PROTECTION OF PRIVACY AND PERSONAL DATA IN THE ERA OF
DIGITAL ECONOMY IN UNITED STATES
Introduction
The protection of privacy and personal data greatly affects the development of the digital
economy in a country, and United States is no exception. Such protection is a determining
factor for online trust, which is important in digital transactions. Privacy and personal data
are important because online users will not conduct digital transactions if they feel that the
security of their privacy and personal data is threatened. One of the protections of privacy and
personal data concerns how the personal data will be processed, including sensitive data from
users, which if disseminated to irresponsible parties will potentially cause financial losses,
and even threaten the security and safety of the owner. The threats arising from the lack of
privacy and personal data protection have a straight line correlation with the economic
growth generated from online transactions.
News about the rise of fraud using e- commerce sites is often found in the country.1 This has
resulted in a decrease in the level of public trust in online commerce transaction sites. People
who are aware of this are reluctant or worried about using credit cards that involve privacy
and personal data. With so many e-commerce sites, United Statess need a guarantee of
privacy and personal data protection. Now, fraud is thriving by utilizing social media such as
Facebook and Instagram. With the decline in public trust in online trading sites, as well as
online trading utilizing other online media, the growth of United States digital economy will
stagnate, and even tend to decline along with the loss of user confidence.
Many United Statess have complained about telemarketing activities that fall into the
category of direct marketing, which directly offers financial products such as insurance and
unsecured loans. One of the problems in this practice is the transfer of personal data of
customers or the public that is not in accordance with ethical principles. Customers' personal
data is widely circulated among companies that use direct marketing using telephone. If this
kind of problem arises, the Financial Services Authority can be a complaint institution that
can be used by the public. However, the practice of telemarketing without prior public
consent remains rampant in United States.
Not only in the case of direct marketing, controversy also occurs in the practice of requesting
family card data in prepaid card registration. Serious problems arise when such practices are
confronted with issues of privacy and protection of consumers' personal data. Cellular phone
operators in this case become collectors, processors as well as processors of personal data
that are massively submitted by the public because they are encouraged by government
policies. Both of the above reflect systemic problems in public legal awareness, lack of
effective regulation and law enforcement.
The disorder that occurs in terms of public protection in the midst of the digital economy era
requires law as a guardian so that developments towards the digital economy run in an
orderly manner. However, the protection of privacy and personal data in United States in a
specific legal instrument does not yet exist and is still sectoral in nature so that it is not
sufficient to encourage the development of the digital economy in United States. For this
reason, it is necessary to first examine what regulations exist in United States regarding
privacy and personal data that can encourage the development of the digital economy. This
can be done using the legal search method. In addition, with regard to morality, it is also
necessary to know how it should be done.
The protection of privacy and personal data in United States can be responsive to the
changing trends from the traditional economic era to the digital economic era.
This topic is important to research because United States is currently in the era of transition
from the traditional economy to the digital economy. The Traditional Economic Era is an era
before information technology developed rapidly. In the traditional economic era, the trade of
funds or other transactions between communities was carried out directly. This kind of
transaction requires the parties to the transaction to be physically present at the same time and
place. In contrast to the digital economy era, the transactions described earlier can be carried
out with the help of information and communication technology, thus a new era has emerged
called the Digital Economy Era.
The rapid development of information and communication technology has changed the way
people conduct business and/or make transactions. Thus, transactions known as "e-
transaction", "e-comerce" and "e-business" have emerged. United States is now in the era of
digital economy. This claim is supported by the state of United States society which makes
the internet, cellular phones a commodity, and these commodities are used by traders and
sellers to signify electronic transactions through the internet network. This requires that the
laws governing these activities can follow or even anticipate developments into the Digital
Economy Era.
Legal provisions related to the protection of privacy and personal data in United States are
still partial and sectoral. United States has personal data protection rules that are scattered in
various regulations, for example Law Number 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law Number 10 of 1998 concerning
Banking regulates personal data regarding depositors and their deposits. In addition, privacy
and personal data protection regulations are also found in Law No. 36 of 1999 on
Telecommunications, Law No. 39 of 1999 on Human Rights, Law No. 23 of 2006 on
Population Administration (amended by Law No. 24 of 2013) and Law No. 11 of 2008 on
Electronic Information and Transactions (amended by Law No. 19 of 2016), as well as
Government Regulation No. 82 of 2012 on the Implementation of Electronic Systems and
Transactions.
United States also has a Draft Law (Bill) on Personal Data Protection that is being drafted in
the House of Representatives. The bill was made on the basis that the existing arrangements
on privacy and personal data are deemed not to provide maximum protection with the
development of technology, Informatics, communication and the needs of the community, as
well as the development of privacy arrangements and personal data globally and the practices
of other countries. The substance of the Personal Data Protection Bill is directed to be able to
reach various community activities related to the protection of privacy and personal data in
addition to the regulatory substance must pay attention to the "common elements" of various
privacy and personal data protection regulations that are developing both internationally,
regionally and in the practices of other countries. The scope and direction of the regulation of
this Draft Law is to provide limitations on the rights and obligations of the parties against
every act of acquisition and utilization (management) of all types of personal data both
carried out in United States and personal data of United States citizens abroad, whether
carried out by individuals or legal entities (public, private, and community organizations).4
Both the provisions scattered in various laws, as well as the provisions contained in the
Personal Data Protection Bill must be able to guarantee the orderly change of society from
the traditional economic era to the digital economic era. The existing provisions must be able
to protect the community in the midst of the digital economy era. This article will provide
answers to the question of whether the existing and future provisions are sufficient to
encourage the development of the digital economy in United States. With regard to what
should exist (das sollen), this article will discuss how privacy and personal data protection in
United States should be responsive to anticipate the changing trends from the traditional
economic era to the digital economic era.
Discussion
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.
Privacy and Personal Data Protection in United States
Data is personal data if it relates to a person, so that it can be used to identify that person, the
owner of the data.5 For example, a phone number on a blank piece of paper is data. It is
different if the piece of paper contains a phone number and the name of the owner of the
phone number, the data is personal data. The phone number on a blank piece of paper is not
personal data because the data cannot be used to identify the owner, while the phone number
and the owner's name can be used to identify the owner to identify the owner of the data,
therefore it can be referred to as personal data.
An identifiable person is someone who can be recognized/identified directly or indirectly
based on an identification number or based on one or more specific factors of physical,
psychological, mental, cultural or social identification. The entity protected in the personal
data protection mechanism is a "natural person" not a "legal person".6 The right to personal
data protection develops from the right to respect for private life. The concept of private life
relates to humans as living beings. Thus the natural person is the ultimate owner of the right
to personal data protection.
In terms of the protection of personal data, there are several categories of legal subjects that
must be regulated. The first legal subject is the "Personal Data Manager", namely persons,
public or private legal entities and other community organizations that individually or jointly
manage personal data. Personal Data Manager conducts "personal data management"
activities in the form of activities or series of activities carried out on personal data, either by
using data processing tools automatically or manually, in a structured manner and using data
storage systems, including but not limited to processing activities for collecting, using,
disclosing, disseminating and securing personal data.
Other legal subjects are "Personal Data Processors" which are public or private legal persons
and other community organizations that perform personal data processing on behalf of data
managers. Data Processor Personal data processing activities in the form of collecting,
recording, recording and or storing personal data, or the preparation, adjustment, amendment
of personal data, recovery of personal data that has been destroyed, disclosure of personal
data, merging, rectification, deletion or destruction of personal data.
Provisions regarding the protection of privacy and personal data are the mandate of Article 28
G of the 1945 Constitution of the Republic of United States which regulates the right to
protection of self, family, honor, dignity, and property under their control. To be able to see
these provisions as provisions regarding privacy and personal data, the opinion of Warren and
Brandeis in his work entitled "The Right to Privacy" states that privacy is the right to enjoy
life and the right to be respected for feelings and thoughts. 8 Privacy protection is closely
related to the fulfillment of personal data rights. The relationship between privacy and
personal data protection is emphasized by Allan Westin. He defines privacy as the right of
individuals, groups or institutions to determine whether or not information about them will be
communicated to other parties. 9 The definition put forward by Westin is called information
privacy because it concerns personal information. Under article 28 G of the 1945
Constitution, personal data protection in United States is spread across various laws. Then,
personal data protection is one form of privacy protection mandated directly by the
Constitution of the Republic of United States which contains respect for human rights values
and values of equality and respect for individual rights so that it is necessary to provide a
legal basis to further provide privacy and personal data security and ensure the
implementation of a conducive business climate.
Personal data protection in the banking sector has been regulated in Article 40 of Law
Number 10 of 1998 concerning Banking. Based on this provision, banks are obliged to keep
information about depositing customers and their deposits confidential. However, there are
several exceptions to this protection, namely: (1) In the case of taxation, the Minister of
Finance issues a written order to the bank to provide information and show written evidence
and letters regarding the financial condition of certain Depositing Customers to tax officials;
(2) The Chairman of Bank United States gives permission to officials of the State
Receivables and Auction Agency / State Receivables Affairs Committee to obtain
information from the bank; (3) The Chairman of Bank United States shall grant permission to
the police, prosecutor, or judge for the purpose of trial in a criminal case to obtain
information from a bank regarding the deposits of a suspect or defendant in the bank; (4) The
Board of Directors of a bank may disclose the financial condition of its customers to other
banks in the context of interbank exchange of information; (5) Upon request, approval or
power of attorney from a depository customer in writing, a bank shall provide information
regarding the deposits of the depository customer in the bank concerned and (6) In the event
that a depository customer has passed away, the legal heirs of the depository customer
concerned shall be entitled to obtain information regarding the deposits of the depository
customer.
In the digital economy era, telecommunications infrastructure and activities are the backbone
of information exchange and electronic transactions between communities. For this reason,
United States has Law Number 36 of 1999 concerning Telecommunications. The law also has
rules regarding personal data. Article 40 of Law No. 36/1999 on Telecommunication
regulates the prohibition of wiretapping activities. Every person is prohibited from tapping
information transmitted through telecommunication networks in any form. The prohibition is
positive for the protection of privacy and personal data. In addition, Article 42 paragraph (1)
stipulates that telecommunication service providers are obliged to keep the information sent
confidential.
In addition, in terms of privacy and personal data in electronic transactions, the use of any
information through electronic media concerning a person's personal data must be done with
the consent of the person concerned.10 The right to privacy implies:11 (1) the right to enjoy
one's private life and the right to enjoy one's personal life. Furthermore, in terms of privacy
and personal data in electronic transactions, the use of any information through electronic
media concerning a person's personal data must be done with the consent of the person
concerned.10 The right to privacy implies the following:11 (1) the right to enjoy a private life
and to be free from all kinds of interference; (2) the right to be able to communicate with
others without spying; and (3) the right to monitor access to information about one's private
life and data. The implementation of electronic systems is also related to privacy and personal
data. Thus, Government Regulation No. 82/2012 regulates the protection of personal data that
must be carried out by electronic system organizers.
Some privacy and personal data protection laws outside United States, such as the EU
Directive, distinguish between 'sensitive' and 'non-sensitive' data based on the level of harm
that will be felt to individuals if accessed by irresponsible parties.13 One of the data included
in sensitive data is data regarding a person's health or health condition. United States, in this
case, has regulated the protection of privacy and personal data for health data. United States
guarantees that every person has the right to the confidentiality of their personal condition
that has been disclosed to health service providers.14 However, the health law does not
explicitly state that personal data regarding health is sensitive data. Thus, United States has
not actually distinguishes between general personal data and sensitive personal data. In fact,
sensitive personal data requires higher protection than general personal data.
The management of population administration also does not escape the regulation regarding
the protection of privacy and personal data. Every Resident has the right to obtain protection
of privacy and personal data as well as compensation and restoration of good name as a result
of errors in Population Registration and Civil Registration and misuse of personal data by the
Implementing Agency. 15 Thus the Implementing Agency carrying out Population
Administration affairs has an obligation to guarantee the confidentiality and security of
population data.16 This obligation is a consequence of the state's obligation to, not only store,
but also protect the privacy and personal data of residents. Population data is personal data
that if leaked will threaten the privacy of its owner, because population data includes but is
not limited to date/month/year of birth, information about physical and/or mental disabilities;
and some contents of Important Event records.
Convergence of Privacy and Personal Data Protection
All of the above privacy and personal data protection arrangements, particularly those
relating to privacy and personal data, are currently in the process of convergence. The term
"convergence" is an English term that has been absorbed into United States. The term has
gained a place as standardized United States. According to the Kamus Besar Bahasa United
States, convergence means:17 "the state of heading towards a single point of convergence or
centering." In this article, the term "Convergence of Privacy Protection and Personal Data" is
a concept that describes the process or effort to combine the arrangements regarding privacy
and personal data that are scattered in various legal instruments into one separate legal
instrument. Thus, the protection of privacy and personal data has a sui generis place. The
current state of privacy and personal data regulation in United States is divergent, as opposed
to convergent.
This convergence of privacy and personal data protection is not only happening in United
States, but also spread in various parts of the world, without exception within the scope of
countries and international organizations. The European Union has had The European Union
DP Directive (Directive) introduced in 1995 with the aim to harmonize national regulations
among EU member states. The Directive is considered to be one of the most robust regimes.
Hong Kong has the Personal Data Privacy Ordinance of 1995 (PDPO) as the first national
legislation to comprehensively regulate data privacy and personal data issues. 18 Privacy of
personal data in Malaysia is protected through The Personal Data Protection Act No. 709 of
2010 (PDPA Malaysia).19 Meanwhile, privacy and personal data in Singapore is protected
sectorally by The Personal Data Protection Act No. 26 of 2012 Singapore (PDPA 2012
Singapore).
United States is currently in the process of converging privacy and personal data protection as
it has a Personal Data Protection Bill. The Bill aims to merge the scattered privacy
regulations on personal data into a separate law. The drafting of the Academic Paper as the
initial phase of the convergence process was completed in October 2015, as a result of a
study between the Ministry of Communication and Information of the Republic of United
States and the Cyber Law Center, Faculty of Law, Padjadjaran University. After the bill
formed, the next step that the Ministry of Communication and Information Technology must
take is to submit the Personal Data Protection Bill to the 2018 National Legislative Program.
Convergence of privacy protection of personal data is important for United States to provide
privacy and personal data protection on par with other countries. 20 The arrangements to be
drafted in the Draft Law are expected to put United States on par with economically
developed countries that have implemented laws on privacy and personal data protection.
there is an interest in providing personal data protection on par with other countries. The
regulation to be drafted in the Draft Law is expected to put United States on par with
economically developed countries that have implemented laws on privacy and personal data
protection. This will further encourage and strengthen United States position as a trusted
business center, which is a key strategy in United States national economy. This will further
encourage and strengthen United States position as a trusted business center, which is a key
strategy in United States national economy. In addition, a bill that protects privacy and
personal data will address the threat of misuse of consumer privacy and personal data and
provide economic benefits to United States.
It is unfortunate that the process of passing the Personal Data Protection Bill into the Personal
Data Protection Law has been slow. The Personal Data Protection Bill has not yet been
accepted to be included in the 2018 National Legislative Program.21 Although it is still
hampered, United States has taken the right business steps to be able to move from the state
of divergent regulation of privacy and personal data to convergent regulation.
Privacy Protection Law on Personal Data supporting the Digital Economy
The main driver of the Digital Economy is the internet. The internet has become a global
marketplace where economic actors meet. 22 Not only that, the internet also allows for more
efficient patterns of communication and information distribution to market a product more
broadly than in the traditional economy. Information technology that is getting cheaper,
faster, better and easier to use allows organizations and individuals to be more wirelessly
connected which then becomes the center of economic and social activities. 23 Technological
developments have driven the shift from the traditional economic era, which can also be
called the "pre-digital" era, to the Digital Economy era. As such, the legal protection of
privacy and personal data is also required to adjust.
In the pre-digital era, the protection of privacy and personal data from infringement by the
government or other parties can be achieved by a divergent pattern of legal arrangements,
where privacy and personal data arrangements are placed in different laws. This claim is
supported by world practices.24 In this phase, individuals around the world who want their
privacy rights preserved can implement self-protection mechanisms. Important records
containing privacy and personal data can be hidden in the drawers of a cabinet or in a safe.
This kind of self-defense mechanism will be difficult to do in the next era, namely the Digital
Economy Era.
The top of the pyramid is called "The spearhead". It houses the technological inventions and
products of the silicon and semiconductor industries. 26 Although it is not a large sector, it is
very important because its products are the core of computer and information technology.
The second part of the pyramid, which is below "the spearhad", consists of the computer and
telecommunications manufacturing and service industries. These industries are called "core
sectors" because they are the core of the Digital Economy and enable the sectors at the
bottom of the pyramid to operate. 27The third section is called the "main body", representing
the main body of the digital economy. Included in this section are manufacturing and service
delivery activities that rely heavily on digital technologies.28 Most people working in these
industries spend their time in front of computers and other communication devices. Some
service industries such as e-commerce, media and entertainment and financial services are
part of this industry. The base of the Pyramid are sectors that are not affected by
digitalization, or are very little affected by digital technology. Examples of such industries
are the agricultural industry, or public services such as domestic help, garbage removal,
hairdressing, where the majority of businesses do not use computers to any significant extent.
The nature of activities in the 2nd and 3rd tiers of the pyramid means that individuals who
want to engage in digital economic activities give their privacy and personal data to other
parties. This privacy and personal data can easily be channeled back to other parties. Not only
personal records, the individual's behavior online becomes more exposed to other parties.
Thus, increased legal protection becomes very important in the Digital Economy Era.
Without stronger legal protection, it is impossible to expect the world to become a privacy
paradise. 30 Traditional means as self-defense mechanisms are no longer possible.
Files on one's health, finances, travel and consumption would be very difficult to store
entirely in a physical room. Correspondence, communication records can even be found and
accessed from anywhere in the world, as they are recorded in the databases of internet or
telecommunication providers. This phenomenon is called "Cloud Storage".31 Data owners no
longer know where their personal data is physically stored, but digitally their personal data
can be accessed all over the world. In such circumstances, protecting privacy and personal
data independently is a difficult challenge.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not yet have a legal instrument that is in accordance with the law digital
era. A legal instrument to protect the privacy of personal data in the digital economy must at
least fulfill several criteria:
Privacy and personal data protection that has an international character Data in the era of
the Digital Economy does not physically move to a destination that is as predictable as it is in
the Traditional Economy. In an economic relationship between private individuals and
companies, the physical storage place of privacy and personal data will be difficult to find if
the transaction is done digitally. The place where the data is stored can no longer be limited
by the scope of national jurisdiction, as it will be transnational. 32 The data can also be
accessed by someone from a country other than the country that owns the data. Thus, for
reasons of effectiveness, the protection of privacy and personal data must also be supported
by regulations that are cross-border in nature. Such rules include rules that the transfer of
personal data outside the country must require special approval, and can only be made to
countries that have equivalent privacy and personal data protection.
Several international legal instruments set out internationally recognized principles of privacy
and personal data. These principles are the foundation for modern national data protection
laws. One of the international instruments protecting privacy and personal data was issued by
the Organization for Economic Co-operation and Development (OECD). The international
organization issued Privacy Guidelines, which are not legally binding but have long been
recognized as guidelines for establishing privacy protection norms for OECD member
countries.
In addition to the OECD, the Council of Europe (CoE) has adopted the European Convention
for the Protection of Human Rights (ECHR) in 1950. In 1981, the CoE adopted the
Convention for the Protection of Individuals with Regard to Automatic Processing of
Personal Data (DP Convention).33 This convention applies to the automatic processing of
personal data in both the private and public sectors.
Personal data protection and privacy in the European Union have been recognized as
fundamental rights in The European Union Charter of Fundamental Rights. As a derivative
of the Charter, the EU has a new personal data protection legislation in 2016 that is used to
protect personal data in the digital era. The EU legislation is known as The General Data
Protection Regulation (GDPR) which was adopted under Regulation 2016/679. The
regulation is essentially a step to strengthen the fulfillment of the basic rights of EU citizens
in the digital age and will directly impact the drive for business development in the digital
age. As a further step, namely in the law enforcement sector, the EU established The Police
Directive based on Directive 2016/680 which protects individuals in the processing of
personal data that has elements of criminal offenses as well as the application of criminal
sanctions for personal data violations committed against data subjects.34
Data Privacy Protection as an element of the glue of individual and economic society
The right to privacy and personal data is a right that has an international character in its
unclear status in national legal protection. In national legal protection there are two points of
contention. Privacy on the one hand is a right that creates a distance between individuals and
society. 35 On the other hand, especially in the society of the Digital Economy Era, privacy is
also a right that can attach individuals to society. With the existence of With the protection
of privacy and personal data, individuals will have the confidence to participate in the digital
economy.
The protection of privacy and personal data in the Digital Age is experiencing a strengthening
trend in various countries. 36 This is because the protection of privacy and personal data is
far from sufficient when compared to the rapid development of internet and communication
technology. Not only does it stop at the national legal framework, strengthening the
protection of privacy and personal data is also needed in a cross-border framework. In this
case, technological developments and recent cases of wiretapping are the impetus for the
need for a stronger legal framework for the protection of privacy and personal data.
Technological developments, such as the development of what is known as the Internet of
Things (IoT), threaten the privacy and personal data of individuals. In an IoT technology, a
device can be designed in such a way as to constantly monitor every activity of its users, even
collecting sensitive data of its users, and connected via an internet connection.37 This
technology allows someone to remotely access the personal information of the device user,
because it is connected via the internet. In addition, the case of Edward Snowden who leaked
National Security Agency (NSA) documents was recently revealed. This case gave birth to
many discussions about the right to privacy in the Digital Age. The relationship between
personal data, wiretapping and privacy protection has become a major concern in the Digital
Age. 38 In subsequent developments, especially in the context of the Digital Economy, the
relationship between personal data, wiretapping and privacy protection has become a
determining factor in the confidence of market participants to move in the digital market.
Not only at the country level, equal privacy and personal data regulation is also promoted
regionally (between regions and other countries),
An example is the "Transatlantic Trade of Personal Data" between the European Union and
the United States. Under this scheme, a person's personal data can be transferred from the EU
to the US, and vice versa, provided that both countries have equal protection.39 In this
framework, the trade relations between the EU and the US in the digital age are strongly
influenced by the legal rules of privacy and personal data protection. Equal protection is a
prerequisite for the exchange of personal data. If the exchange of personal data is hindered, it
is not only governmental interests that will be hindered, but greater economic interests. In
many industries40 , such as frameworks, the exchange of personal data is critical to the
sustainability of the financial system. The existence of a Law on the Protection of Personal
Data is a necessity that cannot be delayed because it is very urgent for various national
interests. United States international relations also demand the protection of personal data and
information. Such protection can facilitate transnational trade, industry and investment.
Conclusion
United States already has privacy and personal data protection rules scattered in various laws
and regulations, for example Law No. 36 of 2009 concerning Health regulates the
confidentiality of patients' personal conditions, while Law No. 10 of 1998 concerning
Banking regulates privacy and personal data regarding depositors and their deposits. In
addition, the regulation of privacy and personal data protection is also found in Law No.
36/1999 on Telecommunications, Law No. 39/1999 on Human Rights, Law No. 39/1999 on
Human Rights, Law No. 39/1999 on Human Rights, and Law No. 39/1999 on Human Rights.
Law No. 23/2006 on Population Administration (amended by Law No. 24/2013) and Law
No. 11/2008 on Electronic Information and Transactions (amended by Law No. 19/2016), as
well as various other regulations. United States also has a Draft Law (Bill) on Personal Data
Protection which is currently in the intra-ministerial discussion stage and is expected to be
proposed in the 2018 national legislation. Convergence of Personal Data Protection is
important for United States, even though convergence is important to provide privacy and
personal data protection on par with other countries. The regulation to be drafted in the Draft
Law is expected to put United States on par with economically advanced countries that have
implemented laws on privacy and personal data protection.
Until now, there is still uncertainty about the protection of privacy and personal data, because
United States does not have legal instruments that are responsive to the needs of the
community to obtain stronger protection. Existing legal instruments in the digital economy
era. A legal instrument for the protection of privacy and personal data in the digital economy
must at least meet 3 criteria: (1) have an international character; and (2) be an element of the
glue of individuals and economic society. The first characteristic is that the protection of
privacy and personal data must also be supported by regulations that cross national borders.
Such rules include the rule that the transfer of privacy and personal data outside the country's
territory must require special approval, and can only be made to countries that have equal
privacy and personal data protection. Second characteristic, in the context of the Digital
Economy Era, the protection of privacy and personal data must also include the protection of
personal rights. In other words, in addition to being negative rights that require the state not
to do something so that the rights are fulfilled, it must also be positive rights whose
fulfillment can only be done with the active role of the state. The digital economy with all its
special characteristics and rapid development cannot be ignored requires the state to not just
stand by, but to do something more. The third characteristic is that the protection of privacy
and personal data can increase the confidence of individuals to participate in the digital
economy.