as long as they have fulfilled their governance obligations, shared information on subscribers who uploaded the prohibited content for monitoring and law enforcement purposes, and take down the prohibited content as regulated under MOCI Regulation 5. According to the law, private ESOs must ensure that their electronic systems do not (i) contain prohibited electronic information or documents and (ii) facilitate the dissemination of prohibited electronic information or documents. They also must take down prohibited content within 24 hours or four hours (the latter is for urgent prohibited content, such as child pornography content, terrorism content, and content that causes public unrest, which is very broad) after receiving the takedown notice. MOCI Regulation 5 classifies prohibited content into content that: is in violation of laws and regulations; causes anxiety for society and disturbs public order based on the government’s assessment; posts or provides access to prohibited content.
Coverage Internet Intermediaries
Sources
- https://jdih.kominfo.go.id/produk_hukum/view/id/558/t/surat+edaran+menteri++komunikasi+dan+informatika+nomor+5+tahun+2016+tanggal+30+desember+2016
- https://www.mondaq.com/export-controls-trade-investment-sanctions/877568/welcoming-indonesia39s-e-commerce-regulation-a-snapshot#satu
- https://peraturan.bpk.go.id/Home/Details/126143/pp-no-80-tahun-2019
- https://www.globalcompliancenews.com/2021/01/11/indonesia-indonesia-regulates-foreign-private-electronic-system-operators-04012021/
- Show more...
INDONESIA
Since September 2017
Pillar Intermediary liability |
Sub-pillar User identity requirement
Minister of Communication and Information Technology Regulation No. 14 of 2017
According to Art. 5 of the Minister of Communication and Information Technology Regulation No. 14 of 2017, to get a prepaid phone SIM card in Indonesia, a customer must register their phone prepaid SIM card with their valid national ID and family register card, or a passport for foreigners. For the Registration process using passport, the information to be registered includes at least name, passport number, citizenship, and place and date of birth.
Coverage Telecommunications sector
INDONESIA
Since 2011
Pillar Domestic data policies |
Sub-pillar Requirement to allow the government to access personal data collected
Law on State Intelligence 2011
The Law on State Intelligence passed in October 2011 mandates that the collection of information on a person, that is considered harmful to national interest and security, should be based on the Head of State Intelligence Agency's order. The Law broadly authorizes the Indonesian State Intelligence Agency (BIN) to engage in efforts “to prevent and/or to fight any effort, work, intelligence activity, and/or opponents that may be harmful to national interests and national security” (Art. 6). This may include communications surveillance. BIN's intelligence activities, including to collect information, should meet the following requirements: 1) they are for the purpose of intelligence function; 2) they are based on Head of BIN's order; 3) they should be conducted without making any arrest and/or detention; and 4) they should be conducted in a cooperation with law enforcement agency. Civil society advocates in Indonesia had denounced the draft bill, which was nevertheless passed.
Coverage Horizontal
Sources
- https://jdih.kominfo.go.id/produk_hukum/view/id/553/t/peraturan+menteri+komunikasi+dan+informatika+nomor+20+tahun+2016+tanggal+1+desember+2016
- https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwivp5GUqO7uAhUX7aQKHdaKDAQQFjADegQIAhAC&url=http%3A%2F%2Fwww.bpkp.go.id%2Fuu%2Ffiledownload%2F2%2F1%2F1923.bpkp&usg=AOvVaw3EoIZ...
- https://jdih.bumn.go.id/baca/UU%20Nomor%2017%20Tahun%202011.pdf
- Show more...
INDONESIA
Since December 2016
Since November 2019
Since November 2019
Pillar Intermediary liability |
Sub-pillar Safe harbour for intermediaries for copyright infringement
Circular of the Minister of Communication and Information Technology No. 5/ 2016
Government Regulation No. 80/2019
Government Regulation No. 80/2019
Circular of the Minister of Communication and Information Technology No. 5/ 2016 provides the exemption to e-commerce providers from liability for failures to comply with the relevant laws in the event of force majeure, errors, or negligence. E-commerce providers will only be responsible for prohibited content posted on their platform if they are unable to prove that the uploading of such content was caused by the users.
In addition, Government Regulation No.80/2019 provides broad immunity to e-commerce service providers and intermediary service providers from the legal consequences arising from illegal third-party content. For e-commerce service providers, the regulation discharges them from any liability for illegal content found on their platforms, provided they have acted expeditiously to remove or disable access to such content after knowing of its existence (either by way of a report from a third party or finding it out themselves). To ensure that an e-commerce service provider is alerted of illegal content on its platform, the regulation requires such provider to provide terms of use/terms and conditions of the platform to its users and employ certain technology and/or feature in the platform for users to submit a report.
For intermediary service providers, the regulation discharges them from any liability for illegal content provided that such providers are acting as a mere conduit. If an intermediary service provider provides an 'interactive computer service', such as a social media platform, they will be discharged from any liability for restricting or removing access to content if such action was carried out in good faith and based on a report that such content is illegal.
In addition, Government Regulation No.80/2019 provides broad immunity to e-commerce service providers and intermediary service providers from the legal consequences arising from illegal third-party content. For e-commerce service providers, the regulation discharges them from any liability for illegal content found on their platforms, provided they have acted expeditiously to remove or disable access to such content after knowing of its existence (either by way of a report from a third party or finding it out themselves). To ensure that an e-commerce service provider is alerted of illegal content on its platform, the regulation requires such provider to provide terms of use/terms and conditions of the platform to its users and employ certain technology and/or feature in the platform for users to submit a report.
For intermediary service providers, the regulation discharges them from any liability for illegal content provided that such providers are acting as a mere conduit. If an intermediary service provider provides an 'interactive computer service', such as a social media platform, they will be discharged from any liability for restricting or removing access to content if such action was carried out in good faith and based on a report that such content is illegal.
Coverage Internet Intermediaries
Sources
- https://jdih.kominfo.go.id/produk_hukum/view/id/558/t/surat+edaran+menteri++komunikasi+dan+informatika+nomor+5+tahun+2016+tanggal+30+desember+2016
- https://www.mondaq.com/export-controls-trade-investment-sanctions/877568/welcoming-indonesia39s-e-commerce-regulation-a-snapshot#satu
- https://peraturan.bpk.go.id/Home/Details/126143/pp-no-80-tahun-2019
- Show more...
INDONESIA
Since November 2016
Pillar Domestic data policies |
Sub-pillar Requirement to allow the government to access personal data collected
Regulation No. 20 of 2016 on Personal Data Protection in Electronic Systems
Art. 23 of Regulation No. 20 of 2016 on Personal Data Protection in Electronic Systems provides that, for the purpose of the law enforcement process, electronic system providers are obliged to provide personal data that is contained in electronic systems, or personal data generated by electronic systems, upon a legitimate request made by law enforcement officers in accordance with the provisions of laws and regulations.
Coverage Electronic system providers
INDONESIA
Since September 2022, entry into force in October 2022
Since December 2016
Since December 2016
Pillar Domestic data policies |
Sub-pillar Requirement to perform an impact assessment (DPIA) or have a data protection officer (DPO)
Law No. 27 of 2022 regarding Personal Data Protection
Minister of Communication and Informatics Regulation No. 20 of 2016
Minister of Communication and Informatics Regulation No. 20 of 2016
Art. 53 of Law No. 27 introduces the requirement for controllers and processors to appoint a data protection officer (DPO) in certain circumstances, namely where:
- the data processing is carried out for the benefit of public services;
- the nature, scope, and/or purposes of the main activity of the controller require organised and systematic supervision on a large scale; and
- the main activity of the controller consists of large-scale processing which is specific in nature and/or which is related to criminal conduct.
Additionally, while Regulation No. 20 do not stipulate the requirement of a DPO, Art. 28(i) requires electronic system operators to provide a point of contact who can be easily contacted by the data subject relating to the management of their personal data.
- the data processing is carried out for the benefit of public services;
- the nature, scope, and/or purposes of the main activity of the controller require organised and systematic supervision on a large scale; and
- the main activity of the controller consists of large-scale processing which is specific in nature and/or which is related to criminal conduct.
Additionally, while Regulation No. 20 do not stipulate the requirement of a DPO, Art. 28(i) requires electronic system operators to provide a point of contact who can be easily contacted by the data subject relating to the management of their personal data.
Coverage Horizontal
Sources
- https://peraturan.bpk.go.id/Home/Details/229798/uu-no-27-tahun-2022
- https://jdih.kominfo.go.id/produk_hukum/view/id/553/t/peraturan+menteri+komunikasi+dan+informatika+nomor+20+tahun+2016+tanggal+1+desember+2016
- https://platform.dataguidance.com/sites/default/files/data_privacy_english_-_permenkominfo_no_20_of_2016.pdf
- https://www.dataguidance.com/notes/indonesia-data-protection-overview
- Show more...
INDONESIA
Since September 2022, entry into force in October 2022
Since October 2019
Since October 2019
Pillar Domestic data policies |
Sub-pillar Requirement to perform an impact assessment (DPIA) or have a data protection officer (DPO)
Law No. 27 of 2022 regarding Personal Data Protection
Government Regulation No. 71 of 2019 on the Implementation of Electronic Systems and Transactions
Government Regulation No. 71 of 2019 on the Implementation of Electronic Systems and Transactions
According to Art. 34 of Law No. 27, the data controller is obliged to conduct a Data Protection Impact Assessment if the personal data processing has a high potential risk to the personal data subjects. Personal data processing with high potential risk includes:
- automatic decision-making that has legal consequences or a significant impact on the data subject;
- processing of specific personal data;
- processing of large-scale personal data;
- processing of personal data for systematic evaluation, scoring, or monitoring of data subjects;
- processing of personal data for the activity of matching or combining a group of data;
- the use of new technologies in the processing of personal data; and/or
- the processing of personal data that limits the exercise of the rights of the data subject.
On the other hand, under Art. 12 of Government Regulation No. 71, electronic system providers must apply risk management towards damages or losses that they incurred. Such provision provides the meaning of 'risk management' as conducting risk analysis and formulating mitigation measures and countermeasures to overcome threats, disturbances, and obstacles to the electronic system which it manages.
- automatic decision-making that has legal consequences or a significant impact on the data subject;
- processing of specific personal data;
- processing of large-scale personal data;
- processing of personal data for systematic evaluation, scoring, or monitoring of data subjects;
- processing of personal data for the activity of matching or combining a group of data;
- the use of new technologies in the processing of personal data; and/or
- the processing of personal data that limits the exercise of the rights of the data subject.
On the other hand, under Art. 12 of Government Regulation No. 71, electronic system providers must apply risk management towards damages or losses that they incurred. Such provision provides the meaning of 'risk management' as conducting risk analysis and formulating mitigation measures and countermeasures to overcome threats, disturbances, and obstacles to the electronic system which it manages.
Coverage Horizontal
Sources
- https://peraturan.bpk.go.id/Home/Details/229798/uu-no-27-tahun-2022
- https://jdih.kominfo.go.id/produk_hukum/unduhTerjemahan/id/695/t/peraturan+pemerintah+nomor+71+tahun+2019
- https://jdih.kominfo.go.id/produk_hukum/view/id/695/t/peraturan+pemerintah+nomor+71+tahun+2019+tanggal+10+oktober+2019
- https://www.dataguidance.com/notes/indonesia-data-protection-overview
- Show more...
INDONESIA
Since December 2016
Since September 2022, entry into force in October 2022
Since September 2022, entry into force in October 2022
Pillar Domestic data policies |
Sub-pillar Minimum period for data retention
Minister of Communication and Informatics Regulation No. 20 of 2016
Law No. 27 of 2022 regarding Personal Data Protection
Law No. 27 of 2022 regarding Personal Data Protection
The Minister of Communication and Informatics Regulation No. 20 of 2016 mandates the minimum retention for stored personal data at five years (unless stated otherwise in other laws and regulations). An exemption to this provision is stipulated under Art. 16 of Law No. 27, where personal data must be destroyed and/or deleted after the expiry of the retention period or at the request of the data subject.
Coverage Electronic systems operators
Sources
- https://jdih.kominfo.go.id/produk_hukum/view/id/553/t/peraturan+menteri+komunikasi+dan+informatika+nomor+20+tahun+2016+tanggal+1+desember+2016
- https://platform.dataguidance.com/sites/default/files/data_privacy_english_-_permenkominfo_no_20_of_2016.pdf
- https://www.dataguidance.com/notes/indonesia-data-protection-overview
- https://globalcompliancenews.com/argentina-regulation-personal-data-protection-20170125/
- https://peraturan.bpk.go.id/Home/Details/229798/uu-no-27-tahun-2022
- Show more...