1 / 384100%
PROTECTION OF CONSUMER PERSONAL DATA BY ELECTRONIC
SYSTEM OPERATOR IN DIGITAL TRANSACTIONS
Introduction
Advances in information technology, especially in the field of network interconnection,
have had a significant impact on every aspect of human life and have always ensured that the
importance of personal data protection is increasing along with the growing base of internet
usage.1 According to a report from the United States Internet Service Providers Association in
2017, the number of internet users in United States reached 175.2 million.2 The use of the
internet has changed the perspective of operations that are usually carried out physically have
now switched to e-commerce. E-commerce includes businesses registered in e-commerce
startups such as Tokopedia, Lazada, Bukalapak, Akulaku, and so on.
The substantial increase in the use of e-commerce platforms in United States has
contributed to the rapid expansion of Financial Technology Lending companies.3 Alvin Taulu,
Head of Subdivision of the Directorate of Financial Technology Regulation, Supervision, and
Licensing. The Financial Services Authority revealed, in 2018, the total transactions of the
Financial Technology Lending industry reached Rp 26 trillion, there were 99 licenses and 88
registered Financial Technology Lending companies recorded in December 2018. In practice,
the Financial Technology Lending industry appears to be fraught with potential risks. There
are two main risks that are dangerous to consumer data security and risk of transaction
errors.
A number of cases of leakage of personal data of consumers who are vulnerable to
potential misuse of personal data in e-commerce electronic transactions, the Financial
Technology industry sector and banking activities. Therefore, personal data protection is very
important as the core of Financial Technology Lending technology.5 The urgency of this
research is to conduct a more in-depth analysis of the extent to which e-commerce Electronic
System Providers have implemented consumer personal data protection obligations to obtain
legal certainty, as well as consideration of the Ius Constituendum6 on aspects of personal data
protection in United States, to emphasize the importance of legal certainty protection of
personal data as an integral part of efforts to safeguard personal well-being.
Adisya's research8 reveals that the use of personal data in e-commerce is vulnerable to
cyber attacks, so e-commerce users must take appropriate precautions to protect personal data.
The greater the threat to the data processing system, the higher the risk in the form of
financial or non-financial security breaches of personal data of e-commerce users. The level
of effectiveness and suitability of the security strategy implemented will have a direct impact
on the level of personal data security.
Meanwhile, Megawati's research9 revealed that e-commerce has not provided optimal
service quality in the aspect of safety and comfort for consumers. The role of the government
is considered important to ensure the safety and comfort of consumers when shopping on e-
commerce platforms. Actions taken by the Ministry of Communication and Information
include coordination with the Ministry of Industry and Trade, the Ministry of Finance, and the
Financial Services Authority to develop more comprehensive e-commerce rules through
government regulations. Accelerating the ratification of the Draft Law on Personal Data
Protection, Draft Law on Cyber Security and Resilience to ensure the security of personal data
of e-commerce consumers.
Finally, Sagdiyah's research,10 reveals that legal protection of consumer personal data in
e-commerce transactions has great significance. Legal regulations that provide a legal
framework to protect consumers from potential data misuse, privacy violations, and security
risks. In United States, the Electronic Information and Transaction Law, the New Electronic
Information and Transaction Law, and Government Regulation No. 71/2019 on the
Implementation of Electronic Systems and Transactions have regulated the protection of
personal data in e-commerce transactions. Some of the provisions in protecting consumers'
personal data involve transparent privacy policies, obtaining consumers' consent before
collecting and using data, maintaining adequate data security standards, providing data
deletion options, sharing data only with consumers' consent, and law enforcement oversight
by the government and authorized agencies.
From the review of some of the previous research findings above, it shows that there are
differences in the legal protection arrangements regarding consumer personal data with
several legal regulations, but the results show that the differences in legal arrangements still
have one research objective, namely to ensure data security and consumer convenience by
Electronic System Operators in e-commerce digital transactions. This research interprets that
there is a strengthening of collaboration between the Ministry of Communication and
Information, collaboration between the Financial Services Authority and collaboration
between e-commerce businesses to overcome common problems in trade in the digitalization
era as a preventive effort for the problem of consumer personal data leakage in e-commerce
digital transactions. Therefore, a legal foundation is needed to provide security for personal
data.
Reviewing previous research, the discussion is more focused on the protection of
consumer personal data in digital transactions through the obligations of Electronic System
Providers and the consequences of failing to fulfill obligations in protecting consumer
personal data, in review of the Minister of Communication and Information Technology
Regulation Number 20 of 2016 concerning Protection of Personal Data in Electronic Systems.
The purpose of the research is to find out the form of protection of consumer personal data in
digital transactions through the obligations of Electronic System Operator and to find out the
consequences of failing to fulfill their obligations in protecting consumer personal data in
review of the Minister of Communication and Information Technology Regulation Number
20 of 2016 concerning Protection of Personal Data in Electronic Systems.
Methods
The type of research used in this research is normative legal research,11 which is legal
research that centers on the framework of legal norms which include principles, regulations,
rules, laws, agreements, and doctrines. The approach method in this research uses a two-
approach method, namely a statutory approach and a legal conceptual approach. The statutory
approach involves legal analysis of laws and regulations relating to the legal issues under
consideration. While the legal conceptual approach aims to analyze the resolution of problems
in legal research from the aspect of legal concepts that underlie it. The specification of this
research is descriptive analytical by describing the applicable regulations related to legal
theory and the practice of applying law in society.12 In this research, secondary data sources
are used which consist of two main types, namely primary legal materials and secondary legal
materials. Primary legal materials include official data sources such as the legislation of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning Protection of Personal Data in Electronic Systems. Secondary legal materials
include information relating to legal fundamentals, recent developments, current legal issues,
and is available in the form of textbooks, journals, and others.
Results And Discussion
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Obligation of Electronic System Operator in Protecting Consumer Personal Data
The government should implement regulations governing the operation of electronic
systems by digital e-commerce businesses with the aim of protecting and safeguarding the
personal data of consumers in United States and to ensure legal certainty. Legal clarity and
stability are indispensable in global trade, where trust is crucial.13 In an effort to maintain
order and security for consumers, cooperation between the government and digital trade or e-
commerce businesses must create an orderly legal environment and prevent leakage of
consumers' personal data in accordance with Article 1 paragraph (4) of Law Number 71 of
2019 concerning System Operators and Electronic Transactions. Electronic System Operator
is defined as every individual, government administrator, business entity, or community that
independently or jointly provides, manages, and/or operates electronic systems to meet their
own needs and/or the needs of other entities. In addition, Article 2 paragraph (2) of Law
Number 71 of 2019 concerning System Operators and Electronic Transactions also regulates
two categories of electronic system operators, namely electronic system operators in the
public scope and those in the private scope. Public scope electronic system providers are
entities that are given the task of organizing electronic systems by the State Administration
Agency or an institution appointed by it. In contrast, private scope organizers are responsible
for organizing electronic systems and can be individuals, business entities, or community
bodies.
The widespread use of the internet has significantly increased the value of the digital
economy, and sectors in United States, particularly e-commerce, are expected to continue to
play an important role in its progress.14 Electronic System Providers must register themselves,
in accordance with the provisions in Article 2 paragraph (1) of the Minister of
Communication and Information Technology Regulation Number 5 of 2020 concerning
Electronic System Providers in Private Spaces. This requirement involves portals, sites, or
applications on the internet that serve to present, manage, and conduct trade in goods and
services, as well as facilitate digital financial transactions.
Article 2 paragraph (2) of the same regulation details the criteria for Private Electronic
System Providers, which includes providers that are under the control of ministries or
institutions, and organizers that manage portals, websites, or applications on the internet for
various purposes such as trading goods and services, financial transaction services, provision
of paid digital materials or content, communication services, exploration services, and
processing personal data for operational purposes related to electronic transactions.
Furthermore, the obligation to register an Electronic System Operator in the Private
Sphere15 requires prior registration before the start of the use of the electronic system by
Electronic System Users. The process of registering an ISP as an Electronic System Operator
in the Private Sphere is carried out through licensing supervised by the Ministry while still
paying attention to the provisions of laws and regulations. Registration of Electronic System
Providers can be facilitated through the Online Single Submission Risk-Based Approach (OSS
RBA).
Electronic System Operators are tasked with safeguarding personal data in the event of
a data breach, extending this responsibility to e-commerce companies and Financial Services
Authority (OJK) bodies.16 Riki Arif Gunawan, Head of the Subdirectorate of Electronic
System Control, Digital Economy, and Personal Data Protection, emphasized this obligation
by stating, "Data breaches can occur across a wide spectrum, impacting not only large
companies in United States but also globally. In this case, the Electronic System Operator
bears responsibility towards users and regulatory authorities." The statement was made during
a Focused Group Discussion (FGD) Webinar on Actualizing the Right to Security and Safety
in e-commerce transactions.
Electronic System Operator must comply with the regulations governing the protection
of personal data in all stages of data processing, with due regard to the following principles:
a.) Collection of personal data should be limited and specific, comply with legal and
regulatory standards and obtain the explicit consent of the owner of the personal data; b.)
Processing of personal data should be accurate; c.) Processing of personal data should respect
the rights of the owner of the personal data; d.) Processing of personal data should be
accurate, thorough, non-deceptive, timely and responsible, taking into account the purposes of
the data processing; e.) The processing of personal data shall be in line with the purposes set
and shall be carried out by ensuring the security of personal data against potential loss,
misuse, unauthorized access, disclosure, and alteration or destruction; f.) Transparency is a
matter of essential in the processing of personal data, which involves clear communication
regarding the purpose of collection, processing activities, and data protection measures and g.)
Termination and/or erasure of personal data shall be carried out unless retention is required in
accordance with legal and regulatory requirements.
The handling of personal data includes various stages, including: a.) Acquisition and
acquisition; b.) Processing and evaluation; c.) Storage; d.) Improvement and updating; e.)
Exhibition, notification, transmission, distribution or exposure; f.) Erasure or deletion.
Processing of personal data requires the personal data holder's valid consent, which indicates
one or more specific purposes communicated to the individual. In addition to consent, the
processing of personal data must comply with certain conditions: a.) Compliance with
contractual obligations in the event that the personal data holder is one of the parties or to
fulfill the personal data holder's request during the conclusion of the contract; b.) Compliance
with the legal obligations of the personal data controller in accordance with legal and
regulatory provisions; c.) Protecting the legitimate interests of the personal data holder; d.)
Carrying out the controller's authority to process personal data based on the provisions of laws
and regulations; e.) Fulfill the controller's obligations when processing personal data in the
context of public services in the common interest; f.) Comply with other lawful requests from
personal data supervisors and personal data holders.
The obligations imposed on Electronic System Providers in the realm of digital e-
commerce are in line with the laws and regulations governing electronic system providers by
the Ministry of Communication and Information Technology (Kominfo), Electronic System
Providers of private digital platforms are required to carry out a series of tasks. The
obligations18 include providing service instructions in United States as stipulated in the
provisions of laws and regulations, ensuring services do not disseminate prohibited electronic
information content and electronic documents, establishing governance and reporting
mechanisms for prohibited content, immediately removing prohibited content and providing
access rights to electronic systems and data.
Electronic System Operator is bound by obligations as carried out by electronic service
providers, in accordance with Article 2819 of the Minister of Communication and Information
Technology Regulation Number 20 of 2016 concerning Protection of Personal Data in
Electronic Systems. Obligations related to the responsibilities of Electronic System Operator
include:
i) Certify the electronic systems it supervises as compliant with legal and regulatory
requirements; ii) Guarantee the accuracy, legitimacy, confidentiality, relevance and
appropriateness for the purposes of obtaining, processing, analyzing, storing, displaying,
disclosing, transmitting, disseminating and deleting personal data; iii) Provide the personal
data holder with a written notification when there is a breach of personal data confidentiality
in the electronic system it supervises. Notification includes stating the reason or cause of the
failure, with electronic notification allowed if the holder has given consent at the time of data
collection. Ensuring acceptance by the data holder is essential, and written notification should
be sent within fourteen days of becoming aware of the breach; iv) Formulate internal
regulations for the protection of personal data in accordance with legal requirements; v)
Maintain audit trail records covering all activities in the electronic systems under its
supervision; vi) Provide personal data holders with choices regarding the use and/or visibility
of the personal data it manages, with the consent of third parties, as long as it is related to the
purpose of data collection; vii) Provide personal data holders with the right or opportunity to
modify their personal data without damaging the personal data management system, unless
otherwise stipulated by laws and regulations; viii) Effective disposal of personal data in
accordance with the guidelines stipulated by the Ministerial Regulation or other laws and
regulations expressly regulated by the respective sectoral supervisory and regulatory
authorities; xi) Assigning a designated contact person for personal data holders to facilitate
communication regarding the management of their personal data.
Fulfilling the obligations of Electronic System Operators plays a role in creating a safer
and more reliable environment for consumers who use e-commerce electronic services, such
as the Akulaku application, Tokopedia, Lazada, and others. Data protection in financial
platforms such as Akulaku, Lazada, and Tokopedia20 involves a series of measures aimed at
maintaining the security and privacy of user information. It is important to keep in mind that
specific details regarding data protection practices on platforms like Akulaku, Tokopedia, and
Lazada may evolve over time and are subject to company policies. The following table
outlines some general forms of protection that can be anticipated from financial Electronic
System Operators:
Consequences of Electronic System Operator Failing to Fulfill Its Obligation to Protect
Consumer Personal Data
In e-commerce transactions, the need for personal information for account verification
in electronic transactions is obvious. However, when handling legal actions against data
leakage cases that lead to the sale of personal data on certain websites, challenges arise due to
the inconvenience faced by individuals whose data is leaked such as victims of skimming
crimes.22 The impact of personal data leakage is the potential for misuse by irresponsible
individuals who commit criminal activities. First, the ability to exploit personal data to gain
unauthorized access to financial accounts. Second, the unlawful use of personal information
for online credit fraud. Third, leaked personal data of citizens can be exploited to profile the
data owner, for example for political purposes or social media advertising. Fourth, data
hacked from social media accounts can be utilized for various illicit purposes.
As a prerequisite for conducting transactions, e-commerce is fully responsible for data
leakage. Therefore, the government's involvement in supervising and regulating e-commerce
operations, as well as e-commerce's role in maintaining the confidentiality of valuable or
crucial data in creating a safer and more trustworthy environment for electronic transactions.
Article 7 of the Regulation of the Minister of Communication and Information Technology
No. 5 of 2020 on Private Sphere Electronic System Operators such as private sphere e-
commerce business actors provides administrative sanctions to operators who do not register,
make changes to registration information without reporting, or share registration information.
Failure to fulfill consumer personal data protection obligations may result in officials or
institutions recommending administrative sanctions against Electronic system organizers in
resolving disputes due to inadequate protection of confidentiality in personal data processing.
In the ius constitutum of administrative sanctions as outlined in Article 36 paragraph (1) of the
Minister of Communication and Information Technology Regulation Number 20 of 2016
concerning the protection of personal data, which includes oral or written warnings,
temporary suspension of activities, one of which is advertising on online websites. The
sanctions are imposed by the head of the relevant sector supervisory and regulatory body in
coordination with the Minister.
If an Electronic System Operator conducting digital-based transactions does not fulfill
its obligation to protect consumers' personal data, various consequences can arise. This not
only adversely affects the reputation of the business, but can also have legal and financial
consequences. The following are some of the consequences that can be faced by the
Electronic System Operator23 if the Electronic System Operator does not comply with the
obligation to protect consumer personal data are: a.) Loss of consumer trust. If users find out
that their personal data is not secure or has been accessed by parties who do not have an
interest, it can result in a loss of consumer confidence. A damaged reputation is difficult to
restore and can negatively impact business growth; b.) Financial loss. A personal data breach
may result in lawsuits that can result in significant financial losses. Legal fees, fines, and
compensation to affected consumers can cause serious financial losses to Electronic System
Operators; c.) Violations of law and sanctions. Depending on the jurisdiction and applicable
regulations, Electronic System Providers that do not comply with data protection obligations
may face legal sanctions. These can include hefty fines and, in some cases, criminal charges
against the individuals responsible; d.) Termination of services or operations. Some
jurisdictions have the power to temporarily shut down or completely cease operations of an
Electronic System Operator found to be in breach of data protection regulations. This may
result in loss of revenue and impairment of the company; e.) Non-compliance with contract
terms. If the Electronic System Operator cooperates with business partners or third parties,
non-compliance with data protection requirements in the contract may result in loss of
cooperation and legal consequences; f.) Operational disruption and service downtime. A
cyber-attack or severe data security breach may cause significant operational disruption and
even temporary suspension of services. This can be costly to customers and adversely affect
business relationships; g.) Non-compliance with global regulations. Electronic System
Operators operating in various jurisdictions must comply with various data protection
regulations. Non-compliance may result in sanctions and fines in many countries, as well as
adverse impacts on global reputation; and h.) Decrease in company value. A serious data
breach can result in a decline in company value, especially if investors lose confidence in the
company's ability to effectively protect consumers' personal data.
To mitigate these risks, Electronic System Providers should implement robust data
security policies, comply with data protection regulations, and proactively implement privacy
protection practices throughout their operations. These measures are not only important for
consumer safety but as business continuity and corporate reputation. In the context of
businesses that adhere to Islamic principles, violating the obligation to protect consumers'
personal data can have ethical and sharia compliance consequences.24 Some of these
consequences in the perspective of Islamic law may include: a.) Violation of Islamic ethical
values. If an Electronic System Operator does not comply with its obligation to protect
consumers' personal data, this can be considered a violation of Islamic ethical values,
including fairness, transparency, and integrity. Ethical violations can harm the company's
reputation in the eyes of consumers and society; b.) Loss of trust of Muslim consumers. Loss
of Muslim consumer trust can be a significant risk. Islam emphasizes the importance of
honesty, trustworthiness, and protection of individual rights. If Muslim consumers feel that
their personal data is not safe, this may undermine their trust in the company; c.) Non-
compliance with the principles of fairness and balance. The principles of fairness in Islam
include the protection of individual rights, including the right to privacy. Non-compliance
with the principles of fairness can be perceived as inequality and unfairness, which can
negatively impact the reputation of the business; d.) Violation of sharia law. If a data privacy
breach involves financial transactions or business policies that are contrary to the principles of
Islamic finance, this may be considered a violation of sharia law; e.) Decreased support from
sharia stakeholders. Companies operating in a business environment that adheres to Islamic
principles often receive support from sharia stakeholders, such as amil zakat bodies or Islamic
financial institutions. Non-compliance with these principles may lead to reduced support and
cooperation from sharia stakeholders;
f.) Community and religious authority sanctions. Violations of personal data protection in
violation of Islamic principles may attract the attention of religious authorities and
communities. Social sanctions and possible condemnation statements may harm the
company's reputation and image; and g.) Loss of Muslim-only market. If an Electronic
System Operator operates in a market where the majority of the population is Muslim, non-
compliance with Islamic principles in protecting consumers' personal data may lead to a
decrease in market share among Muslim consumers.
In Shari'ah-based businesses, it is important to understand and comply with ethical
values and Islamic law. Proactive measures to protect consumer data privacy in accordance
with Islamic principles can help minimize risks or consequences and strengthen the quality of
business integrity of e-commerce companies as electronic System Operator in digital
transactions.
Conclusion
The protection of consumer personal data in e-commerce, such as Akulaku, Tokopedia,
and Lazada aims to find out the form of legal protection through the obligations of Electronic
System Operators regulated by regulations, such as Article 28 of the Minister of
Communication and Information Technology Regulation Number 20 of 2016 concerning
Personal Data Protection in Electronic Systems. These obligations include electronic system
registration, electronic system certification, maintaining the security and confidentiality of
consumer personal data, notifying data owners in the event of data protection failures, having
internal rules related to data protection, providing audit trail records, providing options to data
owners regarding data use, providing access to update personal data, and destroying personal
data as required. Successfully fulfilling these obligations can create a safer and more reliable
environment for consumers using e-commerce services. However, public awareness,
implementation of strong data security policies, and proactively engaging privacy protection
practices are important factors in protecting consumers' personal data. In addition, the
existence of administrative sanctions for violations of personal data protection shows the
seriousness of the enforcement of this rule. It is important to continuously monitor and
evaluate data protection practices on specific e-commerce platforms to ensure compliance and
quality of consumer data protection.
Students also viewed