• Tidak ada hasil yang ditemukan

lndonesia issues draft Ministerial Regulation on Data Protection.

N/A
N/A
Protected

Academic year: 2017

Membagikan "lndonesia issues draft Ministerial Regulation on Data Protection."

Copied!
2
0
0

Teks penuh

(1)

Safe

Harbor invalid:

lvhat

to

expect

after the

ruling?

Sarah

Cadiot

and

Laura

De

Boel

explain

what

businesses can

do

to

enable transfers

to the

US.

lSsue

137

,l ' ,

fs=w5

dletober

Sl5

zft

rr

6

O*tub,,r

2C15,

rhr.

I

lCnurt ,''i

lr-rsricc

ol

thc

\-/

Iuro[.,c.rn

Uni.'n

(CJI

U]

issucrl

a

landrn;rrtr< iudgrne nrl

invalidatir:g ihe

F,urope*n Comn'rission's

Deci,sion

o{

lC'33:

rvhich

r*cognise,-1

rhe

adequacv

oi

the

IU-U.S

S;,rfe

Harbor frarrenork

{Sale

H;rrbor).

Irr

er"{<liti*n

ro

thc

invalidarion

of this

adeqnacr-cltcision,

rhc

CJEU

lprhclcl

thc

grorver

of

natioaal

lJara

llrorr:ction

Authoriries {DPAsl

tr:

in.lependently

inr.r,stigatc

intcrnational

data

Continued on p.3

:l

-

Safe,Harborinyalid: WhatntlnJ?

1

'

Eu

darifi€s:con*ptof ierdtort*iity

2

-

Cornment

Sate Harbor collapses 7

-

EU and US agree on data

trA*tf

ets

l*r

latrr enforaernetlt

14 - Tehfonica fined tO+ times in Spain

!5

-:l(or*a ehooses'aetive uae

of

lBig

,

Data'tostirnL+late'Crcative,'

Economy'

28 - Book Review: Cloud Cornputing

AIHALYSIS

11 - Getting

to

grips

with

US

government requests for data

16 -

tLi'* Sn*5top"Shrp

mechanism

19 - DPAs'GPEN grows

24 - lndian 5upreme Court causes

confusion on data privacy and lD

LEGISLATION

8

-

Japan arnsrtls its DF Aet

27 - lndonesia issues

draft

Ministerial

Regulation

MANAGEMENT

29 - US N|ST invites comments on loT

standards framework

30 - Assessing privacy risks as part

of

a Privacy by Design programme

*lgwg

tH

ER|EF

1O - Hungary makcs B€Rs porsible

22 - Russian data localisation law

22 - Mexics ronsiders $2 million

fine

13 - €DPS:'Ethic

Advi;ory

Soard and

collection of passenger data

23 - Website awarded Europrise Seal 23 - DPAs: Sweep on children's data

rarses concerns

26 - 5ingapore issues new guidance

Z8 - franee adcpts surveilla,nce Act

ECJ

clarifies

meaning

of

territorial scope

in

DP

Directive

{)urtinue d rtn p.5

Hungarian

data protection law applies

tc

a company's activlties

in

Hungary although registered in Slovakia.

Andrea KLira Soos

reports.

n I

f)ctober

20

15,

tire

rhc ctritr:lusion rhnt the prirrciple r'rf

-Luropc:rn

Cr:urt

ol

Justice

csrrhlishrrcnt should be applied br.

{ECJI publishrd its

decision

thc auth*ritic,s

ol

{-rrhcr

EU }lemlrirr

in

cese

|'lo.

(l-l3Oi!C1+1.

tn

this

States.

(Jonsequ,.:rrth,

it

r'l*r;r

de

cision

thc

I'-CJ {ollarvcd

thc

cor.rrre:ltrcr

cor,rld

hc

inicstigarcd erguncntation

i:f

Adr.utatc Gcncral

Pedro

C*.rz YillaLlnj

rnil

t:arle

r,;

Access

back

issues

on

wugw.prluacylaws,com

5ubscribers

to

paper and eiectro,nic editions can ac(ess the following:

See

the

track page or

www.privacylaws.comlsubsrription_info

To check your lype

of

subscription, contart

gienn@privacylaws.com or telephone +44 {0)20 8868 9200.

.

Back lssues since 1987

.

Special R€ports

.

Materials

from

PL&B eventg
(2)

TEGISLATION

lndonesia

issues

draft

Ministerial

Regulation

on

Data

Protection

By

Sinta Dewi

Rosadi.

A

lthough mobile

traffic

data

A;,n;

i$'ji

::

ilT::::,;'ff;

legal protection

{or

such digital-based

activities

is still

weak. Currently there

are

no

specific

rules that

ensure the

protection of users' dataprivacy.

\fith

a

wide

range

of

applications, users are

asked

to

provide

their

address, mobile

phone number and credit card number

-and those details

will

be recorded.

No

less important

is that

data conrollers process

data

on

transactions, travel

routes,

user

habits,

patterns

of

communications

and

data

about

user

activity

in

the

context

of

a variety

of

applications

or

Internet

pages. To

address these developments, Indonesia's

Ministry

of

Communications

and

Informatics

(Infocom)

has

drafted

Ministerial

Regulations

on

Personal

Data Protection (PDPES)

in

Electronic

Systems as an implementing regulation

based

on

Governmenr Reguiation No.

82/2A12

on

Electronic

Transaction

Systems.2

Ministry

regulations

are

a

lower

form of

legislation

than

Government regulations

or

Acts

of

Parliament. The PDPES

will

cover basic

protection mechanisms such as the rights

of data subjects, user liabiliry liabiliry

for

operators

of

electronic systems; dispute

resolution,

public

participation

and

adrninistrative sancrions.

A

public

consultation was completed in July, but it is not certain when the final Regulation

will

be released.

The

draft

regulation

deserves

attention because

for

the

first

time the

government

of

Indonesia

will

issue a

specific

regulation

on

protection of

personal

data.

However,

it

is

regretmble

that

PDPES

will

overlap

with

the

Personal

Data

Bill

being

prepared

by

another Directorate in

Infocom.

A

ministerial regulation

is

not

compatible

vdth

Indonesia's

Constitution,

according

to

which

personal data protection is

part of

the

Privacy

Right which

is

protecred by

the Constitution

and considered as a

fundamental righq therefore requiring

an

Act'

rather than the lesser form of a

Ministerial Regulation.

It

may also be

criticised

on

other

grounds.

The

PDPES does

not

clearly stipulate its

scope

(individuals

or

legal

entities;

public

and/or private

secrors),

although

it

does

only

apply

ro

'E,lectronic System

Operators'.

The regulation only applies minimum basic

data protection principles such

as

consent,

right

to

verified content, and

right

to

access

and correction.

The

regulation

requires

data

subjecrs'

written

consent,

but

does

not

clearly stipulate whether the rnechanism

to

be

used is opt-in or opt-out.

The

data rerenrion

period is

long

under PDPES

(5

years);

this

is

in

accordance

with the

National

Retention Schedules Regulation

in

the

National Archives Law,

which

was

-

developed

to

regulate

the

public

archive, not personal data.

There is no specific rule

in

PDPES

that

gives authority

to a

stare

institution to supervise this system. To

effectively implement legislation,

a

supervision mechanism

would

be

required, as

well

as a legal instrument

which.

g4overns

personal

data

protectlon.

According

to

the 'data localisation' requirement

in

the draft governmental

regulation

(under

which

this ministerial regulation is made) the'data

centre and

disaster

recovery

centre'

must

be

located

on

Indonesian

territory. This drafr

is still

rentative because the

Ministry

is

in

the process

of receiving input from the public. The

Draft Minlstry

Regulation

will

operate as

follows':

1.

Protected personal data

Personal data refers to any true and real information that can be direcriy or

indirectly identified

as relaring

to

an

individual,

to

be

used

in

accordance

with

existing regulation.

2.

Data collection and processing The PDPES includes protection

of

the collection,

processing, analysing,

storing,

notification,

transmission,

dissemination

and

destruction

of

Personal

Daa.

Personal

data shall be

processed

only if:

(a)

Data

subjects have given their

consent

(b)

Personal

data

obtained

and

collected

directly

must be verified

by the data subject

(c)

Personal

data

obtained

and collected indirectly musr be verified

based on various sources

(d)

Personal

data

may

only

be

processed and analysed accordihg

to the

needs/purpose

of

the

Electronic

Systems

Operator

rhat

have been stated

clearly

when obtaining and collecting the data.

3.

Retention

Electronic Systems operators may

store personal data for 5 years or more

or iq

accordance

with

applicable

regulations.o

4.

Responsibility

of

electronic

system administrator/management Each Electronic System Operator

must have internal rules

to

carry

out the process and ensure the protection of personal data. n

5.

The

rights

of Eata subjects:

a.

The

confidentiality

of

their

personal data

b.

The

right

to

file

a complaint

with

the personai data dispute resolution

institutions

for

failure of

personal

data

confidentiality protection

by

the Operator Electronic

Systems, and the right to sue

in

a civil court

c.

The

right to

reclaim one's personal

data,

when

the

services

of

an

Electronic System Operator are no longer needed

d. The rigEt

to

access

and

the

opportunity

to"'change

or

update

personal

dam

without

disturbing

personal data

management

systems.

5.

The

responsibility

controllers

of

data

a.

To

maintain

the

confidentiaiity

of

personal da''a that

it

has obtained, collected, processed and analysed

b.

To

process personal data

only in

accordance

with

the

purposes

for

which

it

was collected

Referensi

Dokumen terkait

Bias gender tampak pada kategori ini dalam empat bentuk: aktivitas yang secara tradisional dianggap layak dilakukan oleh gender tertentu, aktivitas yang secara

Sistem multi partai merupakan suatu sistem yang terdiri atas lebih dari dua. partai politik

Gedung H, Kampus Sekaran-Gunungpati, Semarang 50229 Telepon: (024)

• Yang terpenting adalah persepsi individu dari keberhasilan atau kegagalan yang menentukan pengaruh kompetensi terhadap motivasi dan ketekunan.. • Nicholls  terdapat dua

Implementasi media pembelajaran berbasis perangkat lunak lectorainspire pada mata pelajaran elektronika dasar.. Universitas Pendidikan Indonesia | repository.upi.edu

[r]

You will always discover something different with Right Travel as a long time tour operator in all our tours, safaris, study tour, honey moon holiday, beach holiday, mountain

STUDI TINGKAT PEMAHAMAN SISTEM UTILITAS BANGUNAN PADA MAHASISWA PROGRAM STUDI PENDIDIKAN TEKNIK BANGUNAN FPTK UPI.. Universitas Pendidikan Indonesia | repository.upi.edu |